PentrAX AI combines autonomous AI reconnaissance, a full multi-agent exploitation engine, and a credentialed in-app browser to deliver audit-ready, compliance-mapped reports — without requiring an internal security team.
Private beta · Founding cohort seats are limited · Authorisation gated by signed Terms of Engagement
PentrAX AI · Engagement #PT-2026-04812
Findings
60
12 actionable
Avg CVSS (open)
7.4
3 above 9.0
Compliance gaps
11
across 6 frameworks
Top attack chain — MITRE ATT&CK
Findings automatically mapped to
Two-phase engagement model
A free AI recon, then optional deep assessment — gated by a DRM-protected preview.
Passive enumeration, tech fingerprint, public CVE matching, surface-level vulnerability discovery. Produces a redacted, watermarked draft report preview.
Deep web, network, API, auth, and cryptographic testing. AI-correlated attack chains, full compliance gap analysis, downloadable PDF.
Testing modules
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Adaptive payloads, AI-driven exploit selection, automatic evidence capture.
Platform capabilities
Beyond scanning: a full engagement lifecycle from recon to remediation tracking.
Specialised agents handle recon, exploitation, correlation, and report writing — each tuned to its own attack surface, not a single general-purpose model.
A live, interactive browser session runs inside the platform so authenticated flows — logins, multi-step forms, SPAs — get tested exactly as a human tester would.
Re-scan targets on a schedule and get alerted the moment posture drifts between releases, not just at engagement time.
Request a retest on any finding directly from the platform — evidence is re-collected and the finding's status updates automatically.
File a finding straight to your existing tracker with one click. No copy-pasting CVSS scores into a ticket template.
Store target login credentials and session cookies, AES-256-GCM encrypted at rest, scoped per target and never returned in plaintext.
Separate clients or business units into isolated workspaces with their own targets, findings, and role-scoped access.
Admin, analyst, auditor, and super-admin roles — auditors get read-only access, analysts triage findings, super-admins manage every tenant.
Scan completion, critical findings, and export-ready reports push to the dashboard and your integrations the moment they happen.
Draft previews render in a viewer that blocks download, copy, print, and screen capture — watermarked per recipient.
Domain-ownership verification and a cryptographically signed Terms of Engagement gate every scan before it starts.
Trigger scans from CI/CD, pull findings programmatically, and push results to Slack, email, or any webhook endpoint.
Every phase — recon, exploitation, analysis, reporting — is AI-driven, not rule-based. The engine learns from emerging CVEs daily.
Draft previews are rendered in a viewer that disables download, copy, print, and screen capture. Watermarked per user.
Trigger scans from CI/CD. Receive Slack / Jira alerts. Track posture drift across releases.
A manual assessment that takes 4 weeks and costs $40k is delivered in hours, at a fraction of the price.
Scope verification, domain ownership proofs, cryptographically signed ToE — preventing unauthorised use across jurisdictions.
Every finding includes evidence, CVSS v3.1 + v4.0, CWE, MITRE technique, and remediation. Reports are accepted by SOC 2 / ISO auditors.
PentrAX AI is in private beta. Founding cohort members get free full assessments and direct input into the roadmap.