# Pentesty > AI-powered automated penetration testing. Run a credible pentest in under 10 minutes — no consultant queue, no false positives, professional PDF report. Pentesty combines large-scale Nuclei scanning (8,000+ vulnerability templates) with Claude AI to triage findings, assign real CVSS 3.1 scores, and generate structured PDF reports. It is designed for security teams, engineering leaders, startups, and developers who need fast, evidence-quality security assessments. ## What Pentesty does - Runs automated penetration tests against web targets the user owns or has written authorization to test - Executes 8,247 Nuclei templates covering OWASP Top 10, CVEs, misconfigurations, exposed panels, and more - Uses Claude Sonnet (AnalystAgent) to filter false positives and classify findings by severity: critical, high, medium, low - Uses Claude Sonnet (ReporterAgent) to produce a full Markdown report with Executive Summary, Risk Score, vulnerability table, detailed findings, and action plan - Renders a branded A4 PDF via WeasyPrint with severity badges, finding cards, and professional typography - Stores PDFs in Supabase Storage and returns a public URL to the user - Average scan-to-report time: under 10 minutes - Accuracy rate: 99.2% (near-zero false positives) ## Who it is for - Security engineers and pentesters who need faster turnaround - Engineering leaders preparing for compliance audits (SOC 2, ISO 27001, PCI DSS) - Startups and SaaS companies that lack an internal security team - Developers who want to test their own applications before launch - Bug bounty hunters and CTF participants (against authorized targets only) ## Pricing Pentesty uses a credit-based model billed monthly via Stripe. Each credit equals one complete scan. Plans include Starter, Growth, and Pro tiers. Users can scale up or cancel at any time from the customer portal. ## Technical stack - Scanner: Nuclei 3.x (ProjectDiscovery) - AI agents: Anthropic Claude Sonnet (claude-sonnet-4-x) - Backend: FastAPI + Celery + Redis - Database & Auth: Supabase (PostgreSQL + Storage) - Frontend: Next.js 16 + React 19 + Tailwind CSS 4 - PDF rendering: WeasyPrint ## Ethics and responsible use Pentesty only supports scanning targets the user owns or has explicit written permission to test. Unauthorized scanning is prohibited. See full policy at https://pentesty.co/ethics ## Key pages - Homepage: https://pentesty.co - About: https://pentesty.co/about - Blog: https://pentesty.co/blog - Ethics policy: https://pentesty.co/ethics - Privacy policy: https://pentesty.co/privacy - Terms of service: https://pentesty.co/terms - Contact: support@pentesty.co ## Selected blog articles - iFood data leak & extortion: https://pentesty.co/blog/ifood-data-leak-extortion-2026 - AI-powered cyber attacks in 2026: https://pentesty.co/blog/ai-powered-cyber-attacks-2026 - Cloud security misconfigurations 2026: https://pentesty.co/blog/cloud-security-misconfigurations-2026 - Prompt injection in a Brazilian courtroom: https://pentesty.co/blog/prompt-injection-brazil-labor-court-2026 - ShinyHunters extortion playbook: https://pentesty.co/blog/shinyhunters-extortion-playbook-2026 - Rockstar Games ransom refusal: https://pentesty.co/blog/rockstar-shinyhunters-ransom-refusal-2026 - BTG Pactual financial data security: https://pentesty.co/blog/btg-pactual-financial-data-security-2026 - Udemy breach & ShinyHunters: https://pentesty.co/blog/udemy-breach-shinyhunters-2026 - CVE-2026-41940 cPanel auth bypass: https://pentesty.co/blog/cve-2026-41940-cpanel-whm-authentication-bypass - OWASP Top 10 developer guide: https://pentesty.co/blog/owasp-top-10-developers-guide - Why pentest reports lie: https://pentesty.co/blog/why-your-pentest-report-is-lying-to-you - Fable 5 and the US government AI shutdown: https://pentesty.co/blog/fable5-mythos5-us-government-ban-cybersecurity - Novo Nordisk breach via leaked GitHub token exposed Ozempic formula: https://pentesty.co/blog/novo-nordisk-ozempic-fulcrumsec-breach-2026 - SpaceX acquires Cursor for $60 billion and what it means for software security: https://pentesty.co/blog/spacex-acquires-cursor-60-billion-software-security - Frontier AI just got better at hacking and what GPT-5.6 Sol means for your security posture: https://pentesty.co/blog/frontier-ai-hacking-security-posture-gpt5-2026 - The AI super bubble warning is a filter not a funeral: https://pentesty.co/blog/ai-super-bubble-cybersecurity-filter-2026