Skip to the waitlist form
01Pre-launch

Pentest tooling that scales down to one.

Scope the engagement, pick your tests, score the findings, ship a branded report, run the retest. Under your own name or your channel partner's. Built for a firm of one to five, not a security operations centre.

Early access, in order. No demo call, no sales sequence.

02The problem

The report is the product. It's still being built in Word.

You run a good test. Then you spend the rest of the engagement moving it into a document.

Findings live in a spreadsheet. Screenshots live in a folder named evidence_final_v3. Severity gets argued into a cell by hand. The write-up for the same SQL injection you've reported nine times gets retyped a tenth, slightly differently, because last quarter's version is buried in a client folder you'd have to go find.

Then the client fixes three of the six issues and asks for a retest. So you open the delivered PDF, edit it, and hope you caught every place the status changed.

The tools that solve this exist. They're priced for teams that aren't you.

PlexTrac

doesn't publish a price. You book a demo and get a quote shaped by seat count and modules.

Dradis

publishes $79 per user per month to write reports, $149 to track remediation, and frames its ROI around “teams of 5.”

For a shop of one to five people, both answers are the same answer: pay for a team you don't have, or keep using Word.

03What's in it

One tool for the whole engagement, not just the write-up.

Scoping questionnaire through delivered PDF through retest round three. Here's what's in the first release, and what isn't.

A test library that already covers AI, not just web apps

First release

Two seeded methodologies, both from OWASP, both public and citable in a client report:

  • OWASP Web Security Testing Guide 4.2. The standard web application methodology, plus a “1 Day Pentest” template bundle you can drop into a plan whole.
  • OWASP AI Testing Guide v1 (released November 2025). All 32 tests, AITG-APP-01 through AITG-MOD-07, organised across its four layers: AI Application, AI Model, AI Infrastructure, AI Data.

Add your own procedures alongside them. Every procedure carries execution steps and success criteria, so a test you wrote once runs the same way next time.

When a client asks whether you can assess the LLM feature they shipped last quarter, you have a methodology to point at instead of a proposal to invent.

CVSS you can't fat-finger

First release

Score findings from a structured vector picker: AV/AC/PR/UI/S/C/I/A, CVSS 3.1 or 4.0. The score is computed server-side from the vector. Severity is computed from the score using the standard bands. Neither is a text field anyone can type into.

Reusable finding templates give you consistent starting text for the vulnerability classes you report constantly. You fill in the specifics: affected assets, proof of concept, evidence.

Branded reports, including someone else's brand

First release

The report carries a theme: logo, colours, company name, footer, and the brand-specific prose that logos alone can't re-skin: confidentiality statement, disclaimer, assessment blurb. Pick the theme at generation time.

If you deliver through a channel partner, that's the same feature. A report generated under your MSP's branding is a theme swap, not a separate export path and not a separate contract. One engagement can be delivered under whichever brand the deal requires.

Drafts are unlimited and watermarked. Final reports are versioned.

Retests that don't mean editing a PDF

First release

A retest opens a new round. Every finding gets a revalidation for that round: fixed, partially fixed, or not fixed, with its own evidence. Rounds are kept as history, so a report stays reconstructible exactly as it was delivered.

An engagement can't be marked delivered until every finding predating the current round has been revalidated. That gate is enforced by the app, not by your memory.

Edit the library. Don't edit history.

First release

Test-plan items and findings copy their content out of the library when you select them. Improving a shared procedure next month never silently rewrites the report you delivered last month.

It's an unglamorous property. It's also the one that keeps a delivered report defensible when a client comes back to it a year later.

LLM-suggested tests

Planned

Answer the scoping questionnaire and get suggested procedures from the library with a written rationale and a confidence score. You accept or reject each one. Rejected suggestions stay rejected and don't resurface.

The library stays yours: nothing generated becomes reusable across engagements until it's approved.

Scanner import

Later

Burp XML, Nessus, Nmap. Field mappings are researched and the findings schema already has the columns they need. The work isn't started.

04Credibility

No logos. No case studies. Here's what there is instead.

This is a pre-launch page for a product being built right now, so there's nothing honest to put in a testimonial slot. What can be checked:

It's being built against a real engagement, not a demo script. The first user is the security practice building it, and the first engagement it has to survive is already scoped. That's what's setting the build order.

The methodology content is public and verifiable. OWASP WSTG 4.2 and the OWASP AI Testing Guide v1 are open standards you can read before you trust anything here. Nothing in the test library is a proprietary black box you'd have to defend to a client.

It's hosted, not self-hosted. Reports and evidence live in object storage scoped per engagement, behind SSO. If running the tool inside your own infrastructure is a hard requirement for your clients, Dradis is the honest answer for you today and this page shouldn't waste your time.

The stage is stated, not implied. Everything above is tagged First release, Planned, or Later. If something moves, waitlist members hear about it in writing.

Where this actually is

Building now
Engagements, scoping questionnaire, OWASP WSTG + AI Testing Guide libraries, CVSS findings with evidence, branded multi-brand reports, retest rounds.
Next
LLM test suggestion. Partner self-service, so your channel partner logs in, manages their own branding, and works at their own domain instead of you generating on their behalf.
Later
Scanner import, client-facing read-only access to findings and reports.
Not decided yet
Pricing. See below.
05Pricing

What it'll cost

Not decided yet. Three things are, and they're commitments, not estimates:

The price will be on the website. You won't book a call to find out whether you can afford it.

No seat minimum. A firm of one pays like a firm of one.

Waitlist members get the number first, with time to say it's wrong before anything launches.

06Waitlist

Get in before pricing is set.

Early access goes out in order. Waitlist members see the pricing model before it's public and get asked what's wrong with it.

How do you deliver reports?

One email when there's something to see. No sequence, no drip, no reselling your address. Unsubscribe in one click.