Now in Public Beta

AI-Powered
Penetration Testing

Autonomous security scanning powered by GPT-4. Submit a target, get a professional pentest report. No setup required.

pentestgpt-agent
$ pentestgpt scan --target example.com
[*] Verifying target ownership...
[+] DNS TXT record verified
[*] Launching container: pentest-a3f8c2
[*] Running reconnaissance...
[+] Nmap: 4 open ports found
[+] Gobuster: 12 directories discovered
[!] Nikto: 3 potential vulnerabilities
[+] Report generated: report-a3f8c2.pdf

Everything You Need for Automated Pentesting

Professional-grade penetration testing powered by AI agents, running in isolated environments with full reporting.

🤖

Autonomous Scanning

AI agent runs nmap, gobuster, nikto, sqlmap and more — automatically choosing the right tools for each target.

📡

Real-Time Monitoring

Watch the AI work through your pentest live via WebSocket. See every command, output, and decision in real time.

📋

Professional Reports

Generate PDF/HTML reports with findings, severity ratings, CVSS scores, and actionable remediation guidance.

📦

Isolated Containers

Every scan runs in a fresh Docker container for complete isolation. No cross-contamination between scans.

Target Verification

Verify target ownership via DNS TXT record or file upload before scanning. Ensures authorized testing only.

🔗

API Access

Integrate with your CI/CD pipeline using our REST API. Automate security testing on every deployment (Pro & Enterprise).

How It Works

Three simple steps from target to report. No infrastructure to manage, no tools to install.

1

Verify Target

Prove ownership of your target domain or IP address via DNS TXT record or file-based verification.

2

Launch Scan

Configure your scan type and parameters, then let the AI agent go to work in an isolated container.

3

Get Report

Download a comprehensive pentest report with categorized findings, severity ratings, and remediation steps.

Simple, Transparent Pricing

Choose the plan that fits your security testing needs. All plans include target verification and isolated containers.

Starter

$99
per month
  • 1 scan per month
  • 1 concurrent scan
  • 30 minute timeout
  • HTML reports
  • Target verification
  • Isolated containers
  • API access
  • Priority queue
Get Started

Enterprise

$1,895
per month
  • 25 scans per month
  • 5 concurrent scans
  • 4 hour timeout
  • PDF + HTML + JSON reports
  • Target verification
  • Isolated containers
  • API access
  • Priority queue
Get Started