About PentSeal
PentSeal is an authorization-first workspace for teams that run security tests against systems they own or are explicitly allowed to test. It keeps the authorization record, the asset inventory, the check results, the findings and evidence, and the exported report in one place.
Engagements and authorizations. Create an engagement, record who authorized the test, and keep that record attached to everything that follows.
Assets and ownership checks. Save a domain, compare the target against your inventory, and capture the ownership and scope evidence for the record.
Safe protocol checks. Visible TLS, DNS, and HTTP checks run against in-scope targets. The Stress Test and CMRTC screens are honest about their state: they show this deployment's real records, not a scripted history.
Findings, evidence, and report. Record findings and vulnerabilities, attach evidence, and export a PDF that documents what was tested and what was found.
PentSeal is not a self-serve hacking kit and is not sold as one. It does not include exploit proof-of-concepts or post-exploitation modules.
The exported PDF is a test record. It is not an attestation, and it does not replace SOC 2 / ISO evidence tools such as Vanta, Drata, or Secureframe. PentSeal is not a penetration-testing service, a live cloud-assessment engine, or an internet-facing asset-discovery replacement.
PentSeal is in an early pilot stage. The core path — engagement, authorization, asset verification, safe checks, findings, and report export — works today. Hosted production (backups, status page, hosted database), SSO/SCIM, live third-party integrations, and retest/ticketing export are planned but not yet available. We would rather tell you that plainly than imply capabilities that are not there yet.
Questions before a pilot? Reach us through the contact page.