Skip to main content

Documentation

PentSeal has one supported path from authorization to a signed-off test record. This is how it works today.

1. Create an engagement
Start in the workspace and create an engagement for the system you are authorized to test. Record who authorized the test and the testing window. The authorization record stays attached to the engagement.
2. Verify ownership and scope
Add the domains and hosts in scope. The Scope workspace compares the target against your asset inventory and captures the ownership evidence for the record. Confirm every target is one you own or are explicitly permitted to test.
3. Run safe checks
Run the built-in TLS, DNS, and HTTP checks against in-scope targets. Checks are read-only and visible from the outside. Screens that have no data for your tenant say so instead of showing example history.
4. Record findings and evidence
Log findings and vulnerabilities, attach evidence, and link them back to the engagement and the asset they affect. Add manual findings where an automated check does not cover the case.
5. Export the test record
Generate a PDF that documents the scope, the checks that ran, and the findings, so the record can be handed to the client or kept for the audit trail.
Findings and manual testing

From an engagement you can open a finding or vulnerability to see its detail page, including the affected asset, severity, status, and evidence. Manual findings let you record anything the automated checks do not cover, and they follow the same evidence and reporting path.

Current status: what is and is not available

AvailableEngagements, authorizations, asset verification, TLS/DNS/HTTP checks, findings, evidence, PDF report export.

Not yetSSO and SCIM (these endpoints currently return 501 Not Implemented), live third-party integrations that sync rows into Discoveries, hosted production deployment, and export to ticketing systems such as Jira.

Integration forms currently store credentials for later use; they do not yet pull live data. The Integrations, Stress Test, and CMRTC screens reflect your tenant's real records and show an empty state when nothing has run.