Home / Pentest scope authorization
Scope authorization is the record that answers the only question that matters if a test is ever questioned: who permitted this, on which assets, and when. This page explains what a defensible record has to contain, and how PentSeal makes that record the thing that decides whether a scan may run at all.
A penetration test is, technically, the same set of actions an attacker performs. What separates the two is authorization: a specific, dated permission from the party who controls the target, covering a defined scope and window. Scope authorization software exists so that permission is a structured record inside the tool that does the testing — not a signed PDF kept in a folder that nobody can tie back to the scans that ran.
The distinction is not academic. In a dispute, an incident review, or a client audit, the question is not whether the test was legitimate in principle. It is whether you can show, from the system of record, that this scan against this asset fell inside this authorization. A record assembled after the fact cannot answer that; a record the tool enforced as a precondition can.
A dashboard that shows a scanning window is not a control; it is a reminder. The control is a scanner that refuses to run outside the ports and hours that were agreed, and an ownership challenge that has to be answered from the target itself before any scan is permitted. That is the difference between documenting a limit and enforcing one.
PentSeal verifies target ownership, records the signed scope and testing window as a single record, and gates execution on it: no valid authorization, no scan. Findings come back with CVSS, CWE and evidence, mapped to the SOC 2 and PCI DSS controls they touch, and export as one deliverable. The authorization record and the evidence trail are the same object, so the story the report tells and the permission that allowed it cannot drift apart.
If you have not signed up yet, the free scope generator will produce the document in the browser — nothing is uploaded or stored — and you can pair it with the free authorization letter and rules of engagement templates. Those give you the paperwork. PentSeal is what makes the paperwork binding on execution.
PentSeal is priced per account, not per scan: Starter is $79/month for one user with up to five engagements per billing month, and Professional is $249/month for up to five users with unlimited engagements. Enterprise is priced per deployment. The pricing page lists the plan limits from the same definitions the product enforces. The templates and the scope generator above are free and require no account.
The interactive demo runs the ownership challenge, signed scope and scan gate on sample data — no account and no scan required.