Pentr runs autonomous pen testing campaigns against your estate (PCI, ISO, SOC 2, OWASP ASVS, NIST CSF, ENS) and seals every artifact in a tamper-evident locker your auditor will actually accept.
A fixed PTES pipeline, run in order. Every step the agent takes is timestamped, signed, and sealed into the locker. Abort the run at any point — the locker keeps every artifact already captured — and nothing executes outside the scope you declared.
Every control catalog maps to a phase in the agent. Evidence comes back labelled with the control it satisfies — not just dropped in a folder.
Sections 11.3 + 11.4 evidence automatically mapped from external and internal pen tests. Quarterly cadence ready out of the box.
Annex A technical-vulnerability and security-testing evidence, packaged the way surveillance auditors expect to receive it.
Drop scheduled campaigns into your Trust Services control catalog. Share the locker link directly with your auditor.
Verification requirements across chapters V1–V14, evidenced at the level you target — L1, L2, or L3 — with a real request/response proof per requirement.
Evidence mapped to CSF 2.0 Functions and Subcategories — Govern, Identify, Protect, Detect, Respond, Recover — in the outcomes language your risk team already reports in.
Spain's public-sector security framework. Pentr runs the periodic penetration tests MEDIA and ALTA systems require and seals the evidence your ENS audit expects.
Three operator actions. The agent owns everything in between.
Hosts, CIDR ranges, wildcards, and a framework. The agent plans every phase from there. No playbook to author.
Seven PTES phases in order: pre-engagement, intelligence, threat modeling, vulnerability analysis, exploitation, post-exploitation, reporting. Abort the whole run at any point — the locker keeps what's already sealed.
Every artifact framework-mapped and tamper-evident. Auditors verify integrity offline with one command, pentr-verify run_2k81m4 --key acme.pub, and walk away.
Auditors don't argue with hashes. The locker is an append-only, sha-256-chained store of every screenshot, request/response pair, command log, and exploit artifact the agent produced, bound to the run, the phase, and the control it satisfies.
Your team's runs become reproducible, not anecdotal. Every command the agent issued, every response it observed, every screenshot it captured, re-viewable from a single signed manifest. Hand it to a client. They can verify it themselves.
Inspect any campaign down to the request/response pair the agent captured at the moment it found the bug.
You shouldn't pay more for letting your whole security team see the same finding.
pentr-verify run_id --key acme.pub and receive control-mapped artifacts (e.g. PCI 11.3.1 next to the screenshot it satisfies). We've shipped to PCI QSAs, ISO surveillance auditors, and Big-4 SOC 2 reviewers without exceptions.Plug in a scope and a framework. The agent does the work. You walk into the audit with evidence already accepted.