Automated penetration testing & vulnerability management

Know your vulnerabilities
before attackers do.

Professional security testing for growing businesses. Find vulnerabilities across your web applications and infrastructure, prioritise what matters, and verify every fix — without waiting weeks for a consultant.

1 free credit
No credit card
Credits valid 1 year
Up and running in minutes
01
Register
02
Add & verify your website
03
Run your first scan
app.penscan.org / dashboard
Main
Dashboard
Targets
Scans 1
Security
Vulnerabilities 24
Reports
Security Dashboard
Acme Corp · 4 targets · Last scan: 2h ago
Open Vulns
24
↑ 3 new
Scans / mo
11
Active
Assets
47
Found
Risk score
C+
↑ Up
api.acmecorp.com
100%
Complete 12 vulns
staging.acmecorp.com
71%
Scanning 7 so far
shop.acmecorp.com
100%
Complete 3 vulns
Scan only what you own — always verified
Re-test after every fix — one credit
Data encrypted in transit & at rest
Audit trail for security reviews & compliance
Role-based access for your whole team
1 free credit — no card required

Broad security coverage, one workflow.

PenScan combines multiple security testing engines into a single workflow — deduplicating findings and giving your team one prioritised view of what actually needs attention.

The scanners are the technology. The workflow is the product: run a scan, review findings by severity, assign to your team, fix, and verify — without switching tools or waiting for a consultant.

OWASP ZAP Nuclei Wapiti Dalfox SSLyze Nikto Nmap
Seven security scanners — OWASP ZAP, Nuclei, Wapiti, Dalfox, SSLyze, Nikto, Nmap — feed into PenScan which deduplicates 247 raw findings down to 58 unique issues shown on a unified dashboard

Everything your team needs to find, fix, and prove it.

From first scan to verified fix, PenScan keeps every finding, remediation action, and testing history in one place — so your team always knows where things stand.

Security testing evidence, audit-ready
Security reviews and audits often require documented evidence of testing and remediation. PenScan generates PDF reports with scope, methodology, findings, and remediation steps, and keeps the full scan and remediation history in one place.
Reports and history ready when reviewers ask
Expose the attack surface you didn't know you had
Old subdomains, staging environments, forgotten endpoints — attackers enumerate these before you do. PenScan automatically discovers every asset connected to your domain before the scan begins, so nothing gets missed.
No blind spots, no forgotten corners
Authorised scanning — every time
PenScan confirms domain ownership via DNS verification before any scan runs. You stay legally protected, and no third-party domain can be targeted without proven consent. Every scan is authorised by design.
Legally sound and ethically enforced
Critical issues first — not the noisiest
Every finding is scored by actual severity. Your team sees what matters most at the top, assigns issues for remediation, tracks progress, and confirms fixes — all from one live dashboard. No spreadsheets. No guesswork.
Never lose a critical finding in the noise
Turn a passing scan into a trust signal
Once your site passes a scan, display a verified security badge to customers, prospects, and partners. A concrete signal that your security posture has been independently tested — not just assumed.
Security posture you can show, not just claim
One platform, the right access for every role
Invite your engineering team, security lead, and compliance officers — each with the exact permissions their role requires. All scan data stays isolated within your organisation. No cross-tenant visibility, ever.
Collaborate securely across your whole team

Don't wait for your next penetration test.

Formal penetration tests are valuable — but they're scheduled, periodic, and expensive to repeat. PenScan gives you automated security testing you can run between assessments, whenever your application changes.

Register, verify, scan. You're testing within the hour.

A traditional penetration test takes weeks to arrange — scoping calls, NDAs, and a five-figure invoice before anyone has looked at your code. PenScan removes every one of those steps. Register, verify your domain, and your first scan is running within minutes.

Ownership verified in minutes, not days
Add a DNS TXT record to prove you own your domain. Takes 1–5 minutes. Scanning unlocks immediately after — no back-and-forth with anyone.
Re-scan after every deployment — one credit
When a traditional consultant found a bug, getting it re-checked meant a new scope and a new invoice. With PenScan, re-testing a fixed vulnerability costs one credit.
From $35 — pay only for scans you actually run
No subscription, no annual contract, no minimum seats. Credits are valid for a full year. Security testing that matches your actual usage, not a consultant's day rate.
How does this compare?
Traditional pentest
PenScan
Engagement
Scheduled
Self-service
Testing
Periodic
Repeatable
Retesting
Separate engagement
Run another scan
Findings
Assessment report
Live workflow
Remediation
Separate workflow
Track in platform
Evidence
Assessment deliverables
Reports + history
Best suited for
Deep manual assessment
Continuous testing
PenScan complements formal penetration testing — making security testing easier to repeat between assessments.
app.penscan.org / vulnerabilities
SQL Injection — /api/users  ·  CRITICAL
Discovered
Flagged by OWASP ZAP · Jul 14, 09:32
Open
Assigned
Assigned to @mchen · same day
In progress
Re-scanned
Fix deployed · scan confirmed · Jul 16, 14:05
Verifying
Verified closed
No longer detected · logged to audit trail
Fixed
Discovered → fixed → verified in 2 days · full timeline in audit log

Finding a vulnerability is only the beginning.

PenScan gives your team a workflow to assign findings, track remediation, re-scan and verify that the fix actually worked — with a full timestamped timeline built automatically as you go.

Assign findings to the right engineer
Each vulnerability can be owned by a specific team member directly in the dashboard. No copying findings into Jira manually — track remediation where the work starts.
Re-scan and confirm the fix actually worked
Mark a finding as resolved, trigger a new scan, and see it disappear from the report. One credit. No new contract, no waiting for a consultant's calendar.
Audit trail built as you work
Every action — discovery, assignment, fix, re-verification — is timestamped and logged automatically. When your auditor asks for a remediation timeline, you have one.

Security testing that goes beyond a report.

A PenScan assessment gives your team findings, context, and a workflow to act on them — not just a PDF to file away.

Every vulnerability is scored by severity — Critical, High, Medium, Low — with the specific endpoint affected, the scanner that found it, and step-by-step remediation guidance. Your engineers know exactly what to fix and how.
Prioritised findings
Critical issues surfaced first — not buried in noise
Assign any finding to a team member directly in the dashboard. Mark it fixed, trigger a re-scan, and verify the remediation actually worked. The full timeline — discovered, assigned, fixed, verified — is logged automatically.
Remediation workflow
Assign, fix, re-scan, verify — in one platform
Every scan produces a PDF report with scope, methodology, findings, and remediation steps. Combined with the remediation timeline and audit log, you have documented evidence of your testing programme ready when you need it.
Audit-ready evidence
Reports and history in one place when reviewers ask

Professional security testing for growing businesses.

You don't need a dedicated security team to run professional vulnerability testing. PenScan is built for the teams that keep your product running.

Growing SaaS & Technology Companies
Professional security testing without a dedicated security team
Get the coverage of a professional security assessment without hiring a security engineer or keeping a consultant on retainer. PenScan gives growing companies repeatable security testing at a cost that scales with the business.
Learn more
Engineering Teams
Test applications and infrastructure as you ship
Run automated security assessments after deployments. Vulnerabilities get flagged, assigned, and tracked directly in your workflow — before users encounter them, not after an incident forces your hand.
Learn more
IT & Security Teams
Centralise findings, remediation, and security evidence
One platform for scanning, tracking remediation, and maintaining testing history. When security reviews require documented evidence of testing, your audit trail is already built.
Learn more

Also used by MSSPs managing multiple client organisations. See all capabilities →

Your data is private, isolated, and encrypted.

We hold our own platform to the same standards we help you achieve for yours.

You can only scan what you own
PenScan never scans a target until DNS ownership is cryptographically verified. No third-party domain can be tested without demonstrable control — by design, not policy.
Your data is invisible to other tenants
Multi-tenant architecture ensures complete data isolation. Each organisation's targets, scans, and reports are inaccessible to every other account on the platform.
Role-based access control
Granular RBAC with Owner, Analyst, and Viewer roles. Team members can only access the functionality their role requires — nothing more.
Immutable audit logs
Every scan, target verification, and configuration change is logged with full attribution. Audit logs support security reviews and audit preparation — giving reviewers the evidence trail they need.
Encrypted in transit & at rest
All data is encrypted in transit via TLS 1.3 and at rest. Scan results, credentials, and API tokens are never stored in plaintext.
Authorized scanning by design
Users acknowledge a legal disclaimer before initiating any scan. PenScan's Terms of Service prohibit unauthorized testing, enforced by the ownership verification requirement — not just stated in a checkbox.

Security testing that scales with your business.

Start with the testing you need. Scale when your security programme grows. Every plan includes the full PenScan platform.

Starter
$ 35
per scan · 1 free scan on signup
1 domain
1 seat
All 7 scanners
Technical Assessment PDF
Trust certificates
Get started free
Enterprise
Custom
pricing on request
Unlimited scans
Unlimited domains & seats
Premier customer support
Cyber security expert access
Enterprise-grade SLA
Talk to sales

All plans include the full PenScan platform. No feature tiers, no hidden fees. Compare all features →

Questions we hear before the first scan

No sales call required to get answers.

Yes. PenScan enforces ownership verification via DNS TXT records before any scan begins — you can only scan domains you demonstrably control. Users must also acknowledge a legal disclaimer confirming authorisation before initiating a scan. This makes PenScan both legally sound and ethically enforced, not just policy-stated.
A full combined scan typically completes in 15–30 minutes, depending on the size and complexity of your target. All seven scanners run concurrently — OWASP ZAP accounts for the largest share of scan weight and usually takes the longest. You'll receive a notification when your results are ready.
One credit powers one full combined scan of a single target — all seven scanners running concurrently, results merged and deduplicated into a single report. Starter credits are $35 each with no minimum purchase or subscription required. Passive asset discovery (subdomain enumeration) when you add a new target is always free and never consumes a credit.
Credits are valid for one year from the date of purchase. Buy what you need and use them at your own pace — whether that's this afternoon or several months from now.
Yes — and this is one of PenScan's key advantages over a traditional pentest. With a consultant, getting a fix re-verified meant a new scoping conversation and often a new invoice. With PenScan, mark a finding as fixed, run a new scan, and confirm the remediation actually worked. The audit log captures the full timeline for compliance purposes.
Yes. PenScan supports team collaboration with role-based access control. Invite team members as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access to reports). All roles operate within your organisation's isolated workspace — completely separate from every other account on the platform.
PenScan orchestrates seven industry-standard tools: OWASP ZAP (web application scanning), Nuclei (CVE & misconfiguration templates), Wapiti (SQLi, XSS, CSRF), Nikto (web server fingerprinting), SSLyze (TLS/SSL analysis), Nmap (port & service discovery), and Dalfox (advanced XSS fuzzing). All results are merged and deduplicated into a single prioritised report.
Yes. Each organisation's data is isolated in a multi-tenant architecture — no other user or organisation can access your targets, scans, or vulnerability reports. Data is encrypted in transit (TLS 1.3) and at rest. Scan results and API tokens are never stored in plaintext.

Stop hoping you're secure.
Know that you are.

Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.

1 free credit included  ·  No credit card required  ·  Credits valid for 1 year