Self-service penetration testing · starts today

Know your vulnerabilities
before attackers do.

PenScan runs seven industry-standard security scanners on your website and delivers a single, prioritised report with step-by-step remediation guidance — results in minutes, not weeks.

2 free credits
No credit card
Credits valid 1 year
Up and running in minutes
01
Register Free account, no card needed
02
Add & verify your website Paste your URL, quick DNS check
03
Run your first scan All 7 scanners, one ranked report
app.penscan.org / dashboard
Main
Dashboard
Targets
Scans 1
Security
Vulnerabilities 24
Reports
Security Dashboard
Acme Corp · 4 targets · Last scan: 2h ago
Open Vulns
24
↑ 3 new
Scans / mo
11
Active
Assets
47
Found
Risk score
C+
↑ Up
api.acmecorp.com
100%
Complete 12 vulns
staging.acmecorp.com
71%
Scanning 7 so far
shop.acmecorp.com
100%
Complete 3 vulns
Scan only what you own — always verified
Re-test after every fix — one credit
Data encrypted in transit & at rest
Audit trail for SOC 2 & ISO 27001
Role-based access for your whole team
2 free credits — no card required

One scan. Seven security engines.

Running a single scanner leaves blind spots. Running seven separately creates alert fatigue.

PenScan combines the industry's leading security scanners into one intelligent workflow, automatically merging duplicate findings into a single prioritised list of vulnerabilities that actually need your attention.

OWASP ZAP Nuclei Wapiti Dalfox SSLyze Nikto Nmap
Seven scanners — OWASP ZAP, Nuclei, Wapiti, Dalfox, SSLyze, Nikto, Nmap — feed into PenScan, which deduplicates 247 raw findings down to 58 unique issues

Security testing that closes vulnerabilities — and satisfies auditors.

From SOC 2 to ISO 27001, compliance frameworks demand documented proof of regular penetration testing. PenScan delivers both: real vulnerability findings and audit-ready reports in a single workflow.

Audit-ready evidence for SOC 2 and ISO 27001
SOC 2 Type II and ISO 27001 both require documented evidence of regular penetration testing. PenScan generates compliance-ready PDF reports complete with scope, methodology, findings, and remediation steps — exactly what auditors ask for.
Turn every scan into audit evidence
Expose the attack surface you didn't know you had
Old subdomains, staging environments, forgotten endpoints — attackers enumerate these before you do. PenScan automatically discovers every asset connected to your domain before the scan begins, so nothing gets missed.
No blind spots, no forgotten corners
Authorised scanning — every time
PenScan confirms domain ownership via DNS verification before any scan runs. You stay legally protected, and no third-party domain can be targeted without proven consent. Every scan is authorised by design.
Legally sound and ethically enforced
Critical issues first — not the noisiest
Every finding is scored by actual severity. Your team sees what matters most at the top, assigns issues for remediation, tracks progress, and confirms fixes — all from one live dashboard. No spreadsheets. No guesswork.
Never lose a critical finding in the noise
Turn a passing scan into a trust signal
Once your site passes a scan, display a verified security badge to customers, prospects, and partners. A concrete signal that your security posture has been independently tested — not just assumed.
Security posture you can show, not just claim
One platform, the right access for every role
Invite your engineering team, security lead, and compliance officers — each with the exact permissions their role requires. All scan data stays isolated within your organisation. No cross-tenant visibility, ever.
Collaborate securely across your whole team

Traditional pentests take weeks to arrange. PenScan starts today.

Most penetration tests are designed for annual compliance checkboxes — not teams that ship code every sprint. PenScan replaces the consultant cycle with self-service security testing you can run whenever you need it.

Register, verify, scan. You're testing within the hour.

A traditional penetration test takes weeks to arrange — scoping calls, NDAs, and a five-figure invoice before anyone has looked at your code. PenScan removes every one of those steps. Register, verify your domain, and your first scan is running within minutes.

Ownership verified in minutes, not days
Add a DNS TXT record to prove you own your domain. Takes 1–5 minutes. Scanning unlocks immediately after — no back-and-forth with anyone.
Re-scan after every deployment — one credit
When a traditional consultant found a bug, getting it re-checked meant a new scope and a new invoice. With PenScan, re-testing a fixed vulnerability costs one credit.
From $35 — pay only for scans you actually run
No subscription, no annual contract, no minimum seats. Credits are valid for a full year. Security testing that matches your actual usage, not a consultant's day rate.
How does this compare?
Traditional pentest
PenScan
Time to first scan
3–6 weeks
Today
Cost
$5,000+
From $35
Report format
Static PDF
Live dashboard
Re-test after fix
New contract
1 credit
Who you talk to
Consultants
Nobody
No setup fee. No contract. 2 free credits included.
app.penscan.org / vulnerabilities
SQL Injection — /api/users  ·  CRITICAL
Discovered
Flagged by OWASP ZAP · Jul 14, 09:32
Open
Assigned
Assigned to @mchen · same day
In progress
Re-scanned
Fix deployed · scan confirmed · Jul 16, 14:05
Verifying
Verified closed
No longer detected · logged to audit trail
Fixed
Discovered → fixed → verified in 2 days · full timeline in audit log

Finding a vulnerability is only half the job.

Once a scan surfaces an issue, PenScan gives your team a workflow to own it — assign it, mark it fixed, re-scan to confirm, and log the full timeline automatically. When your auditor asks for evidence, it's already waiting.

Assign findings to the right engineer
Each vulnerability can be owned by a specific team member directly in the dashboard. No copying findings into Jira manually — track remediation where the work starts.
Re-scan and confirm the fix actually worked
Mark a finding as resolved, trigger a new scan, and see it disappear from the report. One credit. No new contract, no waiting for a consultant's calendar.
Audit trail built as you work
Every action — discovery, assignment, fix, re-verification — is timestamped and logged automatically. When your auditor asks for a remediation timeline, you have one.

What teams find on their first scan

Real accounts from engineering leads, security teams, and compliance officers.

"We found a critical SQL injection in our API on the very first scan — an issue that had been in production for months. The report was specific enough to hand directly to our engineering lead, and we had it patched and re-verified within the same week. One scan, one critical fix closed."
JW
James Whitfield
CTO, FinStack Technologies
"We manage security assessments for 14 client organisations. PenScan's multi-tenant setup let us onboard all of them in a single day — something that would have taken weeks with individual tooling. The combined scanner output consistently finds issues that any single tool would miss."
SN
Sarah Novak
Head of Security, CyberShield MSSP
"Our SOC 2 auditor asked for penetration test evidence. We pulled scan reports, remediation timelines, and the full audit log from PenScan in under an hour. That's work that would have cost us $15,000 and six weeks with an external firm. The trust certificates are a bonus our customers actually notice."
TB
Tom Barrett
VP Engineering, Cloudnine SaaS

Built for teams that can't wait weeks for a pentest

Whether you're a solo founder moving fast or an MSSP managing dozens of clients, PenScan fits how you work.

Engineering Teams
Catch vulnerabilities before they reach production
Run automated scans after each deployment. Security issues get flagged and assigned before users see them — not after an incident forces your hand.
Learn more
SaaS Startups
A full security posture without the dedicated hire
Get the coverage of a penetration test without hiring a security engineer or keeping a consultant on retainer. PenScan gives early-stage companies the same testing rigour as a mature security organisation — at a fraction of the cost.
Learn more
Compliance & Audit
Satisfy your auditor without the six-week scramble
Continuous scan history, remediation timelines, and immutable audit logs give your auditors everything they need. Stop scrambling to gather evidence at audit time.
Learn more
Managed Security Providers
Run security testing for multiple clients from one dashboard
PenScan's multi-tenant architecture lets MSSPs manage scans across dozens of client organisations without context-switching. Deliver professional assessment reports at scale — no extra tooling.
Learn more
E-commerce & Fintech
Protect customer data before regulators ask about it
Regular security testing is a regulatory expectation for businesses handling payments and personal data. PenScan makes it continuous — and gives you trust certificates to show customers their data is being protected.
Learn more
Security Researchers
Automate reconnaissance on your own infrastructure
Combine passive asset discovery with active scanning across multiple targets systematically. Credit-based pricing means you pay only for what you actually use — no subscription, no monthly minimum.
View pricing

Your data is private, isolated, and encrypted.

We hold our own platform to the same standards we help you achieve for yours.

You can only scan what you own
PenScan never scans a target until DNS ownership is cryptographically verified. No third-party domain can be tested without demonstrable control — by design, not policy.
Your data is invisible to other tenants
Multi-tenant architecture ensures complete data isolation. Each organisation's targets, scans, and reports are inaccessible to every other account on the platform.
Role-based access control
Granular RBAC with Owner, Analyst, and Viewer roles. Team members can only access the functionality their role requires — nothing more.
Immutable audit logs
Every scan, target verification, and configuration change is logged with full attribution. Audit logs support compliance requirements and give auditors the evidence trail they ask for.
Encrypted in transit & at rest
All data is encrypted in transit via TLS 1.3 and at rest. Scan results, credentials, and API tokens are never stored in plaintext.
Legally compliant by design
Users acknowledge a legal disclaimer before initiating any scan. PenScan's Terms of Service prohibit unauthorized testing, enforced by the ownership verification requirement — not just stated in a checkbox.

Three plans. No surprises.

Start free, scale when you need to. Every plan includes the full platform — no feature tiers, no upsells.

Starter
$ 35
per scan · 2 free scans on signup
1 domain
1 seat
All 7 scanners
Technical Assessment PDF
Trust certificates
Get started free
Enterprise
Custom
pricing on request
Unlimited scans
Unlimited domains & seats
Premier customer support
Cyber security expert access
Enterprise-grade SLA
Talk to sales

All plans include the full PenScan platform. No feature tiers, no hidden fees. Compare all features →

Questions we hear before the first scan

No sales call required to get answers.

Yes. PenScan enforces ownership verification via DNS TXT records before any scan begins — you can only scan domains you demonstrably control. Users must also acknowledge a legal disclaimer confirming authorisation before initiating a scan. This makes PenScan both legally sound and ethically enforced, not just policy-stated.
A full combined scan typically completes in 15–30 minutes, depending on the size and complexity of your target. All seven scanners run concurrently — OWASP ZAP accounts for the largest share of scan weight and usually takes the longest. You'll receive a notification when your results are ready.
One credit powers one full combined scan of a single target — all seven scanners running concurrently, results merged and deduplicated into a single report. Starter credits are $35 each with no minimum purchase or subscription required. Passive asset discovery (subdomain enumeration) when you add a new target is always free and never consumes a credit.
Credits are valid for one year from the date of purchase. Buy what you need and use them at your own pace — whether that's this afternoon or several months from now.
Yes — and this is one of PenScan's key advantages over a traditional pentest. With a consultant, getting a fix re-verified meant a new scoping conversation and often a new invoice. With PenScan, mark a finding as fixed, run a new scan, and confirm the remediation actually worked. The audit log captures the full timeline for compliance purposes.
Yes. PenScan supports team collaboration with role-based access control. Invite team members as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access to reports). All roles operate within your organisation's isolated workspace — completely separate from every other account on the platform.
PenScan orchestrates seven industry-standard tools: OWASP ZAP (web application scanning), Nuclei (CVE & misconfiguration templates), Wapiti (SQLi, XSS, CSRF), Nikto (web server fingerprinting), SSLyze (TLS/SSL analysis), Nmap (port & service discovery), and Dalfox (advanced XSS fuzzing). All results are merged and deduplicated into a single prioritised report.
Yes. Each organisation's data is isolated in a multi-tenant architecture — no other user or organisation can access your targets, scans, or vulnerability reports. Data is encrypted in transit (TLS 1.3) and at rest. Scan results and API tokens are never stored in plaintext.

Stop hoping you're secure.
Know that you are.

Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.

2 free credits included  ·  No credit card required  ·  Credits valid for 1 year