Pentest-Tools.com
Pentest-Tools.com is a bootstrapped, Romania-based SaaS platform that consolidates 25+ penetration testing and vulnerability scanning tools for security consultants, enterprise security teams, and MSSPs, serving 2,000+ teams across 119+ countries via tiered subscriptions and AWS/Azure Marketplace listings.
- Company typePrivate
- Founded2017
- HeadquartersBucharest, Romania
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Pentest-Tools.com does
Pentest-Tools.com (legally PentestTools S.A.) is a Romania-domiciled, bootstrapped SaaS provider of a cloud-based penetration testing and vulnerability assessment platform, founded in 2017 by professional penetration testers. The platform consolidates 25+ security testing tools across reconnaissance (Subdomain Finder, Port Scanner, Google Hacking, Website Recon, WAF Detector, People Hunter, URL Fuzzer), vulnerability scanning (Network Scanner, Website Scanner, API Scanner, SSL/TLS Scanner, Cloud Scanner, Kubernetes Scanner, WordPress/Drupal/Joomla/SharePoint scanners, Password Auditor), and exploitation (Sniper Auto-Exploiter, SQLi Exploiter, XSS Exploiter, Subdomain Takeover, HTTP Request Logger). The proprietary scanning engine detects 17,175+ vulnerabilities, ships 191 exploit modules, and is benchmarked 1st in remote detection accuracy across 128 environments against Qualys, Nessus, and OpenVAS. The platform executes 6.3 million vulnerability scans and 1.6 million scheduled scans annually, and is used by 2,000+ security teams across 119+ countries.
The company monetizes via three subscription tiers priced at $95 (NetSec), $140 (WebNetSec), and $190 (Pentest Suite) per month, with asset-based quotas that scale from 5 to 500 unique network hosts, plus optional add-ons for internal network scanning and branded reports. A free tier with limited features and a 7-day trial drive a product-led growth motion, layered with enterprise custom pricing for organizations holding 500+ assets or advanced compliance needs (ISO 27001, NIS2, SOC 2, DORA, CRA). Distribution is direct self-serve complemented by AWS Marketplace and Azure Marketplace listings, with integration into Jira, Slack, Microsoft Teams, Discord, Vanta, Nucleus Security, GitHub Actions, and an MCP Server for AI clients. Customer segments include independent security consultants, internal enterprise security teams, and managed security service providers (MSSPs), with named enterprise users including Vodafone, Starbucks, Orange, Generali, Accenture, and Mercedes-Benz do Brasil.
The company has been bootstrapped since founding, holds ISO 27001 certification and GDPR compliance, and received Deloitte Fast 50 CE 2022, SC Awards Europe 2022 (Best Vulnerability Management Solution, highly commended), and Deloitte Fast 500 EMEA 2023 recognition. Recurring strategic activity in 2025-2026 centers on AI feature integration (ML Classifier, Flowmapper, AI-Assisted Authentication, MCP Server), enterprise compliance positioning, and rapid CVE-specific tooling such as the April 2026 cPanel authentication bypass scanner.
Pentest-Tools.com firmographics
Firmographics- Name
- Pentest-Tools.com
- Legal name
- PentestTools S.A.
- Website
- https://pentest-tools.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Pentest-Tools.com is a bootstrapped, Romania-based SaaS platform that consolidates 25+ penetration testing and vulnerability scanning tools for security consultants, enterprise security teams, and MSSPs, serving 2,000+ teams across 119+ countries via tiered subscriptions and AWS/Azure Marketplace listings.
- Ownership category
- akta.pro rank
Pentest-Tools.com industry classification
Industry- Product category
- Penetration Testing & Vulnerability Management Software
- NAICS
- Software Publishers (513210), Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Penetration Testing & Red Teaming (BPAKAHAF)
Keywords
Where Pentest-Tools.com is headquartered
LocationHeadquarters
- HQ city
- Bucharest
- HQ country
- Romania
- HQ region
- Europe
Offices1 record
Markets served
Pentest-Tools.com business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription SaaS - NetSec: Network-focused vulnerability assessment plan starting at $95/month (billed monthly) or $95/month equivalent (billed annually at 10 months). Includes network scanning, cloud scanning, password auditing, and reconnaissance tools with limited web/API scanning.
- Subscription SaaS - WebNetSec: Web application and API vulnerability assessment plan starting at $140/month (billed monthly) or $140/month equivalent (billed annually). Includes everything in NetSec plus DAST scanning, authenticated web scans, API scanning, and CMS scanning (WordPress, Drupal, Joomla, SharePoint).
- Subscription SaaS - Pentest Suite: Full-cycle pentesting plan starting at $190/month (billed monthly) or $190/month equivalent (billed annually). Includes everything in WebNetSec plus automatic CVE exploitation (Sniper), SQL Injection & XSS exploiters, pentest report generator (DOCX), and Burp Suite findings import.
- Optional Add-ons: Internal network scanning and branded reports & emails available as optional add-ons for additional fees.
- Custom Enterprise Plans: Organizations with 500+ assets or enterprise-level security needs can request custom pricing with invoice-based billing options.
- Marketplace Sales: Sales through AWS and Azure Marketplaces for streamlined enterprise procurement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | NetSec - Network vulnerability assessment starting at $95/month |
| Subscription | Monthly | WebNetSec - Web app & API vulnerability assessment starting at $140/month |
| Subscription | Monthly | Pentest Suite - Full-cycle pentesting starting at $190/month |
| Freemium | Monthly | Free Edition - Limited access with basic scanning |
| Subscription | Monthly | Internal Network Scanning Add-on |
| Subscription | Monthly | Branded Reports & Emails Add-on |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels9 records
Pentest-Tools.com product offering
Product offeringCore offering
Pentest-Tools.com operates a cloud-based SaaS platform that bundles 25+ offensive security tools covering reconnaissance, vulnerability scanning, and exploitation. It delivers network, web application, API, cloud, and CMS scanning with ML-powered false positive reduction and automated CVE exploitation, packaged for security teams and consultants.
Product overview
Pentest-Tools.com is a unified cloud-based penetration testing and vulnerability assessment SaaS platform providing 25+ security testing tools in a single product. The platform organizes tools across three main categories: reconnaissance tools (Subdomain Finder, Port Scanner, Domain Finder, Virtual Hosts discovery, Google Hacking, Website Recon, WAF Detector, People Hunter, URL Fuzzer), vulnerability scanners (Network Scanner, Website Scanner, API Scanner, SSL/TLS Scanner, Password Auditor, Cloud Scanner, Kubernetes Scanner, WordPress Scanner, Drupal Scanner, Joomla Scanner, SharePoint Scanner), and exploitation tools (Sniper Auto-Exploiter, SQLi Exploiter, XSS Exploiter, HTTP Request Logger, Subdomain Takeover). The platform is offered through three pricing tiers: NetSec (network-focused, starting at $95/month), WebNetSec (web and API testing, starting at $140/month), and Pentest Suite (full-cycle pentesting with exploitation and reporting, starting at $190/month). Additional capabilities include Pentest Robots for workflow automation, Pentest Reporting for automated report generation, Vulnerability & Exploit Database with 17,000+ detections, and MCP Server for AI assistant integration.
Differentiator
Problem solved
Functional benefit
Products and services
- Network Scanner Network vulnerability scanner combining 4 detection engines to discover 17,000+ CVEs, identify open ports, running services, and operating systems. Ranked 1st in remote detection accuracy in benchmarks against Qualys, Nessus, and OpenVAS.
- Website Scanner DAST web application vulnerability scanner covering beyond OWASP Top 10, with authenticated scanning, ML classifier for false positive reduction, and benchmark-proven detection accuracy.
- API Scanner Scanner for REST and GraphQL APIs that identifies vulnerabilities in API endpoints and configurations.
- Sniper: Auto-Exploiter Automatic CVE exploitation tool with 191 exploit modules that validates risk and extracts evidence for critical vulnerabilities.
- SQLi Exploiter Exploitation tool for safely confirming SQL injection vulnerabilities with proof-of-concept evidence, supporting error-based, blind, time-based, and union-based SQLi.
- XSS Exploiter Exploitation tool for validating cross-site scripting (XSS) vulnerabilities with real JavaScript payloads and confirmed execution evidence.
- Subdomain Takeover Tool for detecting and exploiting subdomain takeover vulnerabilities where misconfigured DNS records allow attackers to claim unused domains.
- Subdomain Finder Reconnaissance tool for discovering subdomains owned by a target to map exposed assets and attack surface.
- Port Scanner Network reconnaissance tool using Nmap to discover open ports and services on target systems, supporting TCP and UDP scanning.
- SSL/TLS Scanner Scanner for identifying SSL/TLS vulnerabilities, misconfigurations, and weak cryptographic settings in server certificates and protocols.
- WordPress Scanner Specialized scanner for detecting WordPress-specific vulnerabilities including plugin, theme, and core weaknesses, powered by WPScan technology.
Quantifiable outcome
- Ranked 1st in remote detection accuracy across 128 environments in benchmarks against Qualys, Nessus, OpenVAS, and more
- +5 more outcomes
Companies that use Pentest-Tools.com
Customer profileNamed customers7 records
Segments3 records
Ideal customer profiles3 records
Pentest-Tools.com technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability7 records
Feature9 records
Pentest-Tools.com partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and minor.
- JiracoreNative integration with Jira for ticketing and findings management, enabling security teams to automate ticket creation and track remediation workflows.
- Microsoft TeamscoreIntegration with Microsoft Teams for notifications and team collaboration on security findings and scan results.
- SlackcoreSlack integration for real-time alerts and collaboration on vulnerability findings and scan results.
- VantacoreCompliance and risk management integration with Vanta for continuous compliance monitoring and evidence collection.
- Nucleus SecuritycoreIntegration with Nucleus Security for vulnerability management and risk prioritization across security tools.
- WebhookscoreCustom webhook support for integrating scan results and alerts into any workflow or system.
- GitHub ActionscoreCI/CD integration via GitHub Actions for automated security testing in development pipelines.
- Pentest GroundminorRelated platform for hands-on penetration testing practice environments, complementing the tool ecosystem.
- LinodecoreInfrastructure hosted on Linode, whose security practices strengthen the product's security posture. Linode is under Akamai Technologies.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Pentest-Tools.com competitors and assessment
Company assessmentEmerging players
- HostedScan: SaaS vulnerability scanner aggregating multiple open-source engines; targets small security teams with low-cost scanning — overlaps with Pentest-Tools.com's SMB and free-tier motion.
- HackerOne: Offensive security platform combining bug bounty, pentest as a service, and attack surface management. Adjacent competitor for security budgets focused on proof-of-risk validation, overlapping with Pentest-Tools.com's Sniper auto-exploiter.
Direct peers
- Intruder: Cloud-based vulnerability scanner targeting internal security teams and MSPs with continuous scanning, similar PLG motion, and comparable pricing tiers to Pentest-Tools.com's SMB offering.
- Invicti (Netsparker): Direct DAST competitor offering automated web application and API security scanning with proof-based scanning. Targets the same security teams and pentesters with similar pricing and SaaS delivery.
- Acunetix: Long-standing commercial DAST and network vulnerability scanner sold as SaaS and on-prem. Overlaps heavily with Pentest-Tools.com's Website Scanner and Network Scanner offerings.
- Detectify: SaaS-based attack surface monitoring and DAST platform built by ethical hackers. Competes directly with Pentest-Tools.com on external attack surface discovery and continuous web scanning.
Broad incumbents
- Qualys VMDR: Enterprise vulnerability management, detection, and response platform explicitly cited as a benchmark competitor for Pentest-Tools.com's Network Scanner. Operates at much larger scale with broader enterprise footprint.
- Tenable (Nessus): Enterprise vulnerability management leader and Nessus vendor; cited as a benchmark competitor. Broader platform including cloud security, identity security, and exposure management.
- Rapid7 InsightVM: Enterprise vulnerability management and security analytics platform with broader SecOps portfolio. Competes for the same internal security team budgets that Pentest-Tools.com serves.
- Snyk: Developer security platform with DAST/SCA capabilities (Snyk API & Web) plus broader application security portfolio. Competes for the same developer and security team budgets with deeper CI/CD integration.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Pentest-Tools.com social profiles
Digital presencePentest-Tools.com compliance and trust
Trust signalCompliance3 records
Pentest-Tools.com financial estimates
Financial estimateRevenue estimate
Valuation estimate
Pentest-Tools.com leadership team
Management profileNumber of profiles
Pentest-Tools.com funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Pentest-Tools.com M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Pentest-Tools.com
What does Pentest-Tools.com do?
Pentest-Tools.com operates a cloud-based SaaS platform that bundles 25+ offensive security tools covering reconnaissance, vulnerability scanning, and exploitation. It delivers network, web application, API, cloud, and CMS scanning with ML-powered false positive reduction and automated CVE exploitation, packaged for security teams and consultants.
Is Pentest-Tools.com a public or private company?
Pentest-Tools.com is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Pentest-Tools.com founded?
Pentest-Tools.com was founded in 2017. It employs 51 to 100 people.
Where is Pentest-Tools.com based?
Pentest-Tools.com is headquartered in Bucharest, Romania, in the Europe region.
How does Pentest-Tools.com make money?
Six revenue lines are on record. Subscription SaaS - NetSec is the primary driver. The others are subscription SaaS - WebNetSec, subscription SaaS - Pentest Suite, optional Add-ons, custom Enterprise Plans and marketplace Sales.
Who are Pentest-Tools.com's main competitors?
Emerging players on record are HostedScan and HackerOne. Direct peers are Intruder, Invicti (Netsparker), Acunetix and Detectify. Broad incumbents are Qualys VMDR, Tenable (Nessus), Rapid7 InsightVM and Snyk.
Does Pentest-Tools.com have an API?
Yes. Pentest-Tools.com provides REST API access that enables developers and security teams to programmatically trigger scans, monitor scan status, export results (JSON, CSV), and integrate vulnerability scanning capabilities into CI/CD pipelines and custom workflows. API access is included in all paid plans (NetSec, WebNetSec, Pentest Suite) and available to Free plan users. The platform also offers MCP (Model Context Protocol) server integration, which connects the account to MCP-compatible AI clients, requiring an API key with explicit approval required for every tool call. Developer documentation is at pentest-tools.com/docs/api-reference.
What industry is Pentest-Tools.com in?
Pentest-Tools.com's product category is Penetration Testing & Vulnerability Management Software. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 513210 and its SIC code is 7372.