What you get
A Penti subscription is registered to an organization: the vendor names its packages but does not publish the commercial terms, so ask the seller which tier is actually paid for and how many exploit runs per month you get — that governs both coverage and run frequency. Ask which surfaces are inside the agreed scope: web and APIs, mobile apps, network and VPN, cloud, IoT devices — scope is set at kickoff and does not widen on its own. Establish the formal side separately: agentic testing is only launched against assets whose ownership is confirmed on behalf of the organization. The seller states the next charge date and the remaining period at delivery.
About the service
Penetration testing as a service built on agentic AI trained by practising pentesters: the AI first analyses your application and infrastructure to scope the engagement, then continuously hunts for vulnerabilities and tries to exploit them, while human specialists review the findings and add attack scenarios of their own. Coverage spans web applications and APIs, mobile apps, internal and external networks, cloud environments and IoT devices; it looks for the routine issues — SQL injection, cross-site scripting, broken authentication, insecure APIs, misconfigurations — and for the things that usually need a human: business logic flaws and chained exploits. Alongside scheduled agentic runs there are separate recurring checks: open-source scans weekly, network and vulnerability scans monthly. The output is a prioritised remediation roadmap, data flow analysis, retesting at no extra charge, and audit-ready reports for SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIST and CMMC, downloadable as PDF. On-premise deployment is available, along with support over Slack, Teams or WhatsApp and an assigned success team. The vendor does name its packages, which differ by the number of exploit runs per month, but it does not publish the commercial terms — confirm the contents with the seller.