
pentone
AI-Native VAPT & Security Engagement Platform
Hey Indie Hackers! π

If you work in cybersecurity, consulting, or software development, you know the dirty secret of penetration testing: pentesters spend 40β60% of their total engagement time manually writing reports instead of actually testing.
Even though the report is the primary deliverable clients see and pay for, creating it is usually a nightmare: copying scanner output line-by-line, manually recalculating CVSS scores, and wrestling Word templates late into the night.
We built Pentone to solve this exact problem without forcing agencies into rigid, hardcoded software layouts.
π‘ Your Custom Template is the Source of Truth
Most tools force you into static app templates or rely on brittle scripts that break when your document layout changes. Pentone takes a fundamentally different approach: your handmade DOCX design template is the single source of truth.
Upload your agency's custom Word report or a template once. Pentone's AI engine automatically maps raw scan data into your exact document layout, typography, and styling with nearly zero on-boarding friction or learning curves.
βοΈ What Pentone Does Under the Hood
Multi-Scanner Ingestion & Deduplication: Feed in raw scan outputs from Nessus, Burp Suite, Acunetix, or Nmap. Pentone consolidates assets across CIDR ranges and deduplicates findings across past jobs so the same vulnerability is never logged twice.
AI Finding Drafting: Context-aware multi-LLM routing (Azure AI Foundry, Vertex AI, OpenAI, Claude) with prompt caching to draft vulnerability descriptions, technical impacts, and remediation guidance slashing LLM costs by 60β80%.
Google Docs-Style Live Collaboration: Multiple pentesters can work on the same report simultaneously with real-time CRDT co-editing, inline commenting, and team @mentions.
Central Knowledge Base: Store, search, and reuse pre-vetted vulnerability findings across projects and client entities.
Remediation & Retest Tracker: Monitor vulnerability fix progress, manage retest lifecycles, assign tasks, and track remediation deadlines post-engagement.
12+ Risk Scoring Frameworks: Native engines for CVSS v3.1/v4.0, OWASP Risk Rating, DREAD, EPSS, STRIDE, and MITRE ATT&CK.
Enterprise Data Sovereignty: Bring Your Own Database (BYODB) and Bring Your Own AI Key (BYOK) so client vulnerability data stays strictly on your infrastructure.
π¬ Weβd Love Your Feedback!
We just opened up Pentone for security consultancies, MSSPs, and enterprise red teams.
Weβd love for the IH community to roast our landing page, test out the workflow, and give feedback on our feature set!
π Check it out at https://pentone.io
How does your team currently handle custom report generation and vulnerability management? Drop a comment below!
About
Pentesting teams and security consultancies spend up to 40-60% of their total engagement time manually copy-pasting scanner outputs and fighting Word document formatting

1 Comment
The custom-template approach is the part that stands out. Letting an agency keep its existing report format while automating the work underneath removes a major adoption barrier that rigid reporting platforms often create.