Pencheff

The all-in-one security platform

Every attack surface, covered.

  • DAST
  • SAST
  • VAPT
  • API Security
  • OAuth & OIDC
  • GraphQL
  • IDOR
  • Business Logic
  • LLM Red Team
  • Prompt Injection
  • Agent Swarm
  • AI Governance
  • AI-SPM
  • SCA + CVE
  • SBOM
  • Secrets Detection
  • IaC Misconfig
  • Container Scan
  • KSPM
  • KIEM
  • CWPP
  • ASPM
  • Cloud Metadata
  • Subdomain Takeover
  • OWASP Top 10
  • SOC 2 / ISO 27001
  • PCI-DSS
  • NIST 800-53
  • HIPAA
Free during beta·No credit card required·MIT-licensed self-host·Signed + notarised Mac app
Pencheff dashboard
Pencheff schedules
Pencheff target detail

Mapped to the frameworks your auditors recognise.

OWASP Top 10 (2021)SOC 2 CC6 / CC7PCI-DSS 4.0NIST 800-53ISO 27001 : 2022HIPAA Security RuleCWE Top 25CVSS v3.1OWASP Top 10 (2021)SOC 2 CC6 / CC7PCI-DSS 4.0NIST 800-53ISO 27001 : 2022HIPAA Security RuleCWE Top 25CVSS v3.1
01.The methodology

A discipline, not a scan.

Pencheff is the all-in-one security platform — built around three orthogonal commitments: methodology, coverage, and reporting. Each is enforced by the engine, not the operator.

01 Methodology

An assessment, not a scan.

Pencheff follows an adversarial methodology modelled on manual penetration testing — reconnaissance, authenticated coverage, business-logic probing, and exploit chaining — delivered with the consistency of automation.

Read the procedure
02 Coverage

Forty-nine instruments. One verdict.

Injection, access control, authentication, cryptography, client-side, infrastructure, cloud, and API — examined with Pencheff's first-party probes. Auxiliary tools are optional and operator-managed.

See the instruments
03 Reporting

Audit-ready, the moment it finishes.

Every assessment yields a formal report with executive summary, letter grade, and evidence — mapped to OWASP Top 10, SOC 2, PCI-DSS, NIST 800-53, ISO 27001, and HIPAA categories.

Inspect a dossier
02.The adversarial cycle

Five phases, in lockstep.

Each engagement traces the same adversarial path — from passive reconnaissance to multi-step exploit chaining — so that two assessments of the same target, six months apart, are directly comparable.

PHASE 01 / V

Reconnaissance

Passive enumeration: subdomains, DNS, certificate transparency, public artefacts, technology fingerprint.

PHASE 02 / V

Surface Mapping

Authenticated and unauthenticated crawls, API discovery, endpoint inventory, parameter cataloguing.

PHASE 03 / V

Probing

Forty-nine instruments fired against the surface — injection, access control, OAuth, cloud, business logic.

PHASE 04 / V

Verification

Each finding re-fired with crafted payloads. Request and response evidence captured. False positives discarded.

PHASE 05 / V

Exploit Chaining

Single findings composed into multi-step attacks: SSRF → metadata, XSS → session theft, IDOR → privilege escalation.

03.The Pencheff battery

A library of probes, each authored by hand.

Forty-nine first-party instruments cover the modern attack surface — injection, access control, authentication, cryptography, client-side, infrastructure, cloud, and API — and can be composed with repo scanning, threat models, compliance rollups, SBOM output, and LLM red team workflows. Auxiliary tools (nmap, sqlmap, nuclei, ffuf, hydra, nikto) remain optional and operator-managed.

0

First-party probes — exhaustively catalogued, individually verified, weighted by severity. Re-examination of any finding is unlimited on every plan.

1 / 49
Composing the Pencheff Battery
R-01
Passive Reconnaissance
Recon
R-02
Active Surface Discovery
Recon
R-03
API Discovery
Recon
R-04
Subdomain & Cert Transparency
Recon
I-07
SQL Injection
Injection
I-09
Command Injection
Injection
I-11
NoSQL & LDAP Injection
Injection
I-14
Template Injection (SSTI)
Injection
X-01
XML External Entity
Injection
A-03
Broken Authentication
Auth
A-05
Session Management Flaws
Auth
A-08
OAuth & OIDC Flaws
Auth
A-12
MFA Bypass Probing
Auth
Z-04
Broken Access Control
Authz
Z-11
Insecure Direct Object Reference
Authz
Z-18
Privilege Escalation Paths
Authz
C-02
Reflected & Stored XSS
Client
C-05
DOM-based XSS
Client
C-09
CSRF & SameSite
Client
C-12
Open Redirect
Client
S-06
Server-Side Request Forgery
Server
S-08
Deserialization
Server
F-03
File Upload & Path Traversal
File
F-07
Mass Assignment
Server
K-02
Cloud Metadata Exposure
Cloud
K-05
S3 / Bucket Misconfiguration
Cloud
K-09
IAM Policy Audit
Cloud
B-04
Business-Logic Probing
Business
B-08
Race Condition Probing
Business
Y-08
Subdomain Takeover
Infrastructure
Y-12
TLS & Cipher Audit
Infrastructure
W-01
WAF Bypass Discovery
Infrastructure
Σ-01
Repo scanning (Semgrep + OSV)
Supply chain
Σ-02
SBOM generation (SPDX/CycloneDX)
Supply chain
Σ-04
Dependency CVE Audit
Supply chain
M-01
Threat model (STRIDE/DREAD)
Model
L-01
LLM red team (OWASP LLM Top 10)
AI
L-03
Prompt Injection Probing
AI
L-06
Agent swarm execution
AI
04.The surface map

Six surfaces, one finding stream.

Web DAST, code analysis, dependency intelligence, infrastructure posture, AI red team, and cloud surface checks all normalise into the same finding schema — so an engineer triaging injection and an auditor reviewing compliance are reading the same record.

W
Web & API (DAST)
  • SQL, NoSQL, command, SSTI, XXE, SSRF, LDAP, path traversal, deserialization
  • Reflected, stored, and DOM XSS · CSRF · CORS · clickjacking · cache poisoning
  • Sessions, cookies, JWT, OAuth/OIDC, MFA bypass, brute force, IDOR, privilege escalation
  • GraphQL, WebSockets, REST, OpenAPI, SPA browser crawls, business logic
  • Intercepting proxy · parameter fuzzer · OAST callbacks · replayable evidence
See coverage →
S
Code & SAST
  • Semgrep OSS · Bandit · gosec · Brakeman · ESLint-security · tree-sitter rules
  • Python · Go · Rails · JS/TS · Solidity · Kotlin · Swift · Scala · Dart · Lua
  • gitleaks · YARA indicators · suspicious payload patterns · backdoor detection
  • Auto-fix PRs — deterministic patches, SARIF, GitHub checks, reviewer-ready diffs
See coverage →
D
SCA & Supply Chain
  • OSV · NVD · GHSA · RustSec · GoVulnDB advisories
  • EPSS · KEV signal · SSVC triage · reachability mapping · exploitability enrichment
  • SPDX 2.3 · CycloneDX 1.5 SBOM output (optional Syft for higher fidelity)
  • License obligations · transitive dependency tracking
See coverage →
I
IaC & Containers
  • Trivy config · Checkov · tfsec · Kubesec · Hadolint
  • Terraform · Kubernetes · Helm · Dockerfile · ARM · CloudFormation
  • Container image scanning · registry gates · admission webhooks
  • Kubernetes policy enforcement · deployment blocking
See coverage →
Ω
AI & LLM Red Team
  • Prompt injection · insecure output · training data exposure · model DoS
  • Plugin abuse · supply chain · excessive agency · overreliance · model theft
  • Roleplay · payload splitting · obfuscation · encoding · jailbreak corpora
  • Chat completions · HTTP · LiteLLM · MCP tools · hosted chatbots
  • Attacker-LLM loops · regression suites · token accounting · judge scoring
See coverage →
K
Cloud & Infrastructure
  • Passive recon: subdomains, DNS, certificates, public artefacts, tech fingerprint
  • TLS/HTTPS headers · subdomain takeover signals · certificate expiry
  • Cloud metadata exposure · S3/GCS/Azure blob public access indicators
  • ASM: discovered services, exposed ports, drift monitoring
See coverage →
05.AI & LLM security

Red team your models before attackers do.

Pencheff covers the full OWASP LLM Top 10 (2025) with curated payload libraries, attacker-driven loops, and judge-backed scoring. Agentic testing probes tool calls, memory, planners, and swarm workflows. The Sentry guardrail enforces policy at runtime.

OWASP LLM Top 10 · 2025
LLM01Prompt Injection
LLM02Insecure Output Handling
LLM03Training Data Poisoning
LLM04Model Denial of Service
LLM05Supply Chain Vulnerabilities
LLM06Sensitive Information Disclosure
LLM07Insecure Plugin Design
LLM08Excessive Agency
LLM09Overreliance
LLM10Model Theft
R

LLM Red Team

Roleplay, payload splitting, obfuscation, encoding variants, jailbreak corpora, and regression suites against any OpenAI-compatible endpoint. Attacker-LLM loops and judge-backed scoring when configured.

LLM red team →
A

Agentic Testing

Tool authorization abuse, memory and context attacks, planner hijacking, cross-session leakage, retrieval poisoning, and swarm orchestration probes for agent-based products.

Agentic tests →
G

Guardrails & Governance

Sentry runtime guardrail for prompt, response, tool, and PII policy checks. Maps to OWASP LLM, MITRE ATLAS, NIST AI RMF, EU AI Act, ISO/IEC 42001, and SOC 2.

Guardrails →
06.The procedure

Four steps, every engagement.

From registration to remediation, the same procedure governs every assessment — so that the engineer who runs it, the operator who reviews it, and the auditor who reads it are all working from the same record.

Step 01 — Register

Provide a target.

Provide a target URL and, optionally, credentials for authenticated coverage. All secrets are encrypted at rest.

Step 02 — Assess

Commission the engagement.

Commission a quick, standard, or deep assessment. Progress streams live; stages are logged for review.

Step 03 — Review

Triage with evidence.

Triage findings with full request/response evidence. Re-examine any finding after remediation with a single action.

Step 04 — Remediate

Close the file.

Download a formal DOCX or PDF report, dispatch to ticketing, and close out with verified evidence.

0
First-party instruments per assessment.
0/6
Compliance frameworks mapped to every finding — OWASP, PCI, SOC 2, NIST, ISO, HIPAA.
0min
From account creation to first commissioned assessment. No credit card.
Re-examinations per finding, per workspace, per engagement — on every plan, free forever.
07.Subscriptions

Free during beta. Automated remediation lands on Pro.

Pencheff is in open beta. Every feature is unlocked at the Free tier today — DAST, SAST, IaC, container scanning, compliance reporting, the lot. Pro adds automated remediation that doesn’t just find vulnerabilities, it fixes them with verified pull requests. Team is for organisations that need unlimited scale and dedicated support.

Most popular

Pro

₹499/mo · $5.99

Pencheff doesn't just find vulnerabilities — it fixes them. The Expert model, a generous monthly allowance, and verified pull requests.

  • 20 security scans / month
  • 40 AI auto-fixes / month (Expert model)
  • Automated remediation — opens a single PR that fixes every triaged finding
  • DAST exploitation — proves impact with verified PoCs, not scanner noise
  • SAST auto-patching — semantic, reviewer-friendly diffs grounded in scanner evidence
  • AI Triage 2.0 — per-finding walkthroughs and grading
  • Priority correspondence and a private Slack channel
For organisations

Team

Customtalk to us

When security is a shared responsibility. Unlimited workspaces, unlimited seats, dedicated support, and the full Pro feature set at general availability.

  • Unlimited workspaces, seats, and registered targets
  • Branded reporting & custom compliance mappings
  • Single sign-on (SAML / OIDC)
  • Dedicated Slack correspondence channel
  • Priority vulnerability response & onboarding
  • Full automated remediation pipeline at general availability with SLAs
  • Custom data residency & deployment options
08.Deliverables

Contents of the formal report.

Two dossiers, issued together. Engineering receives the technical record; audit and executive readers receive the framework-mapped summary. Bound by a single grade and a single date of issue.

For Engineering
Card A

The technical dossier.

  1. Request & response evidence for every finding.
  2. CVSS 3.1 score and vector.
  3. CWE classification.
  4. Remediation guidance with illustrative code.
  5. On-demand re-examination to confirm a fix.
For Executive
Card B

The executive dossier.

  1. Executive summary with letter grade and severity counts.
  2. Findings mapped to OWASP Top 10 (2021) categories.
  3. SOC 2 CC6 / CC7 control mapping.
  4. PCI-DSS 4.0, NIST 800-53, ISO 27001:2022, HIPAA mapping.
  5. Audit-ready DOCX and PDF.
09a.Compliance coverage

Every finding, framework-mapped.

Pencheff normalises every finding against application security standards, audit frameworks, and AI governance requirements — so your engineers, auditors, and compliance officers work from the same report.

Application Security

Every confirmed finding maps to one or more application security control frameworks.

  • OWASP Top 10 (2021)
  • OWASP API Security Top 10
  • OWASP LLM Top 10 (2025)
  • CWE Top 25
Audit & Compliance

Dossiers are issued with compliance rollup tables ready for auditor review.

  • SOC 2 CC6 / CC7
  • PCI-DSS 4.0
  • NIST 800-53 Rev 5
  • ISO 27001:2022
  • HIPAA Security Rule
  • GDPR Art. 32
AI Governance

AI assessment output maps to governance frameworks for LLM and agentic products.

  • OWASP LLM Top 10
  • MITRE ATLAS
  • NIST AI RMF
  • EU AI Act
  • ISO/IEC 42001
09b.Integrations

Plugs into every workflow you use.

Slack, Jira, GitHub, SARIF, webhooks, and more — findings route into your existing toolchain automatically. No new dashboard to babysit.

GitHubSCM
GitLabSCM
JiraTicketing
LinearTicketing
SlackNotify
TeamsNotify
DiscordNotify
Google ChatNotify
PagerDutyIncident
OpsgenieIncident
SplunkSIEM
DatadogObservability
OpenTelemetryObservability
GitHub ActionsCI/CD
GitLab CICI/CD
JenkinsCI/CD
SARIFCI/CD
WebhooksCustom
S

SaaS Application

Dashboards, reports, multi-workspace, integrations, and schedules. Sign up and run a full assessment in under three minutes.

Get started →
D

Pencheff Studio (macOS)

Native Mac client. Same workspace as the web app, plus on-device repo scanning, Downloads + macOS posture monitors, and an agentic remediation runner that keeps source on your machine.

Get started →
/

CLI & CI/CD

Run deterministic checks in pipelines. Emit SARIF, trigger GitHub checks, and route findings into the platform from any CI system.

Get started →

MCP Server

Expose scanning and security automation as tools to compatible AI agents. Invoke assessments and fetch findings inside AI workflows.

Get started →
H

Self-Hosting

Operate the full stack inside your boundary via Docker Compose. Control data residency, tune scanning, and meet internal security policy.

Get started →
10.Comparison

Subscription tiers in detail.

ProvisionFree$0 · during betaProComing soonTeamCustom
Web DAST (OWASP Top 10, exploitation-grade)···
Repo scanning — Semgrep OSS + OSV advisories···
IaC + container scanning (Trivy, Checkov)···
Authenticated assessments (encrypted credentials)···
Compliance mapping (OWASP · PCI · SOC 2 · NIST · ISO · HIPAA)···
Formal DOCX & PDF reports··Branded
Automated remediation — fix-PR for every finding··
DAST exploitation — verified PoCs··
SAST Auto-Patching (semantic diffs)··
Continuous scan-on-push loop··
Single sign-on (SAML / OIDC)·
Dedicated Slack channel & priority response·
Custom data residency & deployment·
11.Enquiries

Frequently considered questions.

Direct answers — on authorisation, scope, plans, audit acceptance, self-hosting, and credential handling. For anything else, write to us.

Yes. Every shipped feature - URL scanning (DAST), repo scanning (Semgrep OSS + OSV advisories), IaC scanning (Trivy config + Checkov), SBOM generation, threat models (STRIDE/DREAD), compliance mapping, and reporting - is unlocked at $0 while we're in open beta. No card, no trial expiry, no feature gating. Pro and Team are post-beta plans for organisations that want the automated remediation pipeline and dedicated support.

Pro is centred on automated remediation that doesn't just find vulnerabilities - it fixes them. The remediation pipeline opens a single PR that resolves every triaged finding. DAST exploitation proves impact with verified PoCs. SAST auto-patching writes semantic, reviewer-friendly diffs grounded in scanner evidence. Pro is announced as coming soon; Free covers everything else today.

Pencheff is for applications you own or have been granted written permission to assess. It is an instrument of assurance, not a means of unauthorised access. Please direct it only at systems within your mandate.

One complete engagement against a target: reconnaissance, infrastructure, injection, client-side, authentication, authorisation, advanced web, API, business logic, cloud, file handling, websocket, subdomain takeover, and exploit chaining. Re-examination of individual findings is unlimited.

Quick profile: 2-5 minutes. Standard: 10-25 minutes. Deep: 30-90 minutes, contingent on application breadth.

Yes. DOCX and PDF reports include evidence-backed mapping to OWASP Top 10 (2021), PCI-DSS 4.0, NIST 800-53, SOC 2 (CC6/CC7), ISO 27001:2022, and HIPAA Security Rule - accepted by auditors as evidentiary material.

Yes. Pencheff is distributed as a Docker Compose stack under an MIT licence. Refer to the repository documentation for installation.

Credentials are encrypted at rest with Fernet (AES-128 in CBC mode with HMAC-SHA256). Removing a target removes its credentials immediately.

Begin

Commission your first assessment.

A complimentary assessment takes under three minutes to commission and under thirty to complete. No credit card, no sales call.