You authorize the work
PenThreatAI is for authorized security testing. You decide the target, the scope, and when local tools may run.
PenThreatAI
How we process data, where agent code runs, and how billing works — then start free when you're ready.
See how the platform worksFour non-negotiables before the vendor list. Authorized work, deletion you control, payments that never touch our servers, and a commercial product — not a bait-and-switch repo.
PenThreatAI is for authorized security testing. You decide the target, the scope, and when local tools may run.
Delete tasks, sandboxes, shared links, or your whole account from Settings. Canceling removes paid access at period end.
Payment details never hit our servers. Billing, invoices, and portal access live under Settings → Account.
PenThreatAI is a commercial product. This page is the public record of how we process data — not a public repo dump.
How it works
One engagement loop. You stay in control of scope and what remains after the work is done.
Authorized target, prompts, uploads, and whether cloud or local tools may run — all your call.
Messages, files, sandbox output, and search queries go to the providers required to run the agent.
Wipe tasks, sandboxes, shares, or the account. Paid access ends with the billing period when you cancel.
Inventory
Depending on how you use PenThreatAI, the service may process the following.
Task requests route through OpenRouter to the provider behind the model you select — Anthropic, Google, DeepSeek, Moonshot AI, xAI, and others. Your prompt, relevant conversation context, and tool results go to that provider to generate a response.
Web search uses Perplexity; page retrieval uses Jina AI. Message content is screened by OpenAI for moderation. Training use varies by provider — see Subprocessors, not a blanket guarantee from us.
By default, terminal and browser actions run in an isolated E2B cloud sandbox. Delete sandboxes anytime from Settings → Data controls.
Local execution runs on your machine with your privileges and no isolation — use it only on machines dedicated to testing. Setup lives on Download.
Regions
Placement follows where you connect from — not an account toggle.
Agent runs, new cloud sandboxes, and new file uploads place by connection location. Europe uses our EU region (Frankfurt, eu-central-1). North America uses the nearest US region. A VPN or travel changes it.
Sandboxes and files created before regional placement stay where they were until you delete them. The primary database, AI providers, search, moderation, auth, billing, and analytics are not regional — see the Privacy Policy for international processing.
Stripe processes payments; card details never reach our servers. Manage or cancel in Settings → Account. Deleting your account cancels any active subscription.
Extra Usage is prepaid with a monthly cap you control. Flip it on in Settings → Extra Usage when a plan budget runs out — charges draw from your balance, not an open tab.
Vendors
These services process data on our behalf to run PenThreatAI.
| Provider | Purpose | Data categories |
|---|---|---|
| OpenRouter | Routes task requests to third-party AI model providers | Prompts, conversation context, file content, tool output |
| OpenAI | Content moderation | Message content |
| Perplexity | Web search performed by the agent | Search queries from agent runs |
| Jina AI | Webpage content retrieval for the agent | URLs and retrieved page content |
| E2B | Cloud sandboxes (US, or EU for connections from Europe) | Commands, command output, files inside the sandbox |
| Convex | Primary application database | Account data, tasks, messages, files, settings |
| Amazon Web Services (S3) | File storage (US regions, or eu-central-1 for connections from Europe) | Uploaded files |
| Upstash / Redis | Rate limiting and response stream resumption | Transient identifiers and streaming state |
| WorkOS | Authentication and account management | Email, name, sessions, MFA enrollment |
| Stripe | Payments and subscription billing | Billing contact and payment details (held by Stripe) |
| PostHog | Product analytics and error tracking | Usage events and diagnostic data |
| Trigger.dev | Background execution of long-running agent tasks (US regions, or eu-central-1 for connections from Europe) | Task payloads including conversation context |
| Vercel | Application hosting | Request data processed by the web application |
| Intercom | In-app customer support messaging | Account identity and support conversation content |
Reports
Found a security issue in PenThreatAI? Report it through in-app support chat. We review good-faith reports. We don't run a paid bug bounty program at this time.
Assurance
PenThreatAI doesn't currently hold SOC 2, ISO 27001, or other third-party certifications. The service is offered as described in our Privacy Policy and Terms of Service. We'll update this page as our compliance program develops.
Subscribe
Trust the stack. Free to try. Ultra from $200/mo when you need headroom — no card required to start.