Security

Last updated: May 2026

Security is a core part of PentestForge. Our platform is designed to help customers perform authorized vulnerability scanning, AI-assisted security analysis, and report generation while protecting customer data, scan results, and platform access.

Infrastructure

PentestForge is hosted on cloud infrastructure designed for security, reliability, and scalability.

We use technical and organizational safeguards to protect the platform, including:

Data transmitted between users and PentestForge is protected using TLS. Sensitive data is protected using appropriate encryption, access control, and security monitoring measures.

Application Security

PentestForge follows secure development practices and uses security controls throughout the development and deployment process.

Our application security practices include:

We design the platform with reference to recognized security practices, including OWASP guidance for web application security.

Authentication and Access Control

PentestForge accounts are protected through account-based access controls.

Security features may include:

Customers are responsible for keeping account credentials, API keys, and access tokens secure.

API Security

PentestForge API access, where available, is protected using scoped API keys or access tokens.

API usage may be subject to:

API keys should never be shared publicly, committed to source code repositories, exposed in client-side applications, or included in screenshots or logs.

Data Handling

PentestForge processes customer data only as needed to provide the platform and related services.

This may include:

Scan data and reports are logically separated by workspace and account permissions.

Customers can request deletion of their data according to the Privacy Policy and applicable legal, billing, security, and dispute-resolution requirements.

Unless a different retention period applies, scan results and reports may be retained for up to 90 days after subscription expiry, cancellation, or account inactivity, and may then be deleted or anonymized.

Deep Pentest AI Security

Deep Pentest AI is designed to assist with vulnerability analysis, validation, prioritization, and report generation for authorized assets.

To protect customers and reduce misuse risk:

AI-generated outputs may contain inaccuracies, false positives, or false negatives, and should not be treated as a substitute for manual validation.

Responsible Use and Abuse Prevention

PentestForge is intended only for lawful and authorized security testing.

We prohibit:

We may suspend scans, restrict accounts, revoke API keys, or terminate access if we detect activity that appears unauthorized, abusive, harmful, or unlawful.

We may request proof of authorization for submitted assets.

Monitoring and Logging

PentestForge maintains security-relevant logs to help protect the platform and customers.

Logs may include:

Logs are used for security monitoring, fraud prevention, debugging, abuse investigation, service reliability, and compliance with legal obligations.

Payments and Billing Security

Payments are processed by third-party payment providers.

Depending on availability at checkout, PentestForge may use:

PentestForge does not store full payment card numbers, CVV codes, or full card authentication data.

Payment providers process card and payment data according to their own security standards, payment rules, and privacy practices.

Third-Party Providers

PentestForge may use trusted third-party providers for infrastructure, payments, email delivery, analytics, monitoring, security, AI processing, and support operations.

We limit third-party access to the data necessary for the relevant service and apply appropriate security and contractual controls where required.

Compliance

PentestForge is designed with security and privacy principles in mind.

Where applicable, our practices are aligned with:

Formal compliance certifications, audit reports, or enterprise security documentation may be provided only where available and applicable.

For compliance or vendor security review requests, contact:

[email protected]

Vulnerability Reporting

We take security vulnerabilities seriously.

If you discover a vulnerability in PentestForge, please report it to:

[email protected]

Please include:

Please do not:

We aim to acknowledge valid security reports within a reasonable time and prioritize remediation based on severity, impact, exploitability, and affected systems.

Security Contact

For security questions, vulnerability reports, or compliance requests, contact:

[email protected]