Security
Last updated: May 2026
Security is a core part of PentestForge. Our platform is designed to help customers perform authorized vulnerability scanning, AI-assisted security analysis, and report generation while protecting customer data, scan results, and platform access.
Infrastructure
PentestForge is hosted on cloud infrastructure designed for security, reliability, and scalability.
We use technical and organizational safeguards to protect the platform, including:
- encrypted HTTPS connections;
- restricted administrative access;
- network-level access controls;
- isolated service components where applicable;
- monitoring and logging for security-relevant events;
- regular updates and patching of platform dependencies and infrastructure components.
Data transmitted between users and PentestForge is protected using TLS. Sensitive data is protected using appropriate encryption, access control, and security monitoring measures.
Application Security
PentestForge follows secure development practices and uses security controls throughout the development and deployment process.
Our application security practices include:
- security review of material code changes;
- dependency monitoring and vulnerability patching;
- input validation and output handling controls;
- protection against common web application risks;
- access control checks for workspace, asset, scan, and report data;
- logging of security-relevant platform activity;
- review of platform behavior for abuse and unauthorized use.
We design the platform with reference to recognized security practices, including OWASP guidance for web application security.
Authentication and Access Control
PentestForge accounts are protected through account-based access controls.
Security features may include:
- password-based authentication;
- session protection;
- support for two-factor authentication where available;
- scoped API keys;
- API key rotation;
- workspace-level access separation;
- authentication event logging;
- administrative access restrictions.
Customers are responsible for keeping account credentials, API keys, and access tokens secure.
API Security
PentestForge API access, where available, is protected using scoped API keys or access tokens.
API usage may be subject to:
- rate limits;
- access restrictions;
- workspace permissions;
- abuse detection;
- audit logging;
- key revocation or rotation when compromise is suspected.
API keys should never be shared publicly, committed to source code repositories, exposed in client-side applications, or included in screenshots or logs.
Data Handling
PentestForge processes customer data only as needed to provide the platform and related services.
This may include:
- account data;
- billing and subscription metadata;
- authorized assets submitted by the customer;
- scan configuration;
- vulnerability findings;
- scan logs;
- generated reports;
- Deep Pentest AI inputs and outputs;
- technical support communications.
Scan data and reports are logically separated by workspace and account permissions.
Customers can request deletion of their data according to the Privacy Policy and applicable legal, billing, security, and dispute-resolution requirements.
Unless a different retention period applies, scan results and reports may be retained for up to 90 days after subscription expiry, cancellation, or account inactivity, and may then be deleted or anonymized.
Deep Pentest AI Security
Deep Pentest AI is designed to assist with vulnerability analysis, validation, prioritization, and report generation for authorized assets.
To protect customers and reduce misuse risk:
- AI-assisted analysis is tied to customer workspaces and authorized scan context;
- usage may be monitored for abuse prevention and platform security;
- generated outputs should be reviewed by the customer before being used for remediation, disclosure, or business decisions;
- customers should not submit unnecessary secrets, passwords, private keys, regulated data, or confidential third-party information unless strictly necessary and legally permitted.
AI-generated outputs may contain inaccuracies, false positives, or false negatives, and should not be treated as a substitute for manual validation.
Responsible Use and Abuse Prevention
PentestForge is intended only for lawful and authorized security testing.
We prohibit:
- scanning assets without authorization;
- attacking third-party systems;
- denial-of-service activity;
- credential theft;
- phishing;
- malware activity;
- unauthorized exploitation;
- attempts to bypass platform limits or security controls.
We may suspend scans, restrict accounts, revoke API keys, or terminate access if we detect activity that appears unauthorized, abusive, harmful, or unlawful.
We may request proof of authorization for submitted assets.
Monitoring and Logging
PentestForge maintains security-relevant logs to help protect the platform and customers.
Logs may include:
- authentication events;
- API activity;
- scan activity metadata;
- administrative actions;
- failed login attempts;
- suspicious activity indicators;
- abuse prevention events;
- payment and account security events.
Logs are used for security monitoring, fraud prevention, debugging, abuse investigation, service reliability, and compliance with legal obligations.
Payments and Billing Security
Payments are processed by third-party payment providers.
Depending on availability at checkout, PentestForge may use:
- Stripe;
- Monobank acquiring / plata by mono.
PentestForge does not store full payment card numbers, CVV codes, or full card authentication data.
Payment providers process card and payment data according to their own security standards, payment rules, and privacy practices.
Third-Party Providers
PentestForge may use trusted third-party providers for infrastructure, payments, email delivery, analytics, monitoring, security, AI processing, and support operations.
We limit third-party access to the data necessary for the relevant service and apply appropriate security and contractual controls where required.
Compliance
PentestForge is designed with security and privacy principles in mind.
Where applicable, our practices are aligned with:
- GDPR-related privacy principles;
- secure software development practices;
- access control and least-privilege principles;
- security logging and monitoring practices;
- data minimization and retention controls.
Formal compliance certifications, audit reports, or enterprise security documentation may be provided only where available and applicable.
For compliance or vendor security review requests, contact:
Vulnerability Reporting
We take security vulnerabilities seriously.
If you discover a vulnerability in PentestForge, please report it to:
Please include:
- a clear description of the issue;
- affected URL, endpoint, or feature;
- reproduction steps;
- potential impact;
- screenshots or proof-of-concept details where appropriate;
- your contact information.
Please do not:
- access, modify, or delete other users' data;
- disrupt the service;
- perform denial-of-service testing;
- publicly disclose the issue before we have had a reasonable opportunity to investigate;
- use automated high-volume scanning against the platform without permission.
We aim to acknowledge valid security reports within a reasonable time and prioritize remediation based on severity, impact, exploitability, and affected systems.
Security Contact
For security questions, vulnerability reports, or compliance requests, contact:
