v2.0 with bulk AI enhance

The report writer
for pentesters.

From vulnerability discovery to client-ready PDF in minutes. AI fills findings, CVSS, CWE references, and remediation.

Free forever planNo card required5 minute setup
4h 12m
average time saved per report
12,400+
findings written this month
CVSS 3.1
built-in calculator and scoring
6 formats
PDF · DOCX · HTML · MD · CSV · JSON
Write

Type a title.
AI writes the rest.

Description, impact assessment, CVSS 3.1 vector with score, CWE and OWASP references, and concrete remediation steps, filled from just a vulnerability title. Review, tweak, ship.

  • 01
    DescriptionPlain-language explanation of the vulnerability.
  • 02
    ImpactWhat an attacker can do, in business terms.
  • 03
    CVSS 3.1Auto-scored vector string and severity.
  • 04
    ReferencesCWE, OWASP, NIST, automatically attached.
  • 05
    RemediationConcrete steps, not vague advice.
penreport.app / reports / q1-acme / findings / f-024
CriticalCVSS 9.8CWE-89OWASP A03
F-024 / 12
Title
SQL injection in /api/auth/login|
AI filled 5 fields· review below
DescriptionAI

The login endpoint concatenates the email parameter directly into a SQL query without parameterization. An unauthenticated attacker can inject a UNION-based payload to enumerate the entire users table...

CVSS 3.1 vectorAI
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H9.8 / 10
ReferencesAI
CWE-89OWASP A03:2021CAPEC-66
Everything you need

Built for the work that actually matters.

All 19 features
SQL injection in /auth/login|
AI5 fields2.1s

AI finding enhancement

Type a title, get a full finding. CVSS, CWE, OWASP, remediation.

9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 3.1 calculator

Interactive metrics. Score, vector string, and severity live.

PDF and DOCX export

Cover page, executive summary, sorted findings. Print-ready.

SQL injection
Stored XSS
IDOR
SSRF

Reusable templates

Save SQLi, XSS, IDOR. Apply to any report in one click.

penreport.app/r/q1-acme-corp
Read-onlyRevocable

Shareable client links

Read-only links. No account needed. Revoke anytime.

Co.
Pro

White-label branding

Your logo, your colors, your type on every PDF.

Review

Findings, scored
and sorted.

Every finding follows CVSS 3.1. Severity colors are consistent across the editor, the PDF, the share link, and the CSV, so your clients never have to translate.

OWASP WSTGPTESOSSTMMNIST 800-115
Severity breakdown · Q1 Acme12 findings
CriticalCVSS 9.0 to 10.0SQLi · RCE · authentication bypass2
HighCVSS 7.0 to 8.9Stored XSS · IDOR · privilege escalation4
MediumCVSS 4.0 to 6.9Missing headers · reflected XSS3
LowCVSS 0.1 to 3.9Weak ciphers · verbose errors2
InfoCVSS 0.0Best practice gaps1
“Took a five-day reporting workflow down to half a day. The AI gets CVSS right more often than I do.”
MC
M. Carrera
Senior Pentester · Independent consultancy
Pricing

Free until you’re making money.

Full pricing
Free

For individual pentesters getting started.

$0/ month
  • 2 PDF reports / month
  • 5 AI calls / month
  • CVSS 3.1 calculator
  • Unlimited Markdown export
  • Read-only share links
Pro
7-day free trial

For consultants and security firms running engagements every month.

$11.99/ month

7 days free, then $11.99 / month

Start 7-day free trial

Card required · Cancel anytime

  • Unlimited PDF reports
  • 200 AI calls / month
  • Bulk AI enhance
  • DOCX · HTML · CSV · JSON
  • White-label branding
FAQ

Questions,
answered.

Yes, two ways. The free plan gives you 2 PDF reports per month, unlimited Markdown exports, 5 AI calls per month, and the built-in CVSS 3.1 calculator with no credit card. Or start the 7-day Pro free trial to test every Pro feature end-to-end.

Yes. Monthly Pro signups get a 7-day free trial with full access to every Pro feature — bulk AI enhance, DOCX / HTML / CSV / JSON export, white-label branding, 200 AI calls, and the rest. A card is required at signup, but you won't be charged until day 7. Cancel any time before then and you pay nothing.

Claude by Anthropic. It generates descriptions, impact assessments, CVSS 3.1 vectors with scores, CWE and OWASP references, and concrete remediation steps from a finding title. Free users get 5 AI calls per month; Pro users get 200.

Yes. Generate a read-only shareable link, your client sees a clean report view with no install or account required. Revoke the link anytime.

Data is stored in encrypted Postgres. Passwords use Argon2id. Sessions are database-backed, never JWT. We never store your data in plain text.

Free users export PDF and Markdown. Pro unlocks DOCX, HTML, CSV, and JSON. Every format includes a cover page, executive summary, severity breakdown, and color-coded findings.

Yes. Cancel from your billing settings. If you're inside the 7-day trial window, you won't be charged at all. After the trial, you keep Pro access until the end of your current billing period.

Yes. Pay annually and save 30%, $100 per year instead of $143.88. Toggle the period on the pricing page to see the annual price. The 7-day free trial is available on monthly billing.

Stop formatting. Start shipping.

Your next report should take 30 minutes, not three days. Generate your first one free; it’ll take you about five.

Create your first report

Free forever · no card required