Adaptive test planner
Testing adapts to what your application reveals, not a fixed checklist. Every run is auditable.
Product · Inside every pentest
The AI penetration testing pipeline behind every Pentrova engagement. Everything below runs in every engagement. No tier-gating. No add-ons. No noise.
Web App Pentesting and API Pentesting are how you point Pentrova at a target. The capabilities below run inside every engagement: testing adapts to what your application reveals, every finding is verified against the live target, exploits are reproduced inside a sealed sandbox, and confirmed findings are escalated into business-impact paths.
Each card jumps to a section below. Capabilities work together as one engagement — recon, adaptive testing, verification, sandbox PoC, and escalation. None of them are tier-gated; pricing scales on portfolio scope, not pipeline features.
Testing adapts to what your application reveals, not a fixed checklist. Every run is auditable.
Multi-role session replay across reference responses surfaces real privilege bypasses.
Canary-based taint tracking from cookies, window.name, postMessage, hash, search, referrer.
Sanitised RCE, LFI, SSRF, SQLi, XXE, SSTI exploits captured in a sealed sandbox.
Curated escalation catalog plus dynamic LLM chains turn one bug into business impact.
Coverage spans the full application attack surface — recon, injection, access control, business logic, protocol, and post-exploitation.
Every Pentrova engagement is one of two modes. The capabilities below describe how each mode exercises a target.
| Capability | Web App Pentesting | API Pentesting |
|---|---|---|
| Read-only reconnaissance | ||
| Adaptive test planner | ||
| Live-target finding verification | ||
| Sandbox PoC validation Critical / High findings | ||
| Authorization Matrix (multi-role replay) | ||
| Attack chain escalation | ||
| LLM-driven login (SPA / OAuth / SAML / MFA) | — | |
| JS-rendered crawl coverage | — | |
| DOM XSS canary taint tracking Browser-only signal | — | |
| OpenAPI / Postman / GraphQL / Protobuf / WSDL parsers | — | |
| Six auth modes (bearer / API key / basic / OAuth 2 / custom / mTLS) | — |
Capability · Adaptive test planner
Instead of a fixed test list, Pentrova adapts the test plan to what your application reveals — concentrating effort where the attack surface is richest and skipping what does not apply. Every decision is logged with its reasoning so the run is fully auditable after the fact.
Capability · DOM XSS taint
Reflected XSS fuzzing cannot catch DOM-only bugs. Pentrova plants unique canaries in six controlled sources, then instruments the page to follow them through every read and every write until a sink fires. The full sink list is published in the Trust Center.
Canary tokens planted in readable cookies and traced through document.cookie reads.
Canary placed in window.name before navigation and tracked through JS reads.
Controlled postMessage events with canary payloads and targeted origins.
Canaries in location.hash traced through URL parsing and DOM updates.
Canaries in location.search traced through query parsing and DOM writes.
Controlled document.referrer value traced through any JS that reads it.
DOM XSS taint is a browser-side signal and runs only in Web App Pentesting engagements — API Pentesting has no DOM surface.
Capability · Sandbox PoC
For every confirmed Critical or High finding, the sandbox renders a sanitised proof-of-concept exploit. Destructive payloads are swapped for read-only equivalents, customer data is redacted at the boundary, and the resulting artifact replays without Pentrova’s control plane — engineering can re-run the exploit from the audit pack alone.
Capability · Attack chains
Confirmed findings feed the chain resolver. Pentrova ships a curated catalog of escalation chains and adds dynamic LLM-built chains at scan time when the catalog does not already encode a path between two findings. Both kinds are verified against the live target the same way, so the evidence quality is identical.
Impact: Full remote code execution on the application host
Impact: Instance IAM role takeover and downstream cloud access
Impact: Remote code execution on the application worker
Impact: Deterministic remote code execution inside the template engine
Impact: Internal network read and cloud credential exposure
Impact: Account takeover via cross-site request forgery
Capability · Agent library
Pentrova’s agent library is grouped by remit, not by name. Internal agent counts and the exhaustive inventory live behind the product console; the public surface here is the shape of the coverage so you can map it to your application boundaries before the call.
Observe traffic, DOM, headers, and responses without sending exploit payloads. Read-only by design, which is what lets Pentrova run safely against live systems.
Exercise classic injection classes — SQLi, command injection, LFI/RFI, SSTI — with conservative payload budgets and out-of-band confirmation. Every finding is verified before it reaches your queue.
Prove privilege bypasses through cross-role and cross-tenant replay. The Authorization Matrix above is the public face of this family.
Encode application-specific invariants — pricing, workflow order, rate and quota guards. These are findings a generic scanner can never ship because only the application knows what "broken" looks like.
Exercise modern API surfaces — REST, GraphQL, gRPC, SOAP, JSON-RPC, WebSocket — with parser-aware payloads tuned to each transport.
Once a beachhead is confirmed, post-exploitation agents pivot deterministically — cloud metadata reads, file exfiltration, lateral movement — under sandbox guardrails.
Authenticated crawl, JS-rendered DOM coverage, replay-verified findings.
Open Web App Pentesting →OpenAPI, Postman, GraphQL, Protobuf, WSDL across six auth modes.
Open API Pentesting →Findings flow into Slack, Microsoft Teams, Discord, email, and custom webhooks. CI gating templates ship for GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure Pipelines, and Bitbucket.
Open Integrations →Next step
No sales call. No setup fee. Proof in minutes.