Self-hosted by default
PentestFlow ships as a Docker Compose stack you run inside your own network. There is no required SaaS tier, and core workflows do not need outbound internet access. You control where evidence and reports live.
Trust center
PentestFlow is built around a simple principle: your engagement data should stay inside your network. Here is what that means in practice, and what we are honest about not yet having.
PentestFlow ships as a Docker Compose stack you run inside your own network. There is no required SaaS tier, and core workflows do not need outbound internet access. You control where evidence and reports live.
The Community edition uses local AI via Ollama. Cloud AI providers (Gemini, OpenAI, DeepSeek) are available on Pro and Enterprise, and they are explicitly opt-in. No prompts or evidence are sent to third parties unless you configure a provider.
Pro and Enterprise editions ship with JWT-based authentication and bcrypt-hashed credentials. Enterprise adds full RBAC across projects, methodologies, and reports, plus SSO and SAML integrations with your IdP.
Command execution is governed by an allowlist, blocklist, or unrestricted policy that you set in Settings. The backend validates dangerous patterns and pins the working directory for each project to keep runs reproducible and contained.
Enterprise records every meaningful action with actor, target, and timestamp. Audit data is exportable as CSV and is retained according to your tenant configuration.
API endpoints are rate-limited per route (for example, command execution and AI calls have lower per-minute caps than general API traffic) to reduce blast radius from misconfigured plugins or runaway scripts.
Because the product is self-hosted, the list below describes optional components you may run alongside PentestFlow. None are required for core functionality.
PostgreSQL
Primary database when configured.
Ollama
Optional local AI runtime.
Google Gemini, OpenAI, DeepSeek
Optional cloud AI providers (opt-in, Pro and Enterprise only).
Shodan, VirusTotal
Optional external intelligence (opt-in, Pro and Enterprise only).
Found a vulnerability? Email us at yabetsworkaferahu@gmail.com. We acknowledge reports within two business days and credit researchers in our advisories unless you prefer to remain anonymous.