TurboPentest Documentation
Welcome to TurboPentest - agentic AI pentests for SaaS companies. Run 14 professional security tools against your domains, get actionable findings with remediation guidance, and verify fixes with automatic retest validation on your next pentest.
Quick links
- Quick Start - Run your first pentest in 5 minutes
- CI/CD Integration - Add continuous security to your pipeline
- API Reference - Automate pentests via REST API
- Tools & Coverage - See all 14 tools and what they test
Who is this for?
TurboPentest is built for developers and DevOps engineers who need professional penetration testing without the cost and lead time of manual engagements. Use it for:
- One-off pentests - Verify your security posture before a release or audit
- Continuous coverage - Integrate into CI/CD for automated testing on every deploy
- Compliance - Generate PDF reports and attestation letters mapped to SOC 2, PCI-DSS, HIPAA, and ISO 27001
How it works
- Verify your domain - Prove ownership via DNS TXT record
- Start a pentest - Via the dashboard, API, or CI/CD pipeline
- Get results - Findings with severity, proof of exploit, and remediation steps
- Fix and retest - Run a new pentest; each previous finding is re-checked live against fresh evidence and its continuity status is updated (
new,confirmed, orretest_confirmed)
Beyond one-off pentests, TurboPentest also offers Cloud EASM - authenticated multi-cloud asset discovery that maps your external attack surface - and a dedicated AI/LLM security specialist that tests AI-powered features against the OWASP LLM Top 10.