Architecture
Architecture Overview
TurboPentest is a Next.js application deployed on Azure App Service. It orchestrates 14 containerized security tools via Azure Container Instances, with multi-agent AI analysis by Paladin, powered by Anthropic's Claude API across a three-model tier (Claude Sonnet 4.6, Claude Haiku 4.5, and Claude Opus 4.7).
High-Level Architecture
Execution Flow
- Domain verification - User proves ownership via DNS TXT record
- Credit allocation - System checks credit availability and assigns the appropriate tier (Recon, Audit-Ready, Threat-Hunt, or Adversarial-Depth)
- Phase 1 launch - Up to 14 tool containers start on Azure Container Instances in two waves: wave 1 (Port Scanner, Sub Hunter, Secret Scanner, Code Scanner, Dep Scanner, Net Scanner) runs first, then wave 2 web tools (Web Probe, WAF Detect, Server Audit, Web Scanner, Vuln Scanner, Security Checks, TLS Analyzer, Enumerator) launch against the web targets Port Scanner discovers. The 3 white-box tools only run when source code is provided
- Tool execution - Each tool runs against the target with defined timeouts and resource limits
- Callback - Tools report completion via HMAC-signed webhook to the app
- Paladin multi-agent analysis (Phase 2) - Specialist AI agents ingest Phase 1 outputs and analyze findings in parallel, with the number and type of agents determined by the credit tier
- Continuity tracking - If the target has been previously pentested, previous findings are automatically re-evaluated and tracked as new, confirmed, or retest_confirmed
- Report generation - PDF report and a signed attestation are generated; the report and attestation are SHA-256 hashed and issued a public verification link
- Integrations - User notified via email (Mailgun), Slack webhook, Jira ticket creation, and HubSpot CRM sync
- Attestation anchoring (roadmap) - Attestation hashes are batched into a Merkle tree by a daily job; on-chain anchoring to Base L2 is planned and not yet live
Credit Tiers and Agent Allocation
| Tier | Agents | Duration | Specialist Coverage |
|---|---|---|---|
| Recon | 1 | 30 min | Generalist |
| Audit-Ready | 4 | 60 min | Web, API, Infrastructure (+ supervisor) |
| Threat-Hunt | ~10 | 120 min | All 9 specialist domains (+ supervisor + synthesis) |
| Adversarial-Depth | ~20 | 240 min | 9 breadth specialists + depth duplicates + exploit chain + verification |
Key Properties
- Isolated execution - Each tool runs in its own container with no shared state
- Ephemeral - Containers are destroyed after the pentest completes
- Parallel - Phase 1 tools run concurrently in two waves (web tools wait for Port Scanner's target discovery), then Phase 2 agents run in parallel
- Multi-agent - Specialist AI agents analyze findings in their domain of expertise
- Continuity - Finding fingerprints track vulnerability status across pentests
- Tamper-evident - Every attestation is SHA-256 hashed and served through a public verification link; on-chain anchoring to Base L2 is on the roadmap
Deep Dives
- Infrastructure - Azure services, data flow, and deployment
- Paladin AI - How the multi-agent agentic pentesting system works
- Security - Container isolation, data handling, and compliance
Integrations API
Manage your Slack and Jira integrations through the TurboPentest API, listing configured integrations with sensitive tokens masked in every response.
Infrastructure
The Azure services, data flow, and deployment architecture behind TurboPentest - how requests, tool execution, and findings move through the system.