---
title: "Architecture Overview"
description: "How TurboPentest orchestrates 14 containerized security tools and multi-agent Paladin AI analysis on Azure App Service and Azure Container Instances."
canonical: https://turbopentest.com/docs/architecture
source: "TurboPentest Docs"
---

# Architecture Overview

TurboPentest is a Next.js application deployed on Azure App Service. It orchestrates 14 containerized security tools via Azure Container Instances, with multi-agent AI analysis by Paladin, powered by Anthropic's Claude API across a three-model tier (Claude Sonnet 4.6, Claude Haiku 4.5, and Claude Opus 4.7).

## High-Level Architecture

<svg viewBox="0 0 800 800" fill="none" xmlns="http://www.w3.org/2000/svg" style={{width: '100%', height: 'auto', maxWidth: '800px', margin: '1.5rem auto', display: 'block'}}>
  
  <rect width="800" height="800" rx="12" fill="#0A0A0A"/>

  
  <rect x="280" y="24" width="240" height="44" rx="8" fill="#1A1A1A" stroke="#E7F900" strokeWidth="2"/>
  <text x="400" y="51" textAnchor="middle" fill="#E7F900" fontSize="14" fontWeight="bold" fontFamily="sans-serif">Target Domain</text>

  
  <line x1="400" y1="68" x2="400" y2="92" stroke="#9CA3AF" strokeWidth="2"/>
  <polygon points="400,100 394,90 406,90" fill="#9CA3AF"/>

  
  <rect x="120" y="104" width="340" height="50" rx="8" fill="#1A1A1A" stroke="#E7F900" strokeWidth="2"/>
  <text x="290" y="126" textAnchor="middle" fill="#FFFFFF" fontSize="13" fontWeight="bold" fontFamily="sans-serif">TurboPentest Web App</text>
  <text x="290" y="144" textAnchor="middle" fill="#9CA3AF" fontSize="10" fontFamily="sans-serif">Next.js 15 · Azure App Service</text>

  <rect x="490" y="104" width="180" height="50" rx="8" fill="#1A1A1A" stroke="#9CA3AF" strokeWidth="1.5"/>
  <text x="580" y="126" textAnchor="middle" fill="#FFFFFF" fontSize="12" fontWeight="bold" fontFamily="sans-serif">Neon PostgreSQL</text>
  <text x="580" y="142" textAnchor="middle" fill="#9CA3AF" fontSize="10" fontFamily="sans-serif">Prisma ORM · Serverless</text>

  
  <line x1="460" y1="129" x2="490" y2="129" stroke="#9CA3AF" strokeWidth="1.5" strokeDasharray="4 3"/>

  
  <line x1="400" y1="154" x2="400" y2="182" stroke="#9CA3AF" strokeWidth="2"/>
  <polygon points="400,190 394,180 406,180" fill="#9CA3AF"/>

  
  <rect x="40" y="194" width="720" height="160" rx="10" fill="#111111" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.5"/>
  <text x="400" y="218" textAnchor="middle" fill="#E7F900" fontSize="12" fontWeight="bold" fontFamily="sans-serif">PHASE 1 - Tool Execution</text>
  <text x="400" y="234" textAnchor="middle" fill="#9CA3AF" fontSize="10" fontFamily="sans-serif">Azure Container Instances · Up to 14 Tools in 2 Waves</text>

  
  <rect x="60" y="248" width="330" height="90" rx="6" fill="#1A1A1A" stroke="#555555" strokeWidth="1"/>
  <text x="225" y="268" textAnchor="middle" fill="#FFFFFF" fontSize="11" fontWeight="bold" fontFamily="sans-serif">11 Black Box Tools</text>
  <text x="225" y="286" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">Port Scanner · Server Audit · Web Scanner · Vuln Scanner · Security Checks</text>
  <text x="225" y="300" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">TLS Analyzer · Sub Hunter · Web Probe · Enumerator · WAF Detect · Net Scanner</text>
  <text x="225" y="328" textAnchor="middle" fill="#555555" fontSize="9" fontFamily="sans-serif">Isolated containers · Dedicated CPU/memory</text>

  
  <rect x="410" y="248" width="330" height="90" rx="6" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.4"/>
  <text x="575" y="268" textAnchor="middle" fill="#E7F900" fontSize="11" fontWeight="bold" fontFamily="sans-serif">3 White Box Tools</text>
  <text x="575" y="286" textAnchor="middle" fill="#E7F900" fontSize="9" fontFamily="sans-serif" opacity="0.7">Secret Scanner · Code Scanner · Dep Scanner</text>
  <text x="575" y="308" textAnchor="middle" fill="#555555" fontSize="9" fontFamily="sans-serif">Requires source code access</text>

  
  <line x1="400" y1="354" x2="400" y2="382" stroke="#9CA3AF" strokeWidth="2"/>
  <polygon points="400,390 394,380 406,380" fill="#9CA3AF"/>

  
  <rect x="260" y="394" width="280" height="44" rx="8" fill="#1A1A1A" stroke="#9CA3AF" strokeWidth="1.5"/>
  <text x="400" y="414" textAnchor="middle" fill="#FFFFFF" fontSize="12" fontWeight="bold" fontFamily="sans-serif">Azure Blob Storage</text>
  <text x="400" y="430" textAnchor="middle" fill="#9CA3AF" fontSize="10" fontFamily="sans-serif">Tool outputs · Reports · Attestations</text>

  
  <line x1="400" y1="438" x2="400" y2="466" stroke="#9CA3AF" strokeWidth="2"/>
  <polygon points="400,474 394,464 406,464" fill="#9CA3AF"/>

  
  <rect x="40" y="478" width="720" height="155" rx="10" fill="#111111" stroke="#E7F900" strokeWidth="2"/>
  <text x="400" y="500" textAnchor="middle" fill="#E7F900" fontSize="12" fontWeight="bold" fontFamily="sans-serif">PHASE 2 - Paladin Multi-Agent Analysis</text>
  <text x="400" y="516" textAnchor="middle" fill="#9CA3AF" fontSize="10" fontFamily="sans-serif">Claude Opus 4.7 / Sonnet 4.6 / Haiku 4.5 · Specialist Swarm</text>

  
  <rect x="86" y="530" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="160" y="548" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Web App</text>

  <rect x="246" y="530" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="320" y="548" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">API Security</text>

  <rect x="406" y="530" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="480" y="548" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Infrastructure</text>

  <rect x="566" y="530" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="640" y="548" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Code Analysis</text>

  
  <rect x="86" y="564" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="160" y="582" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Crypto/TLS</text>

  <rect x="246" y="564" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="320" y="582" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Auth/Access</text>

  <rect x="406" y="564" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="480" y="582" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Business Logic</text>

  <rect x="566" y="564" width="148" height="26" rx="4" fill="#1A1A1A" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.6"/>
  <text x="640" y="582" textAnchor="middle" fill="#E7F900" fontSize="9" fontWeight="bold" fontFamily="sans-serif">Supply Chain</text>

  
  <text x="400" y="600" textAnchor="middle" fill="#555555" fontSize="9" fontFamily="sans-serif">Threat-Hunt tier adds a 9th specialist: AI/LLM Security Analyst</text>
  <text x="400" y="614" textAnchor="middle" fill="#555555" fontSize="9" fontFamily="sans-serif">Adversarial-Depth tier adds: Depth agents + Exploit Chain + Verification (~20 agents total)</text>

  
  <line x1="400" y1="633" x2="400" y2="660" stroke="#9CA3AF" strokeWidth="2"/>
  <polygon points="400,668 394,658 406,658" fill="#9CA3AF"/>

  
  <rect x="40" y="672" width="720" height="110" rx="10" fill="#111111" stroke="#E7F900" strokeWidth="1" strokeOpacity="0.5"/>
  <text x="400" y="696" textAnchor="middle" fill="#E7F900" fontSize="12" fontWeight="bold" fontFamily="sans-serif">PHASE 3 - Deliverables</text>

  
  <rect x="62" y="710" width="156" height="54" rx="6" fill="#0A0A0A" stroke="#555555" strokeWidth="1"/>
  <text x="140" y="732" textAnchor="middle" fill="#FFFFFF" fontSize="11" fontWeight="bold" fontFamily="sans-serif">PDF Report</text>
  <text x="140" y="748" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">Findings + remediation</text>

  <rect x="234" y="710" width="156" height="54" rx="6" fill="#0A0A0A" stroke="#555555" strokeWidth="1"/>
  <text x="312" y="732" textAnchor="middle" fill="#FFFFFF" fontSize="10" fontWeight="bold" fontFamily="sans-serif">Signed Attestation</text>
  <text x="312" y="748" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">SHA-256 hash · verify link</text>

  <rect x="406" y="710" width="156" height="54" rx="6" fill="#0A0A0A" stroke="#555555" strokeWidth="1"/>
  <text x="484" y="732" textAnchor="middle" fill="#FFFFFF" fontSize="11" fontWeight="bold" fontFamily="sans-serif">Retest Validation</text>
  <text x="484" y="748" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">Oracle re-checks findings</text>

  <rect x="578" y="710" width="156" height="54" rx="6" fill="#0A0A0A" stroke="#555555" strokeWidth="1"/>
  <text x="656" y="732" textAnchor="middle" fill="#FFFFFF" fontSize="11" fontWeight="bold" fontFamily="sans-serif">Integrations</text>
  <text x="656" y="748" textAnchor="middle" fill="#9CA3AF" fontSize="9" fontFamily="sans-serif">Slack · Jira · Email</text>
</svg>

## Execution Flow

1. **Domain verification** - User proves ownership via DNS TXT record
2. **Credit allocation** - System checks credit availability and assigns the appropriate tier (Recon, Audit-Ready, Threat-Hunt, or Adversarial-Depth)
3. **Phase 1 launch** - Up to 14 tool containers start on Azure Container Instances in two waves: wave 1 (Port Scanner, Sub Hunter, Secret Scanner, Code Scanner, Dep Scanner, Net Scanner) runs first, then wave 2 web tools (Web Probe, WAF Detect, Server Audit, Web Scanner, Vuln Scanner, Security Checks, TLS Analyzer, Enumerator) launch against the web targets Port Scanner discovers. The 3 white-box tools only run when source code is provided
4. **Tool execution** - Each tool runs against the target with defined timeouts and resource limits
5. **Callback** - Tools report completion via HMAC-signed webhook to the app
6. **Paladin multi-agent analysis (Phase 2)** - Specialist AI agents ingest Phase 1 outputs and analyze findings in parallel, with the number and type of agents determined by the credit tier
7. **Continuity tracking** - If the target has been previously pentested, previous findings are automatically re-evaluated and tracked as new, confirmed, or retest_confirmed
8. **Report generation** - PDF report and a signed attestation are generated; the report and attestation are SHA-256 hashed and issued a public verification link
9. **Integrations** - User notified via email (Mailgun), Slack webhook, Jira ticket creation, and HubSpot CRM sync
10. **Attestation anchoring (roadmap)** - Attestation hashes are batched into a Merkle tree by a daily job; on-chain anchoring to Base L2 is planned and not yet live

## Credit Tiers and Agent Allocation

| Tier | Agents | Duration | Specialist Coverage |
|------|--------|----------|---------------------|
| Recon | 1 | 30 min | Generalist |
| Audit-Ready | 4 | 60 min | Web, API, Infrastructure (+ supervisor) |
| Threat-Hunt | ~10 | 120 min | All 9 specialist domains (+ supervisor + synthesis) |
| Adversarial-Depth | ~20 | 240 min | 9 breadth specialists + depth duplicates + exploit chain + verification |

## Key Properties

- **Isolated execution** - Each tool runs in its own container with no shared state
- **Ephemeral** - Containers are destroyed after the pentest completes
- **Parallel** - Phase 1 tools run concurrently in two waves (web tools wait for Port Scanner's target discovery), then Phase 2 agents run in parallel
- **Multi-agent** - Specialist AI agents analyze findings in their domain of expertise
- **Continuity** - Finding fingerprints track vulnerability status across pentests
- **Tamper-evident** - Every attestation is SHA-256 hashed and served through a public verification link; on-chain anchoring to Base L2 is on the roadmap

## Deep Dives

- [Infrastructure](/docs/architecture/infrastructure) - Azure services, data flow, and deployment
- [Paladin AI](/docs/architecture/paladin) - How the multi-agent agentic pentesting system works
- [Security](/docs/architecture/security) - Container isolation, data handling, and compliance
