Core Concepts
Credits
Every pentest consumes one credit. Credits come from:
- One-time purchase - Buy individual credits starting at $99 (Audit-Ready tier)
- Subscriptions - Annual plans paid upfront - all credits are issued immediately
- Vouchers - Promotional codes that grant free credits
Credits are consumed when a pentest starts. If a pentest fails to launch, the credit is returned. You can also transfer available credits to other users by email address.
Domain verification
Before pentesting a domain, you must prove you own it. This prevents unauthorized testing.
Verification methods:
- DNS TXT record - Add a
turbopentest-verify=<token>TXT record to your domain's DNS - Domain verification covers all subdomains (verifying
example.comallows testingapp.example.com)
Safe harbor agreement
Before launching your first pentest, you must accept a safe harbor agreement confirming you own or have authorization to test the target domains. This is a one-time confirmation and does not block credit purchases.
Pentests
A pentest runs up to 14 security tools against your target URL. There are two types:
| Type | Tools | Requires |
|---|---|---|
| Black box | 11 network and web app tools | Domain verification |
| White box | All 14 tools including SAST, SCA, secrets | Domain verification + GitHub connection |
Pentests go through these statuses: queued -> scanning -> complete (or failed). When platform capacity is full, a pentest can sit in capacity_queued until a slot frees up. You can run up to 5 pentests at the same time, and only one active pentest per target.
Findings
Each vulnerability discovered is a finding with:
- Severity - critical, high, medium, low, or info
- Title - Short description of the vulnerability
- Description - Detailed explanation
- Proof of exploit - Evidence that the vulnerability exists
- Remediation - How to fix it
- Continuity status - How the finding relates to prior pentests:
new,confirmed, orretest_confirmed - Source tool - Which tool discovered it
- CVSS vector - Detailed breakdown of how the severity score was calculated
Multi-domain pentests
You can test up to 20 domains in a single request. Each domain consumes one credit. All pentests in the group share a groupId for easy tracking.
API keys
API keys authenticate requests to the TurboPentest API. Each key has a tp_ prefix and is shown once at creation. Pass it as a bearer token in the Authorization header: Authorization: Bearer tp_....
Quick Start
Run your first TurboPentest pentest in under five minutes, start to finish, using either the REST API or the dashboard's New Pentest flow.
Running a Pentest
Start a TurboPentest pentest from the dashboard or API - enter a target URL, optionally add a GitHub repo for white-box analysis, and launch the scan.