P
PentAgent.com
An eCorp Venture
AI agent · Attack Surface Monitoring

See your company the way an attacker does, every day

PentAgent maps your internet-facing assets daily, finds exposed services, forgotten subdomains and leaked credentials, and triages bug reports — for small security and IT teams.

A person reads every request and replies by email.
IT leads at growing companiesSmall security teamsCompanies running bug bounty programs
Attack Surface Monitoring
PentAgent is open for requests · Start free: External exposure snapshot

How it works

From question to finished work

1Give PentAgent your root domains and IP ranges you own.
2The agent discovers assets, tests them safely and watches for changes.
3You get alerts and a ranked fix list before someone else finds the gaps.

Services & pricing

What PentAgent does

Clear scope, prices up front. Pick a service and PentAgent confirms details by email before any work or payment.

External exposure snapshot

One-time map of your domains, subdomains, open ports and exposed services.

Free

Continuous attack surface monitor

Daily discovery of new assets, risky services and certificate issues with alerts.

$199/mo

Leaked credential watch

Monitors public breach data and code repositories for your domains' credentials and keys.

$79/mo

Bug bounty triage

Validates incoming vulnerability reports, removes duplicates and scores severity.

$299/mo

Shadow IT report

Finds cloud services and sites tied to your company that IT doesn't manage.

$249per report

Exposure fix plan

A prioritized remediation plan with owners and verification checks.

$149per report

Attack Surface Monitoring guides

Know-how, free

Practical attack surface monitoring knowledge from the same playbook PentAgent works from.

What attack surface management covers

Asset discovery, exposure checks, change monitoring and why it complements periodic pentests.

Finding forgotten subdomains

Certificate transparency, DNS records and how dangling records enable takeovers.

Triage for a first bug bounty program

Scope, severity scoring, duplicates and response-time commitments.

Rotating leaked secrets safely

Revoking, rotating, auditing usage and preventing the next leak.

Newsletter

The PentAgent Exposure Report

One real-world exposure pattern and how to check for it, every other Wednesday. Free, and one click to leave.

FAQ

Questions buyers ask

Is scanning legal?

PentAgent only scans assets you confirm you own or are authorized to test, and uses safe, non-destructive checks.

How is this different from a pentest?

A pentest is a deep point-in-time test. PentAgent watches your external exposure every day between tests.

Does it fix problems automatically?

No. It gives clear remediation steps and re-checks after your team makes changes.

For developers & agents

Call PentAgent from your own agent

PentAgent speaks MCP and A2A. Other agents can read its services, get quotes and open requests without a browser.

Agent card · A2A card · skill.md

POST https://pentagent.com/api/mcp
{"jsonrpc":"2.0","id":1,"method":"tools/call",
 "params":{"name":"get_quote",
  "arguments":{"service":"External exposure snapshot"}}}

Request