Continuous pentest, finished by hand

Three layers.
One report.
Fewer false positives.

We scan your external attack surface every day with 30+ tools, verify every finding against your live environment, and finish with an LLM-driven review that strips out the noise. What reaches the report has survived three filters.

Hostat i Stockholm. GDPR Art. 28-DPA på begäran. Org.nr 556227-6351.

Senaste scan, exempel
Råscan, alla verktyg47
Efter verifiering12
Efter artisanal granskning8
Levererat till kund (varav 2 high)8

39 findings dropped along the way, of which 4 were marked false positive by our FP-learning engine. The rest were duplicates, already known, or fully covered by another control.

Hosted in StockholmGDPR Art. 28 DPA on requestNIS2 + ISO 27001 + NIST CSF 2.0CRA-readyAdminor AB · since 1983

The method

Four steps
that filter
out the noise.

The difference from a regular vulnerability scanner isn't more tools, it's what happens after the scan. Three steps remove findings. Only one adds.

01

Daily scan

nuclei, subfinder, httpx, naabu and ~25 more tools run against your external attack surface. We use what actually works for the stack, not everything at once.

Removes nothing. Builds raw material.

02

Verification engine

Every finding is double-checked against your live environment with HTTP self-tests, snapshot comparison and global FP patterns. Duplicates merge, known FPs are marked.

Removes ~70 % of raw findings.

03

Artisanal LLM review

An Opus-driven review reads scan data with scope-awareness and evidence-grounding, finds coverage gaps and downgrades weak signals. An operator reads and approves.

Sometimes adds. More often removes.

04

A report you actually read

The final product is a short, prioritized list in the dashboard or monthly email. No "Critical: missing X-Frame-Options". Just things worth fixing.

Delivered. Done.

Pricing

In SEK,
upfront.
No "contact sales".

14 days free, no credit card. Standard fits most customers. Guarantee: if we find nothing in 30 days, full refund.

Basic

249SEK/mo~25 EUR
  • 1 domain + 5 subdomains
  • Daily vulnerability scanning
  • Verification Engine
  • Monthly findings email
  • NIS2 + ISO 27001 report
Get started

Standard

990SEK/mo~95 EUR
  • 5 domains + unlimited subdomains
  • Daily scanning
  • Verification Engine + FP-learning
  • Weekly findings email
  • Site monitoring
  • Artisanal LLM review / month
  • REST API + MCP server
  • Priority support
Start 14-day trial

Premium

Contact
  • Everything in Standard
  • Custom scope and scan profile
  • Dedicated operator
  • Signed compliance attestation
  • SLA + on-call
  • Bespoke artisanal passes
Contact us

Comparison

What you get vs what others offer.

Actual features, not claims. Things actually listed on competitor pricing pages as of May 2026.

ServiceDailyAI verif.SwedishEASMMonitoringPrice
Pentesting.se249 SEK
Aikidofr €300/mån
Detectifyfr $275/mån
Intruderfr $172/mån
Pentest-Toolsfr $85/mån
QualysCustom

Frequently asked

What people ask most.

What is external attack surface management (EASM)?+

EASM continuously maps and monitors externally exposed IT assets: domains, subdomains, IPs, ports, web applications, and cloud services. The point is to find vulnerabilities before an attacker does.

How is pentesting.se different from a regular vulnerability scanner?+

The difference is not more tools, but three filters after the scan: cross-tool correlation, verification against your live environment, and an LLM-driven review that cleans and complements. What ends up in the report has survived three filters, not the raw scan.

Which compliance frameworks are supported?+

Findings are automatically mapped to the NIS2 Directive, ISO 27001 Annex A, and OWASP Top 10. Compliance reports can be generated directly from the dashboard. Premium plan includes a signed attestation.

Can it integrate with CI/CD and AI agents?+

Yes. REST API, Prometheus metrics, and an MCP server (Model Context Protocol) that works with Claude Code, Cursor, and other AI assistants. Trigger scans and fetch results programmatically.

Where is data stored?+

All data is hosted on servers in Sweden (Stockholm). No US Cloud Act exposure. GDPR Art. 28 DPA available on request. Org.nr 556227-6351, Adminor AB.

Want to see what your external attack surface actually looks like?

One domain, two minutes, no credit card. We show you what the first scan found, and what survived our three filters.

Adminor AB · Swedish IT security since1983 · Org.nr 556227-6351