Pentesting.se vs Nørdsnipe Hedgehog

External SaaS scanning vs on-prem pentest appliance. Different shape of problem.

Quick summary

Nørdsnipe Hedgehog is a self-hosted pentest platform from a Stockholm startup with strong technical credentials (ex-Google, Ericsson, Microsoft, KTH). The product comes in three tiers: Desktop for individual pentesters, Collaborative for red/purple teams, and Autonomous where multiple Hedgehogs live inside the customer environment and run continuous testing on command. Strength: deep internal-network coverage, AI-augmented for in-house operators, no data leaves the customer network unless they say so.

Pentesting.se is external-perimeter SaaS. Daily scanning of public attack surface (subdomains, APIs, certificates, exposed services) from our infrastructure against assets the customer has authorised. Strength: low monthly price, multi-tenant from day one, NIS2 and CRA mapping built in, MCP integration for AI-agent workflows. Internal-scan (Sentinel) is on the roadmap but not shipped today, that is where Hedgehog leads us.

These are complementary tools, not direct substitutes. If you sell pentest as a service or have a mature in-house red team, look at Hedgehog. If you need continuous external-perimeter monitoring as a managed service, look at us. Many organisations would want both.

Comparison at a glance

AspectNørdsnipe HedgehogPentesting.se
FoundedStockholm startup, ex-Google/Ericsson/Microsoft/KTH foundersAdminor AB 1983, platform 2024
Deployment modelSelf-hosted, on-prem appliance inside customer networkExternal SaaS, scanners run from our infrastructure on customer-authorised assets
Primary perspectiveInternal: AD, lateral movement, internal services, intranetExternal: public perimeter, exposed APIs, subdomains, certs
Target buyerIn-house red/purple team, security engineers with pentest skillCISO/CTO without in-house pentest team, MSP delivering to many SMB tenants
AI angleAI-augmented pentest tooling for the operatorClaude-based summary, FP reduction, MCP for AI-agent integration
Continuous modeYes (Autonomous tier, multi-agent in customer env)Yes, daily scans baseline. Delta findings, regression alerts
PricingNot disclosed publicly, enterprise sales modelFrom 249 SEK/month, transparent pricing on site
External-perimeter coverageNot the primary productCore product (subfinder + naabu + httpx + nuclei + custom plugins)
API security testingGeneric via Hedgehog toolingDedicated: JWT mutation matrix, GraphQL deep audit, OpenAPI-driven fuzzing, OWASP API Top 10 mapped
Internal/AD testingYes, core capabilityNot today (Sentinel internal-scan SKU on roadmap)
Multi-tenant SaaS dashboardNo (per-customer install)Yes (built-in for MSP delivery + multi-tenant orgs)
Data residencyCustomer-controlled, never leaves customer networkAdminor AB infrastructure in Sweden, GDPR-bound, no US Cloud Act exposure
NIS2/CRA mappingNot specifically targetedBuilt-in finding-to-article mapping + CRA-readiness service
MCP integrationNoYes (14 tools, Claude Code + Cursor)

Pick Nørdsnipe Hedgehog if...

  • You have an in-house red or purple team that wants better tooling
  • Your primary risk surface is internal: AD, lateral movement, intranet services
  • Compliance or sensitivity rules out any third-party SaaS, data must stay inside your network
  • You sell pentest as a service and need an operator-facing platform
  • You want a desktop tool that lives in your existing terminal workflow
  • Enterprise procurement and pricing is fine for your organisation

Pick Pentesting.se if...

  • You do not have a pentest team in-house and do not plan to build one
  • Your primary risk surface is external: public APIs, subdomains, exposed services
  • You need continuous monitoring at a low monthly cost, not a project-based engagement
  • You are an MSP and need multi-tenant SaaS to deliver security monitoring to many SMB clients
  • NIS2, DORA or CRA mapping needs to be a standard report, not a custom one
  • You want AI-agent integration via MCP so Claude Code or Cursor can trigger scans from chat
  • Transparent SaaS pricing matters more than custom enterprise contracts

Use both?

For organisations with both external attack surface and internal infrastructure worth testing, the two cover different ground. Pentesting.se watches the perimeter every day, Hedgehog audits the internal network when the operator runs it. The closest comparison we have to Hedgehog's internal mode is our Sentinel SKU, which is on the roadmap but not shipped at the time of writing.

Concretely: an ISO 27001 organisation can run Pentesting.se for the daily external evidence the auditor needs, plus a Hedgehog appliance once or twice a year for an internal sweep. Two tools, two budgets, one risk picture.

Start with a free health check

See your current external exposure in 60 seconds. No account required.