Pentoma Web
Authenticated, business-logic-aware web and API penetration testing with AI discovery, deterministic replay, and human-validated evidence.
Real exploits. Real evidence. AI speed, human judgment.
Pentoma tests web apps, source code, and AI systems with agentic discovery, deterministic replay, and human validation — then ships reports your engineers can fix and your auditors can trust.
12m
engagement time
1
critical confirmed
7
evidence maps
SEWORKS has run offensive-security engagements since 2014 — across web, application, and adversarial testing. Pentoma is that practice, rebuilt as a continuous, AI-assisted product.
Every product produces the same shape of output: reproducible findings, scoped evidence, and compliance mappings the team can act on without translation.
Authenticated, business-logic-aware web and API penetration testing with AI discovery, deterministic replay, and human-validated evidence.
Pentoma Code is offensive source-code analysis. We hunt exploitable vulnerabilities, reconstruct full attack chains from source to sink, and surface 0-day candidates. Findings are validated by deterministic data-flow proof and human reviewers before they reach a customer report.
OWASP LLM Top 10 coverage with replayable prompts, observed behavior, policy mapping, and expert interpretation.
Side-by-side
Each product looks at a different surface, but ships the same kind of finding — what it tested, how it tested, and what the report contains.
Application layer
Target
Running web applications and APIs
Method
AI-assisted exploration, business-logic probing, deterministic replay, and human validation
Output
Confirmed application findings with request/response proof and compliance mappings
Source code
Target
Source-code repositories, pull requests, and release branches
Method
Offensive static analysis: vulnerability hunting, source-to-sink reasoning, attack-chain reconstruction, validated by reviewers
Output
Validated vulnerabilities, attack-chain evidence, line-level remediation guidance, and 0-day candidates worth coordinated disclosure
AI systems
Target
LLM endpoints, RAG flows, tools, plugins, and agents
Method
Adversarial prompts, agent-boundary tests, behavior replay, and policy checks
Output
AI risk evidence mapped to OWASP LLM Top 10 and governance controls
Proof, not promises
Pentoma is a small, founder-led team. Trust comes from artifacts you can read, fork, and forward — not from logo walls we have not earned yet.
How it works
Pentoma does not hide behind a black box. The workflow exposes scope, cost, evidence, and triage reasoning so security and engineering can move together.
01 / connect
Add a domain, repository, or LLM endpoint. Pentoma scopes the engagement and records the evidence boundary up front.
02 / agent runs
Reconnaissance, adversarial tests, replay, and triage run in a controlled loop with cost, scope, and compliance context visible throughout.
03 / evidence ships
Each confirmed issue ships with reproduction steps, severity rationale, remediation, and auditor-ready control mappings.
Pentoma gives auditors the same evidence engineers used to fix the issue: endpoint, payload, replay, severity rationale, and control mapping.
SOC 2
Vulnerability detection, response, and change-management proof.
CC7.1 · CC7.2 · CC8.1
ISO 27001
Technical vulnerability management and risk treatment evidence.
A.8.8 · A.5.36
AI Governance
Evidence for AI risk and governance reviews — adversarial replay, agent-boundary checks, and policy mapping.
Prompt replay · Agent boundary · Policy
Ready when your audit starts