AI-driven penetration testing that runs entirely on your infrastructure. Self-hosted Docker container. Zero-knowledge architecture — ModularCISO never sees your targets, your results, or your API keys.
This tool performs active port scanning, directory fuzzing, vulnerability probing and AI-driven attack chaining against whatever target you give it. Running that against infrastructure you do not own or have permission to test is a criminal offence in most jurisdictions — including under the UK Computer Misuse Act, the US Computer Fraud and Abuse Act, and Article 197 bis of the Spanish Código Penal. Intent is not a defence, and "I was only scanning" is not a defence.
Before you point it at anything:
You are the operator, not us. The tool runs entirely on your own infrastructure — we never see your targets, results, or keys, which also means we cannot vet what you point it at. Responsibility for every scan is yours. Use of the security tools to attack, scan, or test systems you do not own or are not authorized to test is prohibited under our Terms of Service.
Ollama, GPUStack, vLLM, and Custom endpoints use the OpenAI-compatible /v1/chat/completions protocol. API keys never leave your machine.
API keys stay here.
Docker host.
Nmap, ffuf, Nuclei,
AI agent run here.
Results stay on
your machine.
The Pentest Tool is currently in development. Create a free account to be notified when it becomes available.