FIELD NOTES / 001Report production

Pentest report generator for the work after the exploit.

Turn Nmap scans, Burp Suite output, screenshots, and rough tester notes into a report your client can act on. CVSS scoring, finding structure, remediation, and export are handled in one focused workspace.

Nmap Burp Suite CVSS 3.1 PDF / DOCX
Report builder / draft 042
Autosave on
Finding / 01

SQL injection in search

High / 8.1
Impact

An unauthenticated attacker can read records outside the intended tenant boundary.

Vector

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Remediation

Use parameterized queries and enforce tenant scoping in the data access layer.

AI review complete Ready for export
5-step
AI pipeline
CVSS 3.1
Scored findings
05
Report formats
PDF + DOCX
Client-ready output
01Capabilities

The raw material is messy. The deliverable should not be.

A tight workflow for turning evidence into a report that reads clearly, scores consistently, and gives the next person something useful to do.

Parse the evidence

Paste tool output or notes. The parser separates assets, observations, evidence, impact, and remediation without forcing you into a rigid input format.

Score the risk

CVSS 3.1 vectors, severity, CWE mapping, and OWASP categories are attached to every finding. Edit the result when your context demands it.

Shape the report

Choose the structure that matches the engagement. Keep the technical detail, lead with risk, or produce a clean assessment for stakeholders.

Work locally

The Windows and Linux desktop app keeps report creation on your machine. Use direct provider calls when you choose cloud AI processing.

02Workflow

From console output to a report you can send.

01

Drop in the findings

Bring the raw material from Nmap, Burp Suite, a scanner, or your own notes. Screenshots can sit beside the text.

02

Review the intelligence

Let the pipeline structure the finding, calculate a CVSS vector, map the weakness, and draft useful remediation.

03

Export the evidence

Pick a report format, make the final calls, and export a professional PDF or DOCX without rebuilding the document by hand.

03Templates

Five structures. One clear standard.

Start with the shape that fits the engagement, then tune the details. Every format is available as a PDF or DOCX export.

View template library
05FAQ

The useful answers.

What input formats does PentestReportAI accept?

Any text format - paste raw Nmap output, Burp Suite results, manual notes, or any other tool output. You can also paste or drag-drop screenshots and the AI will analyze them using vision.

How does the AI scoring work?

Our 5-step AI pipeline parses your findings, assigns CVSS 3.1 vectors and scores, maps to CWE/OWASP categories, enriches with professional descriptions and remediation steps, then generates an executive summary and risk assessment.

Is my data secure?

On the web app, your data is transmitted over HTTPS and processed via AI. The desktop app is fully privacy-first - all data stays on your machine and AI calls go directly from your device. We never store your raw findings after processing.

What report templates are available?

Five templates: Executive Summary, Technical Detail, OWASP Top 10, Compliance, and Vulnerability Assessment. All available as PDF or DOCX downloads.

Do unused report credits roll over?

Monthly plan credits are allocated per 30-day billing period. One-off $3 report credits do not expire and stay available until you use them.

What is the lowest-cost way to start?

Buy a single report credit for $3. It includes AI parsing, CVSS scoring, all five templates, and PDF or DOCX export.

06Contact

Have a real question?

Tell us what you are trying to report, where the workflow slows down, or what you need from the next release.

Direct support for pentesters
Required0/2000