AN Alpesh Nakrani
SolutionsBlogBooksPraiseAbout Work with me ↗
Cybersecurity · Operating-cost reduction

Penetration test reporting that saves billable hours.

Turn validated tester notes and evidence into consistent executive and technical findings while keeping every vulnerability judgment with the tester.

◆ human-gateda person approves every consequential action
$16,500
fixed-scope pilot
Validate next
launch posture
Strong durable demand
market signal
penetration-test-report-generator
// structure evidence
input: Tester notes
step: draft finding
citations: [ source ✓ ]   confidence: 0.93
HUMAN GATEawaiting review →

Nothing is finalized until a human approves it.

Built for
The buyer
Pentesting-firm CEO, Security Consulting Partner, Offensive Security Director
The champion
Pentest Practice lead, Quality Assurance manager, Principal Consultant
Day-to-day users
Pentesters, report reviewers, project managers and client engineering teams

Designed, built, and evaluated by Alpesh Nakrani, VP of Growth at ViitorCloud, 14 years shipping software, writing on AI-Native engineering and evaluation.

Evals-first
built in from day one
Human-gated
judgment stays with you
The problem

Where the time and money actually go.

Consultants spend billable hours standardizing language, reproduction steps, severity rationale, and remediation while quality varies by author.

Who feels it

Pentesters, report reviewers, project managers and client engineering teams

Trigger to act: Report backlog delays delivery, margins are under pressure, a firm is scaling junior testers, or clients complain about inconsistent remediation guidance.

Outcome & ROI

The result you can model before you sign.

Illustrative, replace with your data
$21,600
per month, illustrative

Illustrative only: 30 reports/month × 6 consultant hours removed × $120 loaded hourly cost = $21,600 monthly capacity. It does not create more valid findings by itself.

The outcome, plainly: Turn validated tester notes and evidence into consistent executive and technical findings while keeping every vulnerability judgment with the tester.

Report hours
reviewer changes
evidence completeness
How it works

Inputs in. A cited, review-ready result out. Your expert decides.

A Evidence-grounded reporting agent. Every material fact is grounded in an allowed source and returned with its identifier, with no invented data.

01
Structure evidence
02
draft finding
03
normalize reproduction steps
04
map CWE/CVSS
05
propose remediation
06
create executive summary
07
detect missing proof
08
render approved format
Reference architecturegrounded · human-in-the-loop · fully auditable
Source systems · scoped access
Pentest project/workflow system
secure evidence store
finding library
report template
CVSS/CWE/CVE references
Grounded reasoning core
Retrieve & extract
grounded on your sources, returns citations
Reason & draft
Claude Sonnet 4.6 or GPT-5.6 Terra
Human gateThe pentester validates exploitability, scope, severity, evidence, and remediation; a senior reviewer approves every report before client delivery.
Action · only after approval
render approved format
Audit trace
sources, rules, confidence, reviewer
Tenant isolation
minimum data, never cross-tenant
Evaluation suite
baselined pre-launch, watched after
Observability
cost, latency & drift telemetry
Model strategy

Claude Sonnet 4.6 or GPT-5.6 Terra for complex grounded work; select by task-level evaluation; Gemini 2.5 Flash, GPT-5.4 mini or Claude Haiku 4.5 for high-volume routing and drafting. PostgreSQL + pgvector or managed vector store; Policy rules and evaluator service.

Inputs
  • Tester notes
  • validated evidence
  • screenshots
  • commands/output
  • affected assets
  • severity rationale
The human gate

AI-Native, not autonomous. Judgment stays with your people.

The machine does the work; the human’s role narrows to the one thing that matters, judgment. That constraint is what makes it safe to deploy.

Non-negotiable human gate

The pentester validates exploitability, scope, severity, evidence, and remediation; a senior reviewer approves every report before client delivery.

What it will never do
No generation of unvalidated vulnerability
no severity decision by model alone
no offensive action
no exposure of client evidence across engagements.
The scorecard

A scorecard, not a demo. We baseline what breaks in production.

Every deployment ships with an evaluation suite. These are the numbers we baseline before launch and monitor after.

Primary
Report hours
reviewer changes
evidence completeness
severity consistency
client clarification
delivery time
unsupported-finding rate
remediation usefulness
Why this, not that

The category is crowded. Most of it isn’t built for your workflow.

The alternatives
PlexTracDradisAttackForgeFaradaySysReptorPentest-Tools reportinginternal Word/LaTeX templates
This implementation

Fixed-scope, tuned to your systems and rules, grounded in your data, with the human gate and audit trail built in from day one. A price you own, not a subscription you rent.

✓ Fixed price, not a seat subscription ✓ Grounded in your data & rules ✓ Human approval on consequential actions ✓ Auditable decision trace
Systems & integrations

It plugs into the stack you already run.

No rip-and-replace. Access is scoped to the minimum data necessary, isolated per tenant, and fully logged.

Pentest project/workflow systemsecure evidence storefinding libraryreport templateCVSS/CWE/CVE referencesticketing/client portal
Pricing

Transparent by design. The build price buys the workflow and the proof.

A fixed implementation fee plus a monthly bill that scales with volume and governance. No hidden seats.

Pilot
$16,500
one-time · bounded proof of value
  • One process / scope
  • Live workflow on your data
  • Baseline evaluation suite
  • Measured vs. current process
Most chosen
Production
$38,000
one-time · full deployment
  • Full scope & integration
  • Human-review UI & audit trail
  • Write-back to your systems
  • Production evals & monitoring
Enterprise
$63,000
one-time · multi-entity / regulated
  • Multi-facility rollout
  • Advanced security & compliance
  • Custom control & escalation
  • Dedicated evaluation program
Monthly operating cost

500–5,000 report runs/month plus source queries, model use and export storage.

$400–3,600
usage (models, OCR, vector, storage)
$2,600/mo
managed evaluation & monitoring

Planning assumptions, not vendor quotations. Your Pentest project and other platform licenses are separate and owned by you. Figures confirmed during scoping.

On working with Alpesh
“His vast knowledge of technologies and a natural problem-solving mindset consistently lead us through complex challenges with clarity and confidence.”
AM
Adil Multani
Senior Backend Developer
Why this is safe to try
01Baseline first. We measure your current numbers before we build anything.
02Fixed scope, fixed price. One process in the pilot. No open-ended engagement.
03Expand only if the scorecard earns it. You see the measured result before committing to production.
04Your people stay in control. The human gate means nothing consequential happens without a human’s approval.
FAQ

Questions serious buyers ask.

Does the AI act on its own?

No. The pentester validates exploitability, scope, severity, evidence, and remediation; a senior reviewer approves every report before client delivery. The system drafts and recommends; a human approves every consequential action. Explicitly excluded: No generation of unvalidated vulnerability; no severity decision by model alone; no offensive action; no exposure of client evidence across engagements..

How do you stop it inventing facts?

Every material claim is grounded in an allowed source record and returned with its source identifier. The system separates observed facts, model inference, and missing information, and routes to a human whenever confidence is low, evidence conflicts, or an adverse outcome is possible.

What does it cost to run each month?

A usage bill of roughly $400–3,600/month (500–5,000 report runs/month plus source queries, model use and export storage), plus a $2,600/month managed retainer for evaluation, monitoring and maintenance. Your existing platform licenses are separate and already yours. Exact figures are confirmed during scoping.

Do we need a ChatGPT or Claude subscription?

No consumer ChatGPT or Claude subscription is required for the production workflow. The client needs an approved API/cloud billing account. Workspace seats are optional for internal prototyping and administrator access.

How is this different from PlexTrac?

Tools like PlexTrac, Dradis, AttackForge are broad platforms you adapt to. This is a fixed-scope implementation tuned to your systems and rules, grounded in your data, with the human gate and audit trail built in, and a transparent price instead of a seat subscription.

How long until it’s live, and how do we prove it works?

This is a validate next. We baseline “Report hours” first, then measure against that baseline. You see the scorecard before expanding scope, the evaluation suite ships with the system, not as an afterthought.

Book a scoping call

Bring your real numbers. Leave with a fixed-scope plan.

A 30-minute engineering-led working session, no slideware. You leave with a sized opportunity estimate, a fixed-scope pilot plan, and the integration & human-review path mapped.

VP of Growth at ViitorCloud · senior delivery owner confirmed before paid work

Ask AI about Penetration Test Report Generator