Pentestrelay
A consultant-facing threat-intelligence gateway that binds every allowed query to a client engagement, verifies provider rights and scope, normalizes source-attributed observations, meters cost, and exports correction-preserving findings evidence.
The source confirms a live adversary-emulation competitor plus several public or paid intelligence sources, but seven of ten referenced capabilities remain unverified. It did not find the proposed per-engagement commercial model. That pricing gap is not a technical moat, and no provider access should be assumed.
Pentestrelay should operate only for an authorized engagement with written scope, targets, methods, time window, exclusions, rate limits, data-handling rules, and customer contacts. Provider terms and target authorization are independent: a legal data subscription does not authorize testing, while customer authorization does not override a provider's license or another person's privacy rights.
Results are source-attributed observations with timestamps, coverage, confidence, licensing, false-positive risk, and reviewer disposition. They are not proof of ownership, compromise, threat-actor identity, vulnerability, exploitability, legal breach, or court admissibility. Active testing and credentialed access remain outside the first release.
Solo penetration testers, boutique consultancies, and red-team operators that need engagement-scoped intelligence cost and evidence without buying a broad enterprise platform.
Enterprise vendors may avoid low-commitment engagement pricing.
Solo and boutique security consultants are specific.
The source has limited graph support but several concrete providers.
The consultant buyer, live competitor, engagement-centered meter, and source-attributed evidence workflow are concrete.
Most named capabilities are unverified, data licenses are fragmented, the pricing model is easy to copy, authorization errors are high risk, and source observations can be stale.
Discussion
No comments yet — be the first to weigh in.
