AI Pentest Reporting.Screenshot In, Finding Out.
Generate vulnerability writeups, improve report sections, translate content and turn screenshots into structured findings.
Automatic Anonymization, Before Anything Leaves
Before any data reaches an AI provider, sensitive values are replaced with placeholders and restored in the response. The provider doesn't see your real client data.
Prefer zero egress? Run a fully local model on a self-hosted instance, or disable AI entirely.
- Company names
- IP addresses
- Domain names and URLs
- Email addresses
- Person names
Turn Screenshots into Findings
- Paste multiple screenshots in a single request
- Finding fields follow your vulnerability template
- Redact secrets first with the built-in screenshot editor
Generate Findings
- Improve options: Rewrite, Shorten, Expand, Fix grammar, Make more professional
- Generation tones: Professional, Technical, Executive, Remediation-focused, Custom
- Per-feature toggles keep generation only where you want it
- Formatting
- Lists
- Code blocks
- Technical terms
- Code snippets
- URLs
Translate In Seconds
- Technical terms, code snippets and URLs are left unchanged
- 72 languages available
Bring Your Own Model
Choose between multiple provider types, from managed to fully local. Plug in your own key or use the built-in Vulnotes AI.
Vulnotes AI is managed and included in every plan: 1M tokens per user per month. See what every plan includes
You can provide your own fully local LLM. Pair it with a self-hosted instance and your prompts stay on your network.
AI on Your Terms
Scope it, steer it, or switch it off.
Turn AI off across the whole instance in one click.
Enable or disable AI separately for any feature of your instance.
Write Reports from Any MCP Client
Connect your instance to Claude or any MCP client with one command, then write and export pentest reports without leaving the chat.
- 40+ MCP tools across reports, findings, templates, vulnerability library, notes...
- Strict template validation rejects malformed AI-created findings
claude mcp add --transport http vulnotes https://your-instance.vulnotes.app/mcp \
--header "Authorization: Bearer vuln_sk_your_api_key_here"Everything in the UI is scriptable
Don't want to use the MCP for redundant workflows? Automate it via our REST API with 160+ endpoints!
Browse the API reference