Compare
Cloud pentesting toolkit & vulnerability scanners
Pentest-Tools.com is a cloud toolkit for pentesters: network and web vulnerability scanners, API and CMS scanning, exploit tools and an editable pentest report generator, sold per asset. Decloak is aimed at teams without a pentester: it scans the browser-visible layer, explains results in plain English, and maps findings to compliance controls.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Pentest-Tools.com: Cloud pentesting toolkit & vulnerability scanners, Romania
“Not advertised” means we could not confirm the capability from Pentest-Tools.com's public website, not that it is absent.
| Capability | Decloak | Pentest-Tools.com |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Free plan with limited features |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Plans and prices are published |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Free; NetSec from $95/mo; WebNetSec from $140/mo; Pentest Suite from $190/mo (5 assets and up) |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes DAST scanning beyond the OWASP Top 10 (WebNetSec and up) |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Authenticated web scans (WebNetSec and up) |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes REST and GraphQL API scanning |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Yes Reconnaissance tools including subdomain discovery |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Partial Exploiters (CVE, SQL injection, XSS) for testers on Pentest Suite; not an autonomous pentest |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Yes Network vulnerability scanning (17,000+ CVEs) |
| Internal network scanning | No External scanning only | Extra cost Internal network scanning is an add-on |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes Cloud scanning with AWS imports |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Not advertised |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes Pentest report generator (editable DOCX and Google Doc) on Pentest Suite |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Extra cost Branded reports and emails are an add-on |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Jira, Microsoft Teams, Slack, Discord, email; Vanta and Nucleus Security |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Yes API access, webhook alerts and an MCP server on paid plans |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Pentest-Tools figures come from its public pricing page and are in US dollars, "from" prices for 5 assets that rise with asset count and billing cycle. Decloak prices are flat monthly plans in GBP.
Decloak produces a scored report with a plain-English executive summary on every scan. Pentest-Tools is a toolkit where a tester interprets the output.
Decloak inspects third-party scripts, tag manager containers, vulnerable JavaScript libraries and every external domain contacted. Pentest-Tools does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases and exposed service keys, on the free tier too.
Pro maps findings to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA, and includes white-label PDFs rather than charging an add-on.
Pentest-Tools scans networks for 17,000+ CVEs, cloud accounts and, as an add-on, internal networks. Decloak is external and web-focused.
Exploiters, editable finding templates and a report generator suit consultants producing manual pentest deliverables. Decloak automates and does not offer an editable report workflow.
Paid plans include unlimited team members and listed Jira, Teams, Discord, Vanta and Nucleus integrations. Decloak has Slack, webhooks and email; native Jira and Teams are planned.
For monitoring a website and getting a readable, compliance-mapped report, yes. For network scanning or building manual pentest reports, Pentest-Tools is the broader toolkit and Decloak does not replace it.
Pentest-Tools has a free plan and paid plans from $95 per month for 5 assets, rising with asset count. Decloak is free for single-page scans, then £29, £79 or £99 per month.
Yes. Decloak Pro and above include a REST API with OpenAPI docs and an MCP server for AI agents.
Pentest-Tools.com details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Pentest-Tools.com. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: