notra·
AI penetration testing

Penetration testing that proves every finding.

Notra runs a real pentest against your live site and returns a short list of verified vulnerabilities, each one backed by the exact request and response that proves it. No security hire required.

Hundreds of raw signals in  →  only the proven ones out
https://
Free scorecard in about a minute. Prove you own the domain, and your first verified audit — the kind others charge $3,000 a year for — is on the house.
100.0%
of what we've shipped is a true positive
0.0%
self-reported false-positive rate
4 min
median time to a full report
100%
of shipped findings carry evidence
What “verified” means
01

Evidenced

Every finding carries the request and response that proves it. No proof, we drop it.

02

False-positive filtered

We re-run each candidate with a harmless test. Under 0.8 confidence, it never ships.

03

Explained

Written so your developer knows what to change, with the CVE to back it.

See how the agent thinks →

Noise vs signal

A scanner hands you 800 findings. A handful are real.

This is one real scan. We cut everything we couldn’t prove and kept only what survives the gate.

800 raw signals in
SQL injection (maybe?)Reflected XSS (unconfirmed)jQuery 1.12.4 outdatedDirectory listing?Server header presentDuplicate of #118X-Powered-By exposedMissing HSTS headerTLS 1.1 supportedCookie without Securerobots.txt foundClickjacking?Open redirect?Verbose 404 pageOutdated Bootstrap 3CORS header seenWordPress detectedLogin page foundEmail in HTML sourceMixed contentComment reveals pathDeprecated API in useSame as #204PHP 7.4 (info)+ 776 more
Verification gateEach candidate re-run with a harmless probe.
0.8
confidence floor
12 proven, ranked by real risk
Unauthenticated remote code execution: WP File Manager 6.0 (CVE-2020-25213)KEVcritical· 9.8
Unauthenticated remote code execution: Bricks theme 1.9.5 (CVE-2024-25600)KEVcritical· 9.8
Backup file leaks live Stripe, SMTP and database credentialshigh· 8.6
CORS reflects any origin with credentials enabled on the Store APIhigh· 7.5
Reflected XSS in product filter 'sort_by' parametermedium· 6.1
+7 more, each with its evidence and fix

Zero unverified findings. Structurally.

The gate re-runs every candidate with a harmless proof-of-exploit before it can ship. Under 0.8 confidence it never leaves the building — not because a policy says so, but because the gate can’t emit it.

How the gate decides
Inside the console

This is the desk you work from.

The verified findings table, sorted by real risk — the same view your team gets after every scan.

The pipeline
How verification works

Nothing runs until you approve it. Four steps, start to finish.

01

Prove it's yours

Add a DNS record or drop a file. We don't touch your site until you do.

02

Live scan

We map the site, then run safe checks. Nothing destructive, and you watch it happen.

03

Verification gate

We try to reproduce each finding. Whatever we can't prove, we cut.

04

Verified report

A ranked PDF. Each finding has its proof, its score, and the fix.

See the evidence

Click a finding, read the request that triggered it.

One finding from the sample audit, with the exact request and response we captured.

Exhibit · request · responsepassed FP-gate
$ curl -s https://harborlanterngoods.com/wp-content/plugins/wp-file-manager/readme.txt | sed -n '1,6p'
=== WP File Manager ===
Contributors: mndpsingh287
Tags: file manager, wp file manager, filemanager
Stable tag: 6.0
Requires at least: 3.0

# 6.0 is < 6.9 -> CVE-2020-25213 (CISA KEV). The elFinder connector is exposed with no auth check.
# Notra's benign write probe (create a directory, no shell, no upload):

POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1
Host: harborlanterngoods.com
Content-Type: multipart/form-data; boundary=----vera7f3a

------vera7f3a
Content-Disposition: form-data; name="cmd"

mkdir
------vera7f3a
Content-Disposition: form-data; name="target"

l1_Lw
------vera7f3a
Content-Disposition: form-data; name="name"

vera_probe_7f3a
------vera7f3a--

HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8

{"added":[{"name":"notra_probe_7f3a","hash":"l1_dmVyYV9wcm9iZV83ZjNh","phash":"l1_Lw","mime":"directory","ts":1756142870,"read":1,"write":1,"locked":0}]}

# Unauthenticated directory creation succeeded -> the connector accepts commands with no nonce and no login.
# Verification gate stopped here. Notra did NOT upload a payload. The empty folder notra_probe_7f3a was left in place
# so your team can independently confirm and then delete it.
The receipts

Every raw signal comes in. Only the proven ones ship. The rest go here:

512

deduped

Same flaw across many paths/params, merged to one.

184

info-only

Real, but harmless on their own.

61

unverified

We couldn't reproduce them.

31

false-positive

False alarms: framework CSRF, ORM "SQLi", bot-blocked 403s.

Fits your workflow
EmailWhite-label PDFREST APICI/CD gateMCP server
Who it’s for
Agencies

White-label every audit under your brand. Rechecks are billable, and clients read a plain-English report, no security hire on their side.

Best on Agency
$499/mo
Solo founders

One honest answer before you launch: what on your site is actually exploitable today, and exactly what to change to fix it.

Best on Deep Audit
$149 once
Eng leads

Catch a regression before your customers do. Every monitored rescan emails you the current findings, so nothing sits unnoticed between deploys.

Best on Monitor / Pro
$49–199/mo
MSP / MSSP

Dozens of client sites in one console, white-label PDFs, and a verification gate that means far fewer false-alarm tickets.

Talk to us
$1k+/mo
Pricing

Pay per site, not per finding.

Priced per site, per month. Pay yearly and two months are free. Early customers keep launch pricing for a year.

Free Instant Scan
$0 / one-time, instant

A letter grade in under a minute. Free with a Notra account.

  • Passive scorecard: TLS, security headers, cookie flags, exposed files, email auth
  • Letter grade and one-line plain-English summary
  • Sign in free — no card, no domain ownership required
  • Results in under a minute
  • No verified findings or evidence pack (that starts at Deep Audit)
Most popular
One-Time Deep Audit
$149 / one-time · standard site

A full pentest, every finding proven. Once.

  • Full active scan across every module (CVE xref, XSS, CORS, TLS, headers, exposed files, redirects)
  • Every finding passes the verification gate before you see it
  • Raw request/response evidence attached to each finding
  • Branded PDF + shareable web report, findings explained like a human wrote them
  • Unauthenticated deep budget: 360 requests · 60 min · 20-finding target
  • Domain ownership required (DNS TXT or file upload)
Deep+
$299 / one-time · authenticated

The deep budget, plus your logged-in sessions.

  • Everything in the Deep Audit, at the same verification standard
  • Authenticated testing with your session cookie (member areas, dashboards, account flows)
  • Extended ceiling ~480 requests · 90 min
  • Raw request/response evidence attached to each finding
  • Domain ownership required (DNS TXT or file upload)
Monitor
$49/mo / per domain

One domain, watched. New criticals alert you.

  • 1 monitored domain, deep-depth scans included
  • Daily automated rescans
  • Diff alerts: new, resolved and regressed findings between scans
  • Findings cross-referenced against real NVD + CISA KEV data
  • Email report on every rescan
Pro
$199/mo / up to 5 domains

Up to 5 domains, monitored and re-scanned.

  • Up to 5 monitored domains
  • 3 team seats
  • Daily automated rescans
  • REST API + CI/CD gate
  • Everything in Monitor
Agency
$499/mo / up to 25 domains

White-label audits for your whole client roster.

  • White-label PDF reports
  • Client workspaces + 10 seats
  • Up to 25 monitored domains
  • REST API + CI/CD gate
  • Everything in Pro, per domain
Enterprise / MSP
Custom · from $1k/mo / bulk / pooled domains

Pooled domains, SSO, and a named contact.

  • Unlimited or pooled domain volume
  • SSO/SAML, full audit log and role-based access control
  • Custom modules and your own severity policy
  • SLA plus named-engineer review of shipped reports
  • On-prem / VPC scan runners for sensitive environments
Notra vs the scanners
 Classic scannersNotra
OutputHundreds of raw plugin & version matchesOnly the findings we can prove, ranked by real risk
EvidenceA version string and a guessThe raw request/response that proves it
False positivesYou triage themFiltered below a 0.8 confidence floor
DeliverableA CSV of noiseA branded, plain-language PDF
ContinuousOne-time snapshotScheduled rescans with email on every result
Who can read itA security engineer, if you have oneAnyone on the team
Questions
Is scanning my site safe?

Yes. Active probes use safe, non-destructive defaults with a per-target rate ceiling, and money-movement endpoints (cart, checkout, pay) stay untouched unless you agree to a sandboxed test. Every proof is a benign detection probe, never a weaponized exploit.

Do you need my passwords or source code?

No. Notra is black-box by default. It only sees what any visitor sees. Optional authenticated scans (Deep Audit) use a session cookie you paste in, encrypted immediately, used once for that run, deleted the moment it finishes, and called out plainly in the report.

How do you avoid false positives?

The verification gate. We throw out anything that can't attach evidence, re-run each candidate with a benign proof, de-duplicate, and hold everything to a 0.8 confidence floor before it reaches you.

Where do the CVEs come from?

We fingerprint your stack, then cross-reference NVD, CISA KEV, GHSA and OSV with version-range logic, and re-check continuously so a newly-published KEV on your stack raises an alert.

What stops someone scanning a domain they don't own?

A hard authorization gate. No active module runs until you prove control with a DNS TXT record or an uploaded file token, and every authorization is logged.

What if a scan fails?

It auto-retries once. If it still fails, it's automatically marked failed and refunded — no ticket to file. You never pay for a scan that didn't deliver.

See what’s actually exploitable.

Run the free scorecard in under a minute — sign in required, passive checks only. Upgrade to a verified deep audit whenever you’re ready.

https://