Knowledge Base
Guides and reference docs for getting the most out of Pentographer.
Getting Started
Getting Started with Pentographer Cloud
Learn how to register for the fully managed Pentographer Cloud, set up your workspace, and invite your security team.
Quick Start: Run Pentographer Locally
Get Pentographer running on your local machine in minutes for evaluation or development. Uses SQLite and default configurations.
Environment Variables Configuration
Reference guide for configuring Pentographer environment variables for database, session, storage, and AI access.
Self-hosting
Reverse Proxy and SSL Setup for Self-Hosted Deployments
Configure nginx or Caddy as a reverse proxy in front of Pentographer with automatic SSL via Let's Encrypt for production self-hosted deployments.
Self-Hosting Pentographer
Deploy Pentographer on your own server using Docker Compose, with full control over data residency, storage, and network configuration.
Upgrading a Self-Hosted Instance
Step-by-step guide for updating Pentographer to a new release on your Docker Compose deployment, including database migration and rollback procedures.
Core Features
Customer Profile Management
How to create customer records and isolate customer-specific assessment deliverables.
Project Lifecycle and Scoping
Learn how to manage project statuses, attach baseline test playbooks, and track justifications for status regressions.
Finding Editor and Version History
How to use the Markdown finding editor, attach evidence screenshots, configure CVSS scoring, and manage version history.
Finding Status Workflow
Understand the five finding statuses in Pentographer, when to set each one, and how status changes affect report snapshots and risk summaries.
Reporting, Templates, and Exports
Learn how to create reports, manage templates, and export deliverables as Word, PDF, or Markdown packages.
Playbook and Checklist Management
Standardize assessment baselines using system and organization playbooks, versioning, and JSON import or export.
Authoring Custom Report Templates
Build custom Word .docx report templates for Pentographer, control branding, structure finding sections, and share templates on the community marketplace.
Tracking Playbook Coverage During an Engagement
How to use Pentographer's playbook checklist to track test coverage, link findings to items, and report which areas were tested during an assessment.
AI & Integrations
AI Drafting Assistant and Review Tools
Use Claude to draft finding descriptions, generate executive summaries, review report text, and build playbooks.
AI Key Management and Key Encryption
Configure Anthropic API credentials, understand the key resolution hierarchy, and learn how Pentographer secures credentials using AES-256-GCM.
Scoped API Keys and OAuth Clients
Generate API keys, register OAuth clients, and authenticate external integrations using client credentials.
GraphQL API Reference
Query and mutate Pentographer data programmatically using the GraphQL API and the GraphiQL interface.
Model Context Protocol (MCP) Server Setup
Connect Claude Desktop, Cursor, or other AI agents directly to your Pentographer workspace using the Model Context Protocol.