About

Built because real pentests do not follow checklists.

AttackCompass exists so work saved during an authorized engagement makes the next step — and the final report — easier to stand behind.

Why

Keep the engagement coherent from discovery to report.

Origin

Who built this — and who it is for

Enough signal to answer “does this come from people who actually understand the job?” — without turning the site into a cult of personality.

Software architecture first

AttackCompass comes from people who care about coherent systems — state, evidence, and decisions that stay connected as work gets complicated.

Offensive security practice

Real engagements do not follow a straight checklist. Hosts lead to services. Logins open new paths. The product is built around that mess.

Operator as the protagonist

The pentester stays in control. AttackCompass ranks next steps and keeps proof ready for the report — it does not run the attack for you.

Principles

What we will not pretend

Try it on work that matters

Seven days of full access. No billing details required to start.