Trust

Don't trust us. Verify us.

A pentest report is only as valuable as it is trustworthy. CarbonMantis seals a cryptographic record of exactly what ran during every scan — and gives you an open tool to verify it yourself, offline, against a key we can't secretly swap. Even we can't rewrite or backdate it.

The problem

Your pentest vendor is a trust concentration

When you hire pentest-as-a-service, you hand a vendor deep access to your systems — then rely on its output for remediation, board reporting, security questionnaires, and compliance evidence. That raises two questions most vendors can't answer:

  1. Did the scans I paid for actually run — as described? Or is the report partly boilerplate?
  2. Can the record be altered after the fact? If the platform is breached, an attacker can rewrite the audit trail to hide their tracks — and nothing stops a vendor from quietly editing or backdating a record either.

"Trust us, it's tamper-proof" is not an answer an auditor accepts. Proof is.

What every scan produces

Two independent, signed, append-only streams

Both are anchored to WORM (write-once, read-many) immutable storage. We anchor compact cryptographic checkpoints — signed digests, not your raw scan data — so the evidence is small and privacy-preserving.

Execution-fact attestations

A signed, monotonic record of what actually executed — the tools that ran, the targets, the scan units, the timestamps. The proof that the work you paid for happened, exactly as described.

A security audit trail

A tamper-evident record of every security-sensitive operation — credential handling, session brokering, lease redemption — so sensitive actions are accountable, not invisible.

How you prove it

Verification you run yourself — offline

You do not have to trust CarbonMantis's servers, database, or staff to trust the evidence. The proof is independent and offline.

1

Every checkpoint is digitally signed

ECDSA P-256 signatures cover a canonical record binding your organization, a sequence number, the log root hash, the previous checkpoint, the signing-key identity, and the issue time. Change a single bit and the signature no longer verifies.

2

The verification key is pinned out-of-band

The public key reaches you through a channel independent of the API that serves your data, and the verifier trusts a pinned keyset with no trust-on-first-use. A compromised API cannot hand you a forged record with a matching forged key — you already hold the real one.

3

You run an open verifier — offline

An open tool checks the signature (authentic, unaltered), the key validity window and revocation (no retired/compromised keys), and the hash chain + monotonic sequence (nothing inserted, removed, reordered, or rolled back). No live dependency on our infrastructure.

4

Cross-check the independent WORM anchor

The record is anchored to write-once, immutable storage with its own independent key and hash chain — proving non-equivocation: we cannot have shown a different history to a different party, and cannot have truncated or rolled the log back server-side.

Net: signature (integrity + authenticity) + chain & monotonicity (completeness + ordering) + key validity (freshness) + WORM anchor (non-equivocation) — all verifiableindependently, offline, against a key we cannot swap.

Why it's different

A record no one can rewrite

Don’t trust us — verify

Most vendors ask you to trust their word and their dashboard. CarbonMantis gives you evidence you verify yourself, with an open tool, offline, against a key we cannot swap.

Even we can’t alter your record

The design removes our own ability to silently rewrite or backdate your evidence — a rare thing to be able to say when we’re the ones holding the keys to your systems.

Breach-resilient by design

If the platform itself is compromised, the sealed evidence survives tamper-evidently — an attacker cannot cover their tracks without it being detectable.

Compliance-grade by construction

Immutable, timestamped, signed retention is exactly the shape of evidence that frameworks asking for tamper-evident record-keeping expect.

For compliance & GRC

Evidence you can hand to an auditor

Because the record is signed, immutable, and independently verifiable, it's built for the moments where "trust us" isn't enough:

Findings you can reproduce. Evidence you can verify. A record no one can rewrite.

Under the hood

The short technical version

Try it, then verify it.

50 free credits, no credit card. Run a scan and verify the sealed evidence yourself.

Request Early Access

Be first in line when we launch · we’ll email your invite