v0.2.0 Alpha

Local AI pentesting for security teams

0xClaw gives security teams a local AI pentest workflow with real tool execution, visible operator control, and evidence that stays on the machine until the report is ready.

Need a team evaluation, BYOK discussion, or local deployment review? Talk to us.

150+
Security tools
12
Attack skills
3
Desktop platforms
Local
Evidence stays local
Quick answer

What security teams should expect from a local AI pentest tool

0xClaw is the local path when you want operator-visible testing, report-ready evidence, and a workflow that moves from first scan to handoff without shipping the whole process to a cloud platform. Start with Download if you want to try the workflow, open the Compare if you are still separating categories, and use Pricing once the operating model already fits.

Set scope and review gate

Start with authorized targets, decide who reviews agent output, and keep the workflow anchored to local evidence handling.

Run the local AI pentest workflow

Use the CLI and built-in security tools to move from recon and validation into findings a human operator can inspect.

Package the handoff

Use reports, retest guidance, and comparison pages to move from discovery into engineering handoff and tool evaluation.

Your AI red team, kept on the operator machine.

Autonomous pentesting that plans, adapts, and produces evidence your team can actually review.

Local operator

Keep the workflow on your machine, with a CLI built for repeatable operator control rather than a cloud demo.

Transparent reasoning

See why the agent chose a path, which checks it skipped, and where human review should stay in the loop.

150+ Security tools

Use scanners, enumerators, and exploit helpers without stitching together custom scripts.

Report-ready output

Turn findings into PTES-style reports with evidence, CVSS context, and remediation notes.

BYOK-friendly

Keep the deployment aligned with team policy when API usage or provider choice matters.

Human review

Stay in control of scope, exploit steps, and final handoff before anything leaves the workflow.

Pricing that matches how teams actually buy.

Starter proves fit, Pro covers full local execution, and Team supports shared delivery and higher volume.

Starter

Proof-of-fit for teams validating local AI pentesting before broader rollout.

$23/month
  • 20 scans/month
  • Recon and vulnerability checks
  • Bilingual reports
Get Started

Pro

Recommended

The full local AI pentest workflow for an individual security operator.

$63/month
  • 100 scans/month
  • Advanced exploit chains
  • API access and webhooks
Get Started

Team

Shared workspaces, higher throughput, and a procurement path for delivery teams.

$159/month
  • 500 scans/month
  • Shared workspace
  • Priority support
Get Started
AI Pentest Guides

Learn the local AI pentesting workflow before you buy

Start with the category definition, then move into workflow and tool-selection guides. These articles are the fastest path from curiosity to an operator-ready mental model.

Questions buyers ask before rollout

Fast answers for teams comparing local execution, cloud alternatives, and rollout fit.

What is 0xClaw?

0xClaw is a local AI penetration testing tool that runs on your machine, executes real security tools, and produces report-ready evidence without handing the whole workflow to a cloud service.

Is 0xClaw free to download?

Yes. 0xClaw is free to download and install on macOS, Linux, and Windows. Use the pricing page for the current Pro, Team, and credit details before rollout.

What is the difference between 0xClaw, NodeZero, and PentestGPT?

0xClaw is a local CLI tool, so scan evidence stays on your machine instead of a vendor cloud workflow. Unlike chat-only pentest assistants, 0xClaw actually executes attacks using 150+ security tools like nmap, nuclei, and sqlmap. Use the compare page for category fit and confirm commercial terms with each vendor directly.

Does 0xClaw work on Windows, Mac, and Linux?

Yes. 0xClaw ships as a native binary for all three platforms. No Docker, no Python environment setup, no dependency management. Download the installer, double-click, and you're ready to run your first pentest.