WE FIND BUGS.
BEFORE THEY DO.
The Pedro is an automated security intelligence platform. We run the same checks an attacker would — DNS enumeration, API exposure, auth weaknesses, dependency vulnerabilities, cloud misconfigurations — and surface them as actionable findings before someone with bad intentions gets there first.
Why we built this
The same vulnerability class keeps showing up, over and over. An API endpoint added six months ago, never audited. A debug route left open. A dependency with a known CVE that nobody got around to patching. Attackers run automated tools constantly — companies run manual audits once a year, if they're lucky.
Pedro closes that gap. Automated assessments, DNS-verified to ensure you can only scan what you own, with findings written in plain language and fixes you can apply the same day.
How it works
Before running any scan, Pedro requires you to add a DNS TXT record to the domain you want to assess. This is a hard requirement — no verification, no scan. It means no third-party domain can ever be scanned without that domain's owner having explicit control over its DNS, which makes authorization provable and auditable.
Once verified, Pedro runs 99+ automated checks across your domain — passive reconnaissance, active HTTP surface enumeration, authentication testing, API exposure detection, CMS-specific checks, and dependency analysis. Results are scored, ranked by severity, and surfaced in your report within minutes.
Agent Mode
On Professional and Enterprise projects, Pedro's Agent Mode goes further. An LLM-backed agent investigates your target the way a human tester would — following threads, chaining findings, and adapting based on what it discovers. It's not a replace for a manual pen test, but for most attack surfaces it finds the same classes of issues in a fraction of the time.
What we do with findings
Findings belong to you. Any personal data discovered during a scan (exposed user emails, phone numbers, PII) is masked by default in your report — you see enough to confirm the issue is real without us displaying raw records in full. We don't sell findings, we don't share them with third parties, and we don't retain them beyond your account.
The company
The Pedro is operated by Quick LLC, incorporated in Wyoming. We're a small team focused on one thing: making serious security tooling accessible to every company that ships software, not just the ones with a dedicated red team.
Questions, feedback, or responsible-disclosure reports: [email protected]
Ready to see what's exposed?
Add a DNS TXT record, run your first assessment, get your report in minutes.