Notes, payloads and reports without a refusal in the middle
A pentest already has a RoE and a window. The model should help you inside that window, not decide that a SQLi payload is a matter for the safety team.
Pentest consultancies and internal appsec teams running scoped tests against systems they own or are contracted to test.
Why the mainstream APIs fail here
The useful questions on a test are exactly the ones a hosted model is trained to dodge: bypasses, chained exploits, realistic post-ex. You end up with two tools, one for the report and one for the work, and the work one is a laptop model with no audit trail.
How Redline is used for this
One Redline key per test, named for the client, capped at the hours you sold. Recon notes and payload drafts go through it. The report can go through a frontier model if you want the prose polished; the offensive steps do not have to.
A working loop
- Mint a key named for the client and the test window.
- Draft payloads and notes against the in-scope hosts.
- Revoke the key when the report is delivered.
Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.