All documentation

Getting Started

PentestHub AI — Master Specification

This is the canonical Master Specification for PentestHub AI. All architecture, module, and roadmap decisions must trace back to this document. Do not fork or rewrite this file casually — amend it deliberately as the product evolves.


Core Philosophy

The platform must become the daily workspace of every pentester.

Users should no longer need to constantly switch between:

  • HackerOne
  • Bugcrowd
  • Intigriti
  • GitHub
  • Burp Suite documentation
  • PayloadAllTheThings
  • HackTricks
  • NVD
  • CVE databases
  • OWASP
  • Google searches
  • ChatGPT

Everything should exist inside one unified ecosystem.


Local-First Core Principle

Added 2026-07-16, superseding the implicit "backend executes everything" assumption in every section below that predates it. Full audit, decision record, and build plan: docs/migration/local-first-architecture-migration.md, docs/adr/0007-local-first-desktop-agent-architecture.md, docs/migration/desktop-agent-roadmap.md.

PentestHub AI is local-first. The backend must never be responsible for expensive computation. It exists only for: Authentication, User accounts, Workspace/Project/Target/Note metadata, Findings metadata, Activity timeline, Team collaboration, API keys, Preferences, Reports metadata, Synchronization, Notifications, RBAC, and Audit logs.

All computationally expensive work — Recon and Vulnerability tool execution, AI inference, local storage, file indexing, voice processing, local RAG, and report/PDF/Markdown/DOCX generation — runs in a new Desktop Agent (Tauri preferred; Electron acceptable only if a required capability has no workable Tauri equivalent), targeting Windows, Linux, and macOS.

Key rules that follow from this:

  • Private target/finding/evidence data never leaves the user's machine unless the user explicitly opts into sync.
  • AI never requires PentestHub's own API keys — every user brings their own provider (OpenAI, Anthropic, Gemini, OpenRouter, Ollama, LM Studio, DeepSeek, Mistral, Groq, Azure OpenAI), defaulting to local Ollama with no key, and degrading gracefully (never crashing) if Ollama is also unavailable.
  • Voice is local-first (Web Speech API primary; Whisper.cpp/Piper TTS as Desktop Agent fallbacks) — cloud TTS/STT is optional, never required.
  • RAG is local only (SQLite+embeddings or LanceDB) — no mandatory cloud vector database, no private data uploaded without opt-in.
  • Sync is user-selectable: Off / Metadata-Only (default) / Everything.
  • Offline mode works for workspace/projects/notes/findings/recon/ scanning/reports/local AI/voice/search.
  • Free tier is unlimited for everything that runs locally (Projects, Targets, Recon, Scans, Reports, Markdown/PDF export, Local AI, Voice, the Desktop Agent itself). Premium unlocks only Cloud Sync, Team Collaboration, Cloud Backup, Advanced Analytics, Priority Queue, Organization Features, and Enterprise Integrations — users never pay to scan locally.

This principle is being retrofitted onto Modules 1-6 via a phased, strangler-fig migration (see the roadmap doc) that preserves existing API contracts and does not break the current web UI. As of this writing, no migration code has shipped yet — Modules 3-6 still execute tool runners, AI calls, RAG, voice, and report rendering server-side, tracked as violations to fix in the roadmap's phases. See the audit doc's module-by-module findings for specifics.


Target Users

  • Bug Bounty Hunters
  • Penetration Testers
  • Red Teamers
  • Security Engineers
  • Students
  • CTF Players
  • SOC Analysts
  • DevSecOps Engineers

Platforms

Build everything from a single codebase where possible.

Required:

  • Responsive Website
  • Progressive Web App (PWA)
  • Android Application
  • iOS Application
  • Windows Desktop
  • macOS Desktop
  • Linux Desktop

Prefer Flutter for mobile/desktop and a modern web framework for the web.


Authentication

Support:

  • Google OAuth
  • GitHub OAuth
  • Email Registration
  • Login
  • Remember Me
  • Email Verification
  • Password Reset
  • Change Password
  • MFA / Two-Factor Authentication
  • Session Management
  • Device Management

User Dashboard

Each user has:

  • Personal Workspace
  • Saved Payloads
  • Saved Notes
  • Saved Reports
  • Saved Targets
  • Saved Recon Data
  • Saved CVEs
  • Saved Tools
  • Recent Activity
  • Favorites
  • API Keys
  • Notification Center

AI Assistant

Note: Built as Module 5 — AI Security Copilot — Phase 1 and Phase 2 both done (backend "brain": workspace/project-aware chat with automatic context gathering, RAG over pgvector, a 5-provider abstraction — OpenAI, Anthropic, Gemini, Ollama, OpenRouter — switchable by configuration with no keys wired yet, an editable prompt-module architecture, tool calling — search findings/recon/ evidence/notes/projects/targets/templates, create note, draft report, generate PoC, generate payloads — SSE token streaming with cancel/regenerate/continue, prompt-injection guardrails, and strict workspace/project isolation; frontend: /ai dashboard with conversation history, context indicator, suggested questions, streaming chat, Markdown rendering). Phase 2 (the "UX layer") adds: Voice Interaction (Web Speech API mic input + text-to-speech message playback, plus a backend SpeechProvider abstraction with 4 unconfigured cloud adapters — OpenAI, Azure, Google, ElevenLabs — same "ships complete, wired later" posture as the chat providers), a Smart Code Block toolbar (language badge, one-click download, wrap toggle, expand/collapse, fullscreen view), One-Click Code/Conversation Export (per-message download plus whole-conversation Markdown export), Terminal Mode (a monospace/dark toggle view for the whole conversation), Artifact Mode (a dedicated side panel for substantial generated content — PoCs, payload sets, draft reports — decoupled from the chat bubble), and Interactive Canvas (pannable/zoomable Mermaid diagram rendering for

Rendering diagram…

Integrate a powerful AI assistant.

The AI must understand cybersecurity.

Capabilities:

  • Explain vulnerabilities
  • Explain CVEs
  • Generate payloads
  • Analyze Burp requests
  • Analyze HTTP responses
  • Analyze Nmap output
  • Analyze Nikto output
  • Analyze ffuf output
  • Analyze nuclei output
  • Generate exploit ideas
  • Explain exploit chains
  • Create pentest reports
  • Explain code
  • Analyze JavaScript
  • Decode JWT
  • Decode Tokens
  • Explain APIs
  • Suggest next attack surface
  • Help with CTFs
  • Summarize writeups

Never hallucinate technical facts. Clearly distinguish verified facts from suggestions.


Voice Assistant

Note: Built as part of Module 5's AI Security Copilot, Phase 2. A SpeechProvider backend interface (apps/api/src/modules/ai/speech/) with 5 adapters — WEB_SPEECH (a documented client-side marker, always "configured") plus 4 real, unconfigured-until-keyed cloud adapters (OpenAI Whisper+TTS, Azure Speech, Google Speech, ElevenLabs TTS-only), surfaced via GET /ai/speech/providers. The only backend actually reachable today is the frontend's own Web Speech API integration (apps/web/features/ai/hooks/use-ai-voice.ts): a mic button appends recognized speech into the chat input (SpeechRecognition), and a Speak/Stop Speaking message action reads assistant replies aloud (speechSynthesis) — both degrade to hidden buttons on browsers without support (e.g. Firefox has no SpeechRecognition) rather than erroring. See docs/adr/0005-ai-security-copilot-module.md.

Support speech recognition.

Users can say:

"Analyze this request."

"Generate XSS payload."

"Explain this CVE."

"Open Recon."

"Create report."

"Search CVE."

Support voice replies where available.


Pentesting Workspace

Provide projects.

Each project contains:

Targets

Subdomains

Notes

Screenshots

Payloads

Credentials

Reports

Timeline

Bookmarks

Files

Tasks

Collaborators


Recon Module

Include:

WHOIS

DNS

Subdomain Enumeration

ASN Lookup

Technology Detection

HTTP Headers

robots.txt

sitemap.xml

Wayback URLs

Security Headers

TLS Analysis

Directory Discovery

Port Information

Fingerprinting

Visual Screenshots


Vulnerability Tools

Note: "Module 4" in the rollout order below was redefined by the project owner into the Vulnerability Engine (external scanner orchestration — Nuclei/ffuf/dirsearch/feroxbuster/Nikto — producing validated Findings; see docs/adr/0004-vulnerability-engine-module.md), not the client-side payload/encoder toolbox described in this section. The toolbox below remains an unimplemented, unscheduled idea, kept here for future reference.

Include:

Reverse Shell Generator

Payload Generator

SQL Injection Payloads

XSS Payloads

SSTI Payloads

Command Injection Payloads

LFI Payloads

RFI Payloads

XXE Payloads

SSRF Payloads

JWT Decoder

JWT Editor

JWT Generator

Hash Identifier

Hash Generator

Password Generator

URL Encoder

URL Decoder

Base64

Hex

Binary

Unicode

Regex Tester

JSON Formatter

XML Formatter

YAML Formatter

HTTP Formatter

Cookie Parser

Request Parser

Response Parser

Header Analyzer

CSP Analyzer

CORS Analyzer

JWT Cracker (only for authorized testing)

Wordlist Generator

Fuzz Helper


Bug Bounty Workspace

Support:

Target Notes

Scope Tracking

Program Notes

Recon Notes

Custom Checklist

Evidence

Screenshots

Findings

Severity Calculator

CVSS Calculator

Timeline

Submission History

Templates

Duplicate Detection

Markdown Editor


Report Generator

Generate professional reports.

Support:

PDF

Markdown

HTML

DOCX

Executive Summary

Technical Details

Risk Rating

Mitigation

Screenshots

Evidence

CVSS

OWASP Mapping

CWE Mapping


Knowledge Base

Include searchable resources for:

OWASP

HackTricks

Payload references

Cheat Sheets

Ports

Protocols

HTTP Status Codes

Linux Privilege Escalation

Windows Privilege Escalation

Active Directory

Cloud Security

Web Security

API Security

Mobile Security

Wireless Security

Cryptography

Reverse Engineering

Malware Analysis

Red Team

Blue Team

MITRE ATT&CK


CVE Center

Provide:

CVE Search

Filters

CVSS

Affected Products

References

Exploit Links

Patch Status

Vendor Links

Timeline


Integrations

Support integrations with services such as:

GitHub

Google Drive

Discord

Slack

Webhook endpoints

Email notifications

Calendar reminders


UI/UX

Modern dark-first interface.

Responsive.

Fast.

Keyboard shortcuts.

Command Palette.

Global Search.

Dockable panels.

Resizable layouts.

Professional dashboards.


Security

Use:

JWT with refresh tokens

Rate limiting

CSRF protection

CSP

Input validation

Secure headers

Encrypted secrets

Audit logging

Role-based access control

Secure file uploads

Session expiration

Account lockout after repeated failures


Admin Panel

Manage:

Users

Reports

Subscriptions

Feature flags

Analytics

Logs

Announcements

Support tickets

System health

API usage


Future Features

Team collaboration

Shared workspaces

Private organizations

Marketplace

Plugin SDK

Extension system

Browser extension

CLI tool

Public REST API

GraphQL API

Offline mode

AI automation workflows


Code Quality

Produce production-ready code.

Use clean architecture.

Use modular design.

Follow SOLID principles.

Write tests.

Document APIs.

Avoid duplicated code.

Ensure accessibility.

Optimize for performance and maintainability.

Every feature should be designed so that additional tools and integrations can be added without major refactoring.


Build Process (binding rule)

Never write the entire project at once. Always:

  1. Plan first.
  2. Build exactly one module at a time.
  3. Finish a module (production-ready, tested, documented) before starting the next.
  4. Every module must ship with tests and documentation before being considered done.

Locked Architecture Decisions

These decisions were made explicitly with the project owner and take precedence over the open-ended "prefer X" language above where they conflict.

AreaDecision
Repo structureMonorepo (Turborepo) at ~/pentesthub-ai
Web frontendNext.js (React, TypeScript)
Backend APINode.js / NestJS (TypeScript)
Mobile/DesktopFlutter (deferred until web core is stable)
First moduleAuth (email + Google/GitHub OAuth) + Dashboard shell

Monorepo layout (actual, as of scaffold)

text
pentesthub-ai/
├── PROJECT_SPEC.md
├── turbo.json
├── pnpm-workspace.yaml
├── apps/
│   ├── web/                    # Next.js 16 (React 19, TS) frontend
│   └── api/                    # NestJS 11 (TS) backend
├── packages/
│   ├── shared/                 # shared types / DTOs (@pentesthub/shared)
│   ├── ui/                     # shared design system / components (@pentesthub/ui)
│   ├── eslint-config/          # shared eslint flat configs (@pentesthub/eslint-config)
│   └── typescript-config/      # shared tsconfig bases (@pentesthub/typescript-config)
└── docs/
    └── modules/                # per-module design docs, ADRs

Package manager: pnpm (workspaces). Task runner: Turborepo (build, lint, check-types, test, dev pipelines all verified working end to end).

Module rollout order (subject to revision after each module ships)

  1. Auth (Module 1) — done (NestJS API: register, email verification, login, logout, JWT + refresh-token rotation with reuse detection, argon2 password hashing, forgot/reset/change password, Google/GitHub OAuth, TOTP MFA + backup codes, RBAC foundation, session/device management, audit logging, rate limiting, Swagger docs, seed data. See docs/modules/01-auth.md and docs/adr/0001-auth-module.md).
  2. Workspace Foundation + Dashboard UI (Module 2) — done (backend: Workspaces, Projects, Targets, Notes, Evidence, Attachments, Tags, event-driven Activity Timeline, Search — all domain-agnostic storage, no Recon/AI logic attached; frontend: full Next.js dashboard covering Module 1 auth UI plus every Module 2 resource, Settings, command palette, dark-mode-first responsive shell. See docs/adr/0002-workspace-foundation-module.md).
  3. Recon Module (Module 3) — done (backend: 14 tools — Subfinder, Amass, Assetfinder, HTTPX, Katana, Gau, Waybackurls, DNSx, Naabu, Nmap, WhatWeb, Gowitness, WHOIS, ASN lookup — behind one ToolRunner/ Normalizer abstraction, a distributed-worker-safe job queue with atomic claiming/retry/cancel/orphan-sweep, a polymorphic ReconFinding model with dedup-key + unique-constraint deduplication, "Promote Finding to Target," SSE live logs; frontend: job list/detail/progress/ findings UI integrated into the target and project pages plus a workspace-wide /recon landing page. See docs/adr/0003-recon-engine-module.md).
  4. Vulnerability Engine (Module 4) — done. Redefined from this document's original "Vulnerability Tools" placeholder (a client-side encoder/payload-generator toolbox) into a full scanner-orchestration engine per explicit direction from the project owner: Recon Assets → Scan Jobs → external scanners (Nuclei, ffuf, dirsearch, feroxbuster, Nikto behind one ScannerRunner/Normalizer abstraction, extension points reserved for SQLMap/XSStrike/Dalfox/Wapiti/OWASP ZAP) → normalized VulnFindings (severity/CVSS/CWE/OWASP category, dedup-key
    • unique-constraint deduplication, auto-attached text Evidence) → Scan Queue with Pause/Resume/Cancel/Retry/Priority/Worker Heartbeat/Dead Worker Recovery → Activity Timeline → events reserved for a future AI hook. The original "Vulnerability Tools" payload/encoder toolbox this section used to describe is not built and isn't currently on the roadmap under that name; the encoder/JWT/hash-utility items listed above this section remain unimplemented client-side utilities, not part of Module 4. See docs/adr/0004-vulnerability-engine-module.md.
  5. Bug Bounty Workspace (Module 6) — done. Merges this document's original "Bug Bounty Workspace" and "Report Generator" placeholders into one module, the same way Module 4 absorbed "Vulnerability Tools": Programs (platform/status/rules/severity-matrix/disclosure policy) with a Scope Manager (9 scope-item types, IPv4 CIDR/range auto-classification, OUT_OF_SCOPE-wins-over-IN_SCOPE), a Program Importer (HackerOne/Bugcrowd/ Intigriti/Markdown/JSON), a read-through Asset Inventory over Targets + Recon/Vuln findings + Notes/Evidence (no new storage), a Finding Lifecycle stage machine (New → Triaged → Verified → Reported → Resolved → Closed → Archived, plus Duplicate/Need More Info side-branches), a Bug Report Generator (one persisted report rendered into 5 platform templates, PDF/Markdown/HTML/JSON/CSV export) with an AI Report Draft Assistant and lexical+semantic Duplicate Detection (both reusing Module 5's AI seam), a Payload Library (16 categories, seed + custom entries, AI explain), a Personal Knowledge Base, Bookmarks, a Dashboard + Statistics view, a Calendar with a self-scheduling deadline-notifier poller, Notifications, and Global Search — plus this codebase's first use of optimistic locking (on BugReport.version). Frontend: 11 pages under /bugbounty. See docs/adr/0006-bug-bounty-workspace-module.md and docs/releases/module-6-release-notes.md.
  6. AI Assistant integration (Module 5) — Phase 1 and Phase 2 done. Built as the "AI Security Copilot": workspace/project-aware AI Chat with automatic context gathering (no manual pasting), a RAG layer over pgvector (per-workspace/per-project isolated memory), a 5-provider abstraction (OpenAI/Anthropic/Gemini/Ollama/OpenRouter — switchable by config, no keys wired yet per explicit direction), an editable prompt-module architecture (system/security/recon/finding-analysis/ report/coding, never hardcoded in controllers), a provider-agnostic tool-calling framework (search findings/recon/evidence/notes/projects/ targets/templates, create note, draft report, generate PoC, generate payloads) built to be extended by future modules without touching the chat engine, SSE token streaming with cancel/regenerate/continue, prompt-injection guardrails, and workspace/project isolation enforced on every command/query. Frontend: /ai dashboard (conversation history, context indicator, suggested questions, streaming chat, Markdown rendering). Phase 2 adds the "UX layer": Voice Interaction (Web Speech API mic input + speak-aloud replies, backed by a SpeechProvider abstraction with 4 unconfigured cloud adapters), a Smart Code Block toolbar (language badge, download, wrap, expand/ collapse, fullscreen), One-Click Code/Conversation Export, Terminal Mode, Artifact Mode (a dedicated side panel for substantial generated content), and Interactive Canvas (pannable/zoomable Mermaid diagrams). See docs/adr/0005-ai-security-copilot-module.md.
  7. CVE Center
  8. Knowledge Base (workspace-wide/cross-project — distinct from Module 6's per-user Personal Knowledge Base, which is done)
  9. Admin Panel
  10. Integrations, Voice Assistant, Mobile/Desktop (Flutter), Marketplace/Plugin SDK

Note on items 7-10 above and this list's staleness: items 7-10 are the original placeholder text and predate Modules 7-16 actually being built — they were not updated as those modules shipped and no longer reflect this project's real status (e.g. Mobile/Desktop exist as Modules 12/7, not as item 10's vague placeholder). A full rewrite of this section to match the project's actual module history was judged a separate, larger task and was not attempted as part of Module 16's documentation pass. For authoritative per-module status, see docs/releases/module-{N}-release-notes.md for Modules 2, 4, 5 (phase 1 & 2), 6, 9, 10, 11, 12, 13, 14, 15, 16, and 17 — the most recent, which covers Global Security Intelligence, the Bug Bounty platform (submissions/rewards, Safe Terminal, Playbooks, Risk Engine, CVE matching), and Collaboration (Watchers/Reactions, a real-time SSE gateway, Public Sharing, Knowledge Graph queries, AI Memory, and an Extension API Registry). Mobile, Desktop Agent, and Browser Extension updates for Module 16 were explicitly deferred by user decision and are not part of it. Module 17 (docs/releases/module-17-release-notes.md) covers the Security Operations Center — attack surface monitoring, a Community Edition-friendly Threat Intelligence Engine (public-feed adapter + manual STIX/TAXII import), Incident Management with an AI-assisted investigation workflow, Remediation tracking, an SLA Engine, Risk Engine v2, and the composed SOC/Executive Security dashboards — again reusing the existing EventBus, graph, Evidence, execution-engine, report, and search infrastructure rather than duplicating any of it. See also docs/soc.md, docs/threat-intelligence.md, docs/incidents.md, docs/remediation.md, docs/risk.md, and docs/sla.md for per-surface detail. Module 18 (docs/releases/module-18-release-notes.md) adds no product features — it is a production-hardening, observability, and reliability pass across Modules 1-17: request correlation, structured logging, health/readiness endpoints, job-queue race/idempotency fixes, SSRF/ rate-limiting/file-storage security audits, AI prompt-injection regression tests, SSE hardening, Prometheus metrics + Alertmanager config, backup/recovery documentation, frontend security headers, a dependency audit, CLI/SDK/Desktop/Mobile reliability fixes, new security-critical and disaster-recovery regression tests, and a final grep-based security sweep. See that release-notes file's "Known gaps" section for every issue this module found and disclosed rather than fixed.

Post-Module-18 reconciliation checkpoint (2026-09-08, docs/reviews/0021-post-m18-sdk-reconciliation.md): Module 18's dependency audit (Phase 22) had claimed packages/sdk-python and packages/sdk-go "do not actually exist in this repository," despite earlier module task histories (Module 16's #402/#429, Module 17's #491) reporting Python/Go SDK work as complete. A dedicated audit against the repository itself (not against prior reports) found that claim was wrong: both SDKs exist, complete and at full 14-resource parity with the TypeScript SDK, at sdks/python and sdks/go — a different path than the one Phase 22 checked, established since Modules 7-10. The earlier module task histories were accurate; Phase 22's audit methodology (checking one path convention and concluding absence without searching further) was the error, and has been corrected in place in docs/reviews/0014-m18-dependency-security-audit.md and docs/releases/module-18-release-notes.md rather than silently rewritten. Two small, real, previously-undisclosed gaps were found and fixed during this checkpoint: the Go SDK's HTTP transport had no request timeout (http.DefaultClient, same defect class Module 18 had already fixed in the TypeScript SDK — corrected to a 30s default, unverified by go build/go test since the Go toolchain remains unavailable in this sandbox, consistent with every prior module); and .github/dependabot.yml was missing pip/gomod entries for the two SDKs (added). Both SDKs' READMEs had a stale pre-Module-16 "Scope (v1)" list (corrected). The Python SDK was verified for real in this pass: python3 -m compileall clean, and python3 -m unittest tests.test_client -v — 5/5 tests genuinely passed in this sandbox.

Local-first migration status (2026-07-16): per the Local-First Core Principle above, Modules 3-6 as described in this list still execute server-side today. Module 3's 14 tool runners and Module 4's 5 scanner runners are slated to move entirely into the new Desktop Agent (backend keeps only job/result metadata, history, activity, and stats). Module 5's provider execution currently uses server-configured keys (a violation, fixed first in the migration's Phase 1), and its RAG (pgvector) and voice (cloud speech adapters) are slated to move to a local vector store and Whisper.cpp/Piper respectively. Module 6's Bug Report template rendering is slated to move client-side (Markdown/HTML/ PDF/DOCX generated locally, only report metadata synced); its AI Draft Assistant and semantic Duplicate Detection inherit Module 5's move. Item 10's "Mobile/Desktop (Flutter)" placeholder is superseded by the Tauri Desktop Agent decision in ADR 0007 for the desktop portion specifically (mobile remains open). Full detail: docs/migration/local-first-architecture-migration.md, docs/adr/0007-local-first-desktop-agent-architecture.md, docs/migration/desktop-agent-roadmap.md.

Module 7 — Desktop Agent (2026-07-19): source-complete. The Tauri desktop app at apps/desktop now has its own Local Tool Runner (16 tools), Background Job Queue, local SQLite database, Sync Engine (Off/Metadata-Only/Everything, conflict resolution, retry queue, multi-workspace), Local AI (9 providers, streaming, tool calling), Local RAG (FTS5 + embeddings, fully offline), Voice (Web Speech API + whisper.cpp/Piper fallback), File Manager/Evidence Library (SHA-256 dedup, Folder Watch), Report Generator (PDF/MD/HTML/DOCX/TXT/JSON/ZIP, all local), a full Desktop AI Chat, a Plugin Manager (Nmap/Burp/ZAP/ Metasploit/Custom Script), and Settings/Auto-Update/Security. This fulfills the "Modules 3/4/6 move client-side" migration items described above. Not yet compiled/runtime-verified — see docs/modules/07-desktop-agent.md's "Verification handoff" section.

Module 8 — Browser Extension + Burp Suite Integration (2026-07-20): source-complete. A new Local Bridge Server (apps/desktop/src-tauri/src/bridge/) gives the Module 7 Desktop Agent a real 127.0.0.1-only, bearer-token-authenticated, AES-256-GCM-encrypted HTTP+WebSocket API, since Tauri's invoke() IPC is unreachable from outside its own webview. A Manifest V3 Browser Extension (apps/browser-extension, Chrome/Edge/Brave/Opera + a Firefox build) talks to it for Target Capture (19 one-click actions), Recon Shortcuts (7), an AI Side Panel (11 quick actions, streaming Markdown/Mermaid/voice), a DevTools panel (8 tabs), a 12-category/ 35-entry Payload Library, 6-format Export, and Bug Bounty scope import (HackerOne/Bugcrowd/Intigriti/YesWeHack/Synack). A Burp Suite extension (extensions/burp, Jython/legacy Extender API — Community + Pro compatible) adds the same capture/finding/AI-context actions from Burp's context menu. Sensitive-data capture (cookies, storage, tokens) requires explicit confirmation, enforced both client-side and server-side. Live Sync keeps the current Project/Target/Conversation in sync across the desktop app, browser, and Burp via a WS ping + REST snapshot protocol. Not yet compiled/runtime-verified (no browser, Burp Suite, or completed npm install in the build environment) — the pure-logic TypeScript modules and the cross-language AES-256-GCM/HKDF crypto were independently verified via direct Node execution; see docs/modules/08-browser-extension.md's "Verification handoff" section and docs/adr/0008-browser-extension-burp-integration.md.

Module 9 — Bug Bounty Platform + Collaboration + Reporting Suite (2026-07-20): source-complete. Extends Module 6's per-hunter workflow into a full team platform: a multi-platform Program Manager (favorite/safe-harbor/rate-limits) with an update-detecting Program Importer (SHA-256 fingerprint + human- readable diff, never destructively reclassifies existing scope on reimport), Scope Manager asset-type/status extensions, a Finding Manager with a real CVSS 3.1 calculator plus CWE/CAPEC/OWASP/MITRE ATT&CK mapping, a Report Builder with custom templates, AI grammar correction and technical review, and a TXT export (DOCX disclosed as unimplemented — no document-generation dependency installed); a new Collaboration layer (workspace invites, 3 new roles slotting between ADMIN and MEMBER, comments with @mentions, assignments, task lists, a read-through activity feed); 7 new Bug Bounty Dashboard widgets; an AI Bug Bounty Assistant (9 capabilities — review/payloads/PoC/repro/ impact/remediation/severity/attack-paths/engagement-summary, all "propose, don't auto-apply"); Knowledge Base entry kinds (playbooks, CVE references, tool references, AI conversation snapshots) plus tagging; scheduled Automation jobs; multi-channel Notifications (Discord/Slack/Telegram/custom API/webhook/email — email disclosed as unimplemented, no provider configured) with AES-256-GCM-encrypted channel secrets; a filterable Analytics rollup distinct from Module 6's Statistics; Global Search extended to AI chats/tags/tasks; a Public REST API (personal/workspace API keys, HMAC-signed webhooks, rate limiting, OpenAPI); and a security-hardening pass that closed a plaintext-secret gap on WebhookToken/NotificationChannelConfig, fixed two pre-existing AuditEventType import bugs, added the missing WORKSPACE_MEMBER_* audit-trail writes, and documented the full Permission Matrix. Frontend and a full apps/api typecheck/test run were not independently re-verified in the sandbox this module was built in (the same environment constraint noted for Modules 7-8); all changes were reviewed by hand against the exact repository-interface signatures they call, and packages/shared's typecheck was re-run clean after every shared-type change. See docs/adr/0009-bug-bounty-operating-system.md, docs/modules/09-bug-bounty-operating-system.md, and docs/security/permission-matrix.md.

Module 10 — Enterprise Platform + SaaS + Global Infrastructure (2026-07-22): source-complete. The largest module by scope to date — fourteen subsystems: real multi-tenant Organization/Team above the existing Workspace boundary (additive, doesn't replace it); a Postgres-native claim-based Distributed Job System (no new message broker); a Plugin Marketplace with a permission-acceptance model (sandboxing is contractual today, not a separate execution runtime — disclosed follow-up before accepting untrusted third-party plugins); an Integrations framework routing every provider action through one generic executor; Team Workspaces; Enterprise Reporting/Analytics reusing Module 6/9's rendering patterns; a full API Platform (GraphQL, an expanded real webhook delivery pipeline with retry/backoff/dead- letter, and TypeScript/Python/Go SDKs — a cross-reference audit mid- module caught and fixed several drifted fields in the Go SDK); a Workflow Automation Engine (nine step kinds, real integration with Reporting/Notifications/AI/Integrations, not stubs); Compliance (retention enforcement, backup snapshots, a GDPR export pipeline — a mid-implementation privacy bug that would have leaked cross-user audit data was caught and fixed before shipping); Observability (Prometheus metrics, OpenTelemetry tracing, structured logging, health checks); High Availability (every Module 9/10 background poller — seven services — is now safe at any replica count via a new Postgres-row-based distributed lease, closing a previously-documented single-replica limitation); Security Hardening (a Content-Security-Policy fix that would otherwise have broken Swagger UI in any deployment that enabled it, plus HSTS/ clickjacking headers); CI/CD (GitHub Actions — lint/typecheck/test/build, Docker image publishing, CodeQL + dependency audit — the first environment in this project's history with an actual Go toolchain, finally compiling the Go SDK for real); and four Production Deployment paths (Docker Compose, Kubernetes with autoscaling, Linux systemd, Windows Services) documented with an explicit accounting of what's genuinely production-hardened by the application itself versus what remains a deployment-specific responsibility (Postgres itself has no built-in HA in any of these paths — call it out before treating this as a solved problem). packages/shared was re-verified clean (tsc --noEmit) after every shared-type change; a full apps/api typecheck could not complete within this sandbox's command timeout, and the newly-added @opentelemetry/* tracing dependencies were never pnpm install'd here (no registry network access) — both disclosed, consistent with the same environment constraint noted for Modules 7-9. Every file was manually re-verified after editing, including a direct cross-check of Prisma field names against schema.prisma rather than assumed. ci.yml is the first real, automated verification pass this code will receive — treat it as authoritative. See docs/adr/0010-enterprise-platform.md, docs/modules/10-enterprise-platform.md, docs/releases/module-10-release-notes.md, and deploy/README.md.

Module 11 — AI Security Copilot + Autonomous Multi-Agent System (2026-07-26): source-complete. Adds a Master AI Orchestrator (AgentOrchestratorService) on top of Module 5's existing single-turn AI chat: a free-text goal is decomposed into a tree of AgentTasks, delegated across twelve specialist agents (Recon, Web, API, Mobile, Cloud, Active Directory, AI Research, Exploit Analysis, Report Writer, Code Review, Risk Assessment, Workflow Coordinator — the last able to delegate further sub-tasks), executed with dependency ordering, bounded concurrency, automatic retry, and a self-evaluation critique pass before completion — sharing Module 5's provider abstraction and tool-calling framework rather than forking them. Alongside the orchestrator: a searchable AI Knowledge Base (OWASP/CWE/CAPEC/MITRE ATT&CK/NIST/CVE, opt- in semantic reindex into the existing RAG store); an Explainability layer (pure aggregation of already-persisted reasoning/confidence/evidence into one "why did the system conclude this" narrative — no new persisted concept); per-workspace Privacy Mode (CLOUD/LOCAL/HYBRID) enforced at the provider-resolution seam every AI/agent call passes through (disclosed as narrower than ADR 0007's full local-first definition — it restricts provider choice, not execution location); four performance fixes from a dedicated review pass (an SSE fast path, a batched tool-call-log query fixing two independent N+1s, an invalidate-on-write Knowledge Base cache, a batched memory-chunk insert); a new AgentRunsController/KnowledgeBaseReferencesController HTTP surface (list/create/get/cancel/retry/explain a run, plus a live @Sse() progress stream mirroring Module 5's chat-stream pattern exactly) — the first way for a human user or the frontend to reach the orchestrator at all, previously only an internal Workflow Automation step could; and a new /agent + /knowledge-base frontend surface, deliberately kept separate from Module 5's existing /ai chat page since a multi-agent orchestration run has a fundamentally different shape than a chat turn. packages/shared and a full apps/api project-wide tsc --noEmit + eslint pass both completed and stayed clean this module — the first module since 6 where that full backend verification loop actually ran to completion in this sandbox (via a detached-background-process technique that works around the environment's foreground command timeout). The identical technique did not reproduce for apps/web or for Jest later in the same session; both were instead verified by direct manual cross-reference against the real shared DTOs and call signatures, which caught and fixed one real type error (a tuple-inference bug in the new Knowledge Base page). Five new Jest spec files were added to the agent module (previously zero) and a pre-existing, since-stale ai-provider-registry.service.spec.ts was found and rewritten to match this module's async, privacy-mode-aware provider resolution. See docs/adr/0011-ai-security-copilot-multi-agent-system.md, docs/modules/11-ai-security-copilot-multi-agent-system.md, and docs/releases/module-11-release-notes.md.

Module 12 — Cross-Platform Mobile Application (Flutter) (2026-07-28): source-complete. Adds apps/mobile, a Flutter app (Clean Architecture, feature-first, Riverpod, GoRouter, Dio, Hive + sqflite) joining apps/web and apps/desktop as a third first-class client of apps/api, covering Auth (full Module 1 integration: email/Google/GitHub, MFA, refresh-token rotation, biometrics/PIN device lock, secure token storage), Dashboard, offline-first Projects/Targets/Findings (a shared SyncEngine/outbox pattern — offline writes apply optimistically to a local sqflite row and sync on reconnect via a per-entity SyncPushHandler), Reports, an AI Security Copilot screen (Module 11 integration: streaming chat over a hand-rolled SSE client since Flutter has no built-in EventSource, Markdown/syntax-highlighted code/Mermaid rendering, voice push-to-talk, Master Orchestrator run tracking, Knowledge Base search), Voice (on-device STT/TTS), Notifications, Evidence Capture (camera/gallery/ file/video/mic/QR, on-device SHA-256 hashing, offline upload queue), File Manager, Global Search (online + an offline FTS5 fallback), Settings (incl. Module 11 Privacy Mode), Workspace, Analytics (fl_chart), and security hardening (encrypted storage, certificate pinning, jailbreak/ root detection, clipboard auto-clear, session timeout, remote logout). Deliberately avoids Freezed/riverpod_generator/json_serializable codegen in favor of Dart 3 native sealed class state unions, since the authoring sandbox had no reachable Flutter/Dart toolchain at all (storage.googleapis.com, where the Flutter engine/Dart SDK are hosted, is blocked by the network allowlist) — every file was hand-authored and manually cross-referenced against real packages/shared contracts instead of compiler-verified, a stricter constraint than any prior module faced, and one disclosed in full in ADR 0012 §8. Manual review still caught and fixed three self-authored bugs (a malformed color hex literal, a ProviderContainer double-construction bug in main.dart's bootstrap, and a data-mapping typo in the Analytics bar chart). android/ and ios/ contain only hand-authored AndroidManifest.xml/Info.plist partials — the Gradle/Xcode native scaffold must be generated on a real machine via flutter create --platforms=android,ios . before this module builds at all, and flutter analyze/flutter test/flutter build have not been run against this source. See docs/adr/0012-mobile-application.md, docs/modules/12-mobile-application.md, docs/releases/module-12-release-notes.md, docs/mobile/mobile-architecture-guide.md, docs/mobile/flutter-development-guide.md, and docs/mobile/api-integration-guide.md.

Module 13 — AI Automation Platform + MCP Ecosystem + Security Agent SDK (2026-08-06): source-complete. Adopts the Model Context Protocol (2025-06-18) as the platform's extensibility substrate: a standards- compliant MCP server (POST /mcp/rpc — initialize/tools/list/ tools/call/resources/list/resources/read/prompts/list/ prompts/get, API-key + scope-scoped sessions) exposing 15 tools (every one dispatching an existing CommandBus/QueryBus handler, no parallel logic), 13 read-only resource types, and Module 11's Prompt Registry; and a dependency-free McpClient (@pentesthub/sdk) making the platform an MCP consumer too. On top of that: an AI Agent SDK (packages/agent-sdk) with eleven built-in prompt-specialist agents (Recon, Web Pentest, API Security, Cloud Security, AD Assessment, Code Review, Threat Modeling, Bug Bounty Assistant, Report Writer, Knowledge Curator, Workflow Agent — all instances of one shared factory, not bespoke classes) plus a CUSTOM agent kind; Workflow Builder extensions to Module 10's engine (parallel/approval/MCP-tool-call steps, WEBHOOK/EVENT triggers) and a matching Event Bus expansion; a Plugin SDK (node:vm hook sandboxing, confirmed-real Ed25519 code signing) and Script Engine (sandboxed JavaScript with a real wall-clock timeout race, a capability-gated pentesthub.* global, PYTHON rejection) sharing one hardened untrusted-code execution primitive; an Automation Marketplace (the existing Plugin Marketplace, now also listing Agent SDK/Script/Workflow artifacts); Local Execution (a relay queue letting the backend or an external MCP client ask a user's Desktop Agent/Browser Extension to run something locally); AI Evaluation (scores agent/tool/script output against a metric catalog); six new Observability Prometheus series plus a GET /observability/ai-platform dashboard aggregating every Module 13 automation surface; a Developer Portal (browsable catalog, a real "try it" tool-call endpoint, a usage dashboard — regular JWT REST, not an MCP session); and packages/cli (@pentesthub/cli), a dependency-free CLI built entirely on the existing SDK/shared contracts. A real, pre-existing bug was found and fixed during the Tests pass: MetricsRegistryService's Histogram.render() was double-cumulating already-cumulative bucket counts, silently corrupting every Prometheus histogram this codebase exposes (including the Module 10 HTTP-duration series) — caught by hand-deriving expected values for a new histogram test. packages/shared was re-verified clean (tsc --noEmit) after every shared-type change, and packages/cli — small and freestanding — was independently verified via a manual node_modules symlink to sibling workspace packages plus a direct tsc --noEmit, a genuine clean compile; apps/api's ~970-file project remained too slow to fully typecheck or Jest-test in this sandbox (the same constraint disclosed in every module since Module 7 — no pnpm binary and no registry access here either), so every apps/api edit was manually cross-checked against already-verified sibling files instead, and three new Jest spec files were written and reasoned through by hand rather than executed. See docs/adr/0013-ai-automation-platform-mcp-ecosystem.md, docs/modules/13-ai-automation-platform-mcp-ecosystem.md, docs/releases/module-13-release-notes.md, and docs/mcp/mcp-guide.md.

Module 14 — Cloud Platform, Enterprise SaaS & High Availability (2026-08-10): source-complete. Closes the gaps Module 10 explicitly left open: three pluggable infrastructure provider seams (QUEUE_PROVIDER memory/Redis, CACHE_PROVIDER memory/Redis/disk, STORAGE_PROVIDER local/S3-compatible — each defaulting to the zero-external-dependency binding, each consumed only through an interface); High Availability (PollerLeaseService generalized into a reusable distributed-lock/ leader-election primitive, with proactive lease release on graceful shutdown for faster failover); Distributed Worker extensions (a canonical job-type-category vocabulary, worker version reporting); Database support (pool sizing, optional read-replica routing, a migration drift-validation script now wired into CI); a real backup system (encrypted pg_dump/config/storage backups, checksummed verification, restore instructions, a recovery-test script) built on the same storage abstraction as everything else; Security (opt-in mTLS, IP allow lists, secrets-management/permission-matrix/WAF docs); an Admin Console (one call aggregating cluster/worker/queue/cache/ storage/database/backup/licensing state); Enterprise-only Tenant Management (billing/branding/usage, a new EditionGuard that treats an unlicensed deployment as trusted rather than locked out); an API Gateway (opt-in per-route response caching); Auto Update (check-and- notify across every client, never silent self-replacement except the pre-existing Tauri desktop path); and production-grade CI/CD (PR-validation/release workflow separation, Turborepo caching, Docker builds with SBOM/provenance/Trivy scanning/cosign signing, a new desktop CI workflow, release-time SBOM generation, secret-gated npm/PyPI publishing). A dedicated Performance pass fixed one real N+1 (GetAvailablePluginUpdatesHandler); a dedicated Community Edition guarantee audit confirmed the standing "no mandatory paid service" guarantee holds across every Module 14 subsystem and, in the process, found and fixed a real bug (deploy/k8s/01-configmap.yaml's QUEUE_PROVIDER: "in-memory" didn't match the zod schema's accepted values and would have failed boot validation as shipped). This module's sandbox verification hit a different set of constraints than Modules 7-13's "no pnpm, no registry access" ceiling: pnpm and a degraded-but-present network were both available, but the turbo npm package itself was never fully installed in this sandbox (only a dangling .bin/turbo symlink), so the requested pnpm turbo run build lint check-types test --force verification could not execute here at all; direct tsc/prisma validate invocations hung with zero output, root-caused to filesystem I/O latency on the mounted host folder rather than a code defect; and no Docker daemon or kubectl was available for image builds or live manifest validation. What did verify cleanly: structural YAML parsing of every new/modified CI workflow and Kubernetes/Compose manifest (9 files, all passed). No git commit was made for this module's work pending that verification — see docs/adr/0014-cloud-platform-enterprise-saas-ha.md, docs/modules/14-cloud-platform-enterprise-saas-ha.md, docs/releases/module-14-release-notes.md, docs/architecture/{api-gateway,auto-update,ci-cd}.md, and docs/reviews/{0006-module-14-performance-review,0007-module-14-community-edition-guarantee}.md.

Module 15 — Production Hardening, Monetization & Marketplace (2026-08-14): source-complete. Answers the questions every prior module's release notes deferred: a PaymentProvider abstraction with a Stripe adapter (plain fetch(), deliberately no stripe npm SDK) over new Subscription/Invoice/Plan/PaymentMethod/QuotaPolicy/ UsageCounter tables, hosted checkout, and a StripeWebhookController (POST /billing/webhook/stripe) verifying Stripe's own HMAC signature scheme independently of Module 14's pre-existing generic billing webhook; UsageService/QuotaService metering and enforcing configurable per-scope limits (BILLING_PROVIDER defaults to none, and the FREE plan's limits are UNLIMITED by seed default, so a self-hosted deployment is never throttled by default); Marketplace security (publisher verification, package checksums, enforced per-plugin permission declarations via PluginPermissionGrant); a versioned Public API v1 layer and expanded API key management (IP allowlists, per-key rate limits, rotation lineage); nine outbound Integrations (Slack/Discord/Telegram/email/GitHub/GitLab/Jira/Linear/ Microsoft Teams) plus a generic webhook, all through one IntegrationConnection/IntegrationProvider abstraction; AI cost control (AiModelPricingService/AiBudgetEnforcerService, per- workspace/organization spend budgets with provider/model fallback); privacy groundwork (self-service data export/deletion, telemetry opt-out, an opt-in privacy-aware TelemetryModule off by default, documented in the new PRIVACY.md and docs/compliance/gdpr-readiness.md); i18n (English/Uzbek/Russian) and an accessibility audit across web/ mobile/desktop; first-run onboarding and an isolated, read-only Demo Mode; Operability (GET /observability/health/diagnostics, a request-correlation ID threaded from AsyncLocalStorage through every AppException and into root/dashboard-segment React error boundaries, and a Support ticket queue — deliberately without a triage UI, since no deployment-wide platform-admin role exists yet, the same posture Module 14's Tenant Management and Admin Console already established); Release engineering (CHANGELOG.md, a RELEASE_CHANNEL env var, root/app package.json versions synchronized to the module-tracking scheme for the first time, 0.15.0); and a Feature Flags system (FeatureFlagsService.evaluateAll() resolving USER > WORKSPACE > ORGANIZATION overrides, then editionRules reusing Module 14's EditionService.isEnterpriseFor(), then defaultEnabled — management endpoints exist and work but, matching the same admin-role gap, are reachable via Swagger/curl only). Dedicated Performance (QuotaService.resolveLimit()'s sequential-findFirst-per-scope loop collapsed into one findMany), Security (two passes — see docs/reviews/0008-m15-security-hardening-review.md and its 0011-module-15-security-review-followup.md follow-up), UX (a missing loading state found and fixed on the Diagnostics page), and Community Edition guarantee passes all ran and are documented in docs/reviews/. This module's sandbox verification constraint is strictly worse than every prior module's: discovered while building the Stripe webhook, the root package.json files for @nestjs/common, @nestjs/swagger, @nestjs/cqrs, @nestjs/config, and @prisma/client are physically missing from this sandbox's pnpm store (confirmed via direct filesystem inspection and a plain node -e "require.resolve(...)" failure), meaning apps/api's tsc --noEmit cannot complete here at all, not merely slowly — every module back through Module 7 could at least attempt a slow/partial compiler pass; this one couldn't attempt one at all. jest remains absent from this sandbox for the same standing reason disclosed since Module 7; three new spec files (Stripe webhook signature verification, the quota N+1 fix, feature-flag precedence rules) were written and manually traced against their targets' real control flow but never executed. npx prisma generate / a real migration have not run here either — Module 15's schema changes are captured in one consolidated migration file. Billing UI (/billing, /pricing, /settings/billing) and a Feature Flags admin UI are both disclosed as the largest remaining end-user- facing gaps, tracked as separate follow-up work rather than folded silently into "Module 15 is done." See docs/adr/0015-production-hardening-monetization-marketplace.md, docs/releases/module-15-release-notes.md, docs/architecture/{stripe-webhook,feature-flags,release-engineering, health-diagnostics,error-handling,support-system,demo-mode,i18n, onboarding}.md, PRIVACY.md, and docs/compliance/gdpr-readiness.md.

Module 19 — Product Completion, Monetization & Launch Readiness (2026-09-09)

A baseline-audit-first pass, not a rebuild: the Module 19 brief asked for a "complete, launch-ready monetization foundation," and the baseline audit found that foundation already existed in production-quality form from Module 15 — Plan/Subscription/Invoice/PaymentMethod/ UsageCounter/QuotaPolicy/FeatureFlag/AiModelPricing/ AiBudgetPolicy schema, BillingService/EntitlementService/ QuotaService/UsageService/SubscriptionService/InvoiceService/ AiBudgetEnforcerService, a provider-neutral PaymentProvider interface (Stripe/Manual/Null adapters), and a real, signature-verified Stripe webhook controller. The one clear, bounded, previously-tracked gap (task #332) was that none of it had a frontend: this module built apps/web/lib/api/{organizations,billing}.ts, features/{organizations,billing}/* hooks and components, and three pages — /pricing, /settings/billing, /settings/usage — all honest about Community Edition / no-organization / provider-not-configured / past-due / canceled states, with zero fake payment-success screens (the only "success" state a page can show is a real BillingCheckoutSessionDto.checkoutUrl redirect or an immediate plan change for NONE/MANUAL providers). A full historical-backlog reconciliation (docs/reviews/0022-module-19-backlog-reconciliation.md) resolved two stale tracker entries (#132, #436 — work existed under different ticket numbers and was never flipped) and disclosed one genuine ticket-reassignment ambiguity: #386/#387 ("Research analytics extensions" / "Security research notebook") were later reused by a different task (#425, Public Sharing) for real, shipped work — the originally-titled features were never built and aren't currently planned, which is recorded as OBSOLETE rather than silently marked done. Two small, real, previously-undisclosed defects were found and fixed during the audit: billing-endpoints.ts had every path missing its leading / (would have produced a malformed URL the moment a frontend consumer used it — none existed before this module) and bugbounty-badges.tsx's BugBountyFindingStage/ScopeClassification badge maps had never been updated for states Module 16/9 added, a real tsc compile error unrelated to Module 19 itself. A dedicated security review (docs/reviews/0023-module-19-monetization-security-review.md) found no IDOR, no client-controlled pricing, and no usage-fabrication path; it also disclosed two pre-existing, not-fixed-in-this-pass architectural limitations — Stripe webhook event ordering (not signature/replay) is unguarded, and quota check-then-act has a concurrency race — both scoped, real follow-up work. By deliberate decision, no separate AI-credit ledger (AICreditBalance/AICreditTransaction) was built on top of the already-functioning AiBudgetPolicy/UsageCounter system, per the project's standing anti-duplication rule. apps/api jest and a real boot/health-check attempt remain VERIFICATION_BLOCKED in this sandbox — three genuine, disclosed pnpm install attempts (full monorepo, --filter web..., --filter api...) each hit the tool's ~170s call cap with only single-digit-to-low-tens of packages downloaded/added, and a background/detached install does not persist across tool calls here — measured throughput (~1 package per 10-15s against a 500-1500-package graph) makes full completion infeasible within this session, not merely slow. See docs/reviews/0022-module-19-backlog-reconciliation.md, docs/reviews/0023-module-19-monetization-security-review.md, and docs/releases/module-19-release-notes.md for full detail.

Module 20 — Final Product Completion, Release & Project Closure (2026-09-09)

The final module of the core development roadmap: a 45-phase closing pass across every surface built in Modules 1-19, not a feature module. Per this module's own standing rule, nothing was rewritten, no working module was replaced, and no duplicate infrastructure was created — every fix reused an existing pattern (mirroring AiBudgetEnforcerService for the new quota checks, mirroring each SDK's own per-resource file convention for the new API-keys wrappers, extending existing deployment configs rather than introducing new ones).

A baseline audit (Phases 0-5) found the platform already in strong shape and surfaced a small number of real, bounded gaps rather than systemic problems: the RECON_JOBS/SCANNER_JOBS quota types had been defined in plan defaults since Module 15 but never actually enforced or metered; the Stripe webhook had no defense against out-of-order event delivery; several deployment artifacts (docker-compose.yml, .env.example, Kubernetes manifests) were missing billing environment variables the worker process needs; the installer prompted for Enterprise Edition provider choices that were silently discarded; and the public API-keys endpoints (live since Module 15) had zero SDK or CLI coverage across all three SDKs and the CLI. Each was fixed with the smallest change that closed the gap (Phases 6-9, 10-14, 15-17), and each fix is traced in its own docs/reviews/00XX-module-20-*.md document.

Phases 18-21 formalized the project's documentation and legal posture without making a business decision on its behalf: a root LICENSE file was added to make the already-consistent UNLICENSED/proprietary convention (declared individually by every package.json) discoverable at a glance, explicitly without adopting or recommending any specific open-source license — that remains a decision for the project's owners. SECURITY.md and docs/security/supply-chain.md were both re-verified in full and found still accurate, with one forward-looking note: the supported-versions language needed a follow-up once the version bump below landed (done in the same module, so no drift window was left open). Phases 22-24 then cut the project's first stable release, 1.0.0, per docs/architecture/release-engineering.md's own pre-existing policy anticipating exactly this once "Module 16+ work settles the plugin/API-versioning surfaces" — a condition this module, being the last one, was positioned to confirm — and backfilled four modules' worth of missing CHANGELOG.md entries (0.16.0-0.19.0) that had drifted out of sync with their own complete release-notes documents. Phases 25-39 closed with a confirmation sweep — TODO/FIXME grep, git history/status audit, a support-docs cross-check, and a guard-decorator spot-check on three representative recently-touched endpoints — that found no regressions and no new work items, consistent with the preceding 24 phases having already done the deep security/performance/ reliability passes.

Two limitations were deliberately left open rather than fixed this late in the release cycle, both because fixing them risks an unrelated-module behavior change for cosmetic-to-moderate severity issues: QUOTA_EXCEEDED is returned as HTTP 403 by the Module-10-era entity-count quota subsystem but HTTP 429 by the Module-15-era usage-metering QuotaService, two different subsystems sharing one error code; and the quota check-then-act concurrency race first disclosed in Module 19's security review remains unresolved. Both are recorded in SECURITY.md's disclosed-limitation scope so a report about either is triaged as already-known rather than novel. This module's sandbox verification followed the same disclosed, honest pattern as every prior module: apps/api's full tsc --noEmit/jest remain infeasible here (confirmed to reproduce identically against untouched files, not caused by this module), while apps/web, the TypeScript SDK, the CLI, and the Python SDK were all verified directly (the Python SDK's full test suite — 5/5 — was re-run after the version bump), and the Go SDK was manually cross-checked against real method signatures since go/gofmt are unavailable in this sandbox.

With this module's completion, the core PentestHub AI development roadmap is CLOSED. Per this module's own standing instruction, no Module 21 is started, and no further roadmap is proposed; future work awaits explicit human direction. See docs/reviews/0025 through 0032 (this module's eight phase-by-phase review documents), CHANGELOG.md's [1.0.0] entry, and LICENSE (new, repository root) for full detail.