# PlexTrac > PlexTrac is a penetration test reporting and proactive exposure management platform that unifies offensive security data - pentests, vulnerability scanners, and bug bounty programs - into a single system of record. It exposes a JWT-authenticated REST API (v1 and v2) for managing clients, reports, findings, assets, and content-library writeups, plus tenant/RBAC administration and outbound webhooks. ## API - [PlexTrac API reference](https://api-docs.plextrac.com/): REST API v1/v2 endpoint reference - [PlexTrac documentation](https://docs.plextrac.com/): product and API documentation - Base URL: your PlexTrac instance host (SaaS instance: https://app.plextrac.com), paths under /api/v1 and /api/v2 - Authentication: JWT bearer token from POST /api/v1/authenticate (15-minute expiry; MFA and refresh supported) ## Artifacts - [Authentication](authentication/plextrac-llc-authentication.yml): JWT bearer auth profile - [Webhooks](asyncapi/plextrac-llc-webhooks.yml): outbound webhook delivery surface - [Conventions](conventions/plextrac-llc-conventions.yml): versioning, rate limiting, scoping - [Lifecycle](lifecycle/plextrac-llc-lifecycle.yml): v1/v2 versioning and deprecated endpoints - [Conformance](conformance/plextrac-llc-conformance.yml): standards and compliance posture - [MCP (candidate)](mcp/plextrac-llc-mcp.yml): derived candidate tool list ## Company - [Website](https://plextrac.com/) - [Help Center](https://helpcenter.plextrac.com/) - [Blog](https://plextrac.com/resources/blog/) - [Pricing](https://plextrac.com/pricing/) - [Vulnerability Disclosure](https://plextrac.com/vulnerability-disclosure/) - [Trust Center](https://app.drata.com/trust/9cbbf37d-0c38-11ee-865f-029d78a187d9): SOC 2 Type II, ISO 27001 - [Terms of Use](https://plextrac.com/terms-of-use/) - [Privacy Policy](https://plextrac.com/privacy-policy/)