Security & pentest
A clean Kali workstation per engagement. GPU for the password crack. Burn it down at the end.
Spin up a fresh Kali workstation for each client engagement — Burp Pro, Nessus, Metasploit, Bloodhound, Maltego preinstalled. Network-isolated from your other engagements. A real GPU on demand when the hashcat run starts. Delete the workstation when the engagement closes; the evidence comes with it.
The pain
- Client engagements bleed together because they live on the same laptop, same Burp project, same browser sessions, same vault.
- Password cracking on a laptop GPU is a slow joke. Bringing a hashcat rig home from the office isn't an option, and remoting into the one at the office isn't great either.
- Carrying client evidence — credentials, exploit screenshots, full Burp histories — on a personal MacBook you also use for everything else.
- Tool licensing pinned to a single device. Burp Pro on the laptop, Nessus on the office workstation, Maltego on the lab box — and you're in a hotel for the next two weeks.
With Canvex
- Fresh sec-workspace workstation per engagement. Tools preinstalled, browser profile clean, no cross-contamination from last week's client.
- Real NVIDIA GPU on demand (24 GB L4 / RTX 4090, 48 GB A6000, 80 GB H100). Spin it up for the crack, spin it back down to a regular Standard-tier box when the crack is done.
- Engagement data stays in the cloud. The pentester's laptop renders pixels. Client A's evidence never touches the workstation where client B's engagement lives.
- Snapshot before a risky exploit; restore in seconds if it bricks the box. Same clean image policy as day-one, on demand.
Recommended config
Most engagements
For day-to-day pentest work: Standard tier (3–4 vCPU, 5–8 GB RAM) with the sec workspace template (Kali-based, with Burp, Nessus, Metasploit, Bloodhound, and the usual recon toolchain preinstalled). Bump to Performance for assemblies of nmap scans against large estates.
For a password-cracking session: resize to Performance or Power + 24 GB GPU (RTX 4090 / L4) for most lists, or 48 GB (A40 / A6000) for heavy work. Resize back to Standard between sessions — once the GPU comes off, the GPU rate stops.
Enterprise platform tier ($99/mo) for session recording — useful as billable-hour evidence and for report-attached video clips of the exploit chain.
What's working for you under the hood
Sec workspace template
Kali base, with the canonical pentest tooling preinstalled — Burp, Nessus, Metasploit, Bloodhound, Maltego, the recon-and-exploit set.
Per-tenant network
Each engagement (or each client, or each team) gets its own isolated private network. Drop your VPN container on the same network to tunnel into the client's environment.
GPU on demand
Resize a Standard workstation to add a 24–80 GB GPU when the crack starts. Resize back between sessions. No standing rig to maintain.
Snapshot before exploitBusiness+
Snapshot before an aggressive exploit chain; restore in seconds if the target bricks itself or you brick the workstation with a bad payload.
Session recordingEnterprise
End-to-end session capture for billable-hour evidence and report-attached video clips. Indexed and exportable.
Burn-on-end
Engagement closes; delete the workstation. The Burp history, the credential dump, the screenshots — gone with it. No personal device residue.
The traditional answer — a Kali VM on your personal laptop plus a USB-C hashcat rig at the office — works right up until the client asks where their data lives or your insurance carrier asks how engagements are isolated. Cloud desktops give you a clean per-engagement environment, a real GPU when the engagement actually needs one, and an audit trail you can attach to the final report.
Your first desktop, in five minutes.
3-day free trial. Cancel anytime before it ends.