# Core Components of the Pentagi Architecture: A Technical Deep Dive

> Explore the core components of the Pentagi architecture: React frontend, Go API, PostgreSQL vector store, Redis queue, and AI system. Learn how they power autonomous penetration testing.

- Repository: [VXControl/pentagi](https://github.com/vxcontrol/pentagi)
- Tags: deep-dive
- Published: 2026-03-21

---

**Pentagi's architecture consists of five core components—a React frontend, Go backend API, PostgreSQL vector store, Redis task queue, and multi-agent AI system—that together enable autonomous, AI-driven penetration testing workflows.**

The Pentagi platform, developed by vxcontrol/pentagi, implements a modular, scalable, and secure architecture designed specifically for autonomous security assessments. Understanding the core components of the Pentagi architecture is essential for security engineers deploying self-hosted instances or integrating the platform into existing DevSecOps pipelines.

## The Five Core Components of Pentagi

### Frontend UI: React-Based Security Interface

The **Frontend UI** serves as the primary interaction layer for security engineers. Built with React and TypeScript, this component provides the web interface where users create testing flows, monitor real-time progress, and review generated security reports. The frontend communicates with the backend via GraphQL subscriptions for live updates, making it critical for real-time penetration testing visibility.

### Backend API: Go-Powered Orchestration Layer

The **Backend API** functions as the central nervous system of Pentagi. Implemented in Go, it exposes both REST and GraphQL endpoints protected by bearer-token authentication. This component orchestrates flows, exposes data to the frontend, and drives the multi-agent system. In [`backend/pkg/server/router.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/server/router.go), the API router sets up Gin handlers, CORS policies, and authentication middleware that secure all communications.

### Vector Store: PostgreSQL with pgvector for Semantic Memory

The **Vector Store** provides long-term memory and semantic search capabilities essential for autonomous testing. This component utilizes PostgreSQL with the **pgvector** extension to store embeddings, historical actions, and discovered vulnerabilities. The system queries this store to retrieve context from previous testing steps, enabling the AI agents to learn from prior actions. Typed Go queries in [`backend/pkg/database/queries.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/database/queries.go) handle all vector operations.

### Task Queue: Redis-Backed Asynchronous Processing

The **Task Queue** manages asynchronous job processing for long-running operations. Backed by Redis, this component guarantees reliable execution of parallel tasks including tool runs, LLM reasoning cycles, and external API calls. When users initiate a flow, the Backend API enqueues jobs that the AI Agent workers pick up asynchronously, preventing blocking operations and enabling scalable concurrent testing.

### AI Agent: Multi-Agent System for Autonomous Testing

The **AI Agent** represents the intelligent core that executes penetration testing workflows. This multi-agent system implements specialized roles including the Researcher, Developer, Executor, and Adviser agents. These agents plan testing steps, execute security tools, analyze results, and iterate on findings. The component leverages LLM providers implemented in `backend/pkg/providers/` to interface with OpenAI, Anthropic, Gemini, Bedrock, and Ollama models.

## How the Pentagi Components Interact

The core components of the Pentagi architecture communicate through well-defined APIs and shared data stores to form a cohesive autonomous testing workflow:

1. **User initiates flow** via the **Frontend UI** (or directly through the **Backend API**).
2. **Backend API** stores the flow definition in the **Vector Store** and enqueues a job on the **Task Queue**.
3. **AI Agent** picks up the job, queries the **Vector Store** for prior knowledge, and may call external LLM providers or search engines.
4. **Results and discovered knowledge** are persisted back into the **Vector Store** and knowledge graph.
5. **Frontend UI** continuously polls the API or receives GraphQL subscriptions to present live progress and final reports.

## Key Implementation Files

The following source files implement the core components of the Pentagi architecture:

- [`backend/pkg/server/router.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/server/router.go) — Sets up the Gin router, CORS, auth middleware, and registers all REST/GraphQL endpoints for the **Backend API**.
- `backend/pkg/graph/schema.graphqls` — Defines the GraphQL schema exposing flows, tasks, agents, and analytics.
- [`backend/pkg/config/config.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/config/config.go) — Parses environment variables and configures services including the **Vector Store**, **Task Queue**, and provider URLs.
- `backend/pkg/providers/` — Implements the `provider.Provider` interface for OpenAI, Anthropic, Gemini, Bedrock, and Ollama, powering the **AI Agent** LLM interactions.
- [`frontend/src/app.tsx`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/app.tsx) — Entry point for the React SPA implementing the **Frontend UI**.
- [`backend/pkg/database/queries.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/database/queries.go) — Generated SQLC queries for the **Vector Store** (PostgreSQL + pgvector).
- [`backend/pkg/services/flow_service.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/services/flow_service.go) — Business logic for managing flows and interfacing with the **Task Queue**.

## Practical Integration Examples

### Creating a New Penetration Testing Flow

Use the GraphQL mutation to create a flow through the **Backend API**:

```graphql
mutation CreateFlow {
  createFlow(
    modelProvider: "openai"
    input: "Run a full security assessment on https://example.com"
  ) {
    id
    title
    status
    createdAt
  }
}

```

Execute via curl:

```bash
curl -X POST https://your-pentagi-instance:8443/api/v1/graphql \
  -H "Authorization: Bearer $API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"query":"mutation CreateFlow { createFlow(modelProvider:\"openai\",input:\"Run a full security assessment on https://example.com\") { id title status createdAt } }"}'

```

### Configuring an LLM Provider

Configure the **AI Agent** to use OpenRouter via YAML:

```yaml

# examples/configs/openrouter.provider.yml

provider: openrouter
model: meta-llama/Meta-Llama-3.1-70B-Instruct
api_key: ${OPENROUTER_API_KEY}

```

The **Providers** package in [`backend/pkg/providers/providers.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/providers.go) registers this configuration for the multi-agent system.

### Monitoring Real-Time Progress

Subscribe to flow updates via GraphQL subscription:

```graphql
subscription FlowProgress($flowID: ID!) {
  flowProgress(flowId: $flowID) {
    subtaskId
    status
    logs
  }
}

```

The **Backend API** delivers these updates through `pkg/graph/subscriptions` to the **Frontend UI** via WebSocket connections.

## Summary

The core components of the Pentagi architecture work together to deliver autonomous penetration testing capabilities:

- **Frontend UI** provides the React-based interface for security engineers to manage testing workflows.
- **Backend API** serves as the Go-powered orchestration layer securing all communications with bearer-token authentication.
- **Vector Store** implements PostgreSQL with pgvector for semantic search and long-term memory of testing history.
- **Task Queue** utilizes Redis for reliable asynchronous processing of long-running security tasks.
- **AI Agent** operates as a multi-agent system leveraging specialized roles and multiple LLM providers to execute autonomous testing.

## Frequently Asked Questions

### What programming languages power the Pentagi architecture?

Pentagi utilizes a polyglot architecture: the **Frontend UI** is built with TypeScript and React, while the **Backend API**, **AI Agent**, and data services are implemented in Go. The **Vector Store** relies on PostgreSQL with the pgvector extension.

### How does Pentagi handle authentication between components?

The **Backend API** implements bearer-token authentication for all REST and GraphQL endpoints, configured in [`backend/pkg/server/router.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/server/router.go). The **Frontend UI** passes these tokens with each request, while internal services communicate through secured channels with environment-based credentials.

### Can Pentagi integrate with custom LLM providers?

Yes, the **AI Agent** supports custom LLM providers through the **Providers** package in `backend/pkg/providers/`. The system implements the `provider.Provider` interface for OpenAI, Anthropic, Gemini, AWS Bedrock, and Ollama, with configuration handled via YAML files or environment variables.

### What database does Pentagi use for storing embeddings?

Pentagi uses **PostgreSQL** with the **pgvector** extension as its **Vector Store**. This configuration stores embeddings and semantic data for long-term memory, enabling the **AI Agent** to retrieve context from previous testing steps. Typed queries are generated via sqlc in [`backend/pkg/database/queries.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/database/queries.go).