Executive summary
Broken access control on invoices
High2. Change the invoice number in the address
3. Another company's invoice opens
How to fix it
How an attacker would chain it
Retest
Fixed. Checked again on the retest.
Signed letter
Buying a pentest is hard if you have never bought one. Here is how we work and what you get at the end, before you commit to anything.
Example report
What we found
Before we touch anything, we map what is publicly knowable about you: exposed infrastructure, forgotten subdomains, leaked credentials, third-party surface. Attackers start here, so we do too.
A report only helps if two people can use it: the engineer who fixes the problem, and the leader who decides to pay for the fix.
Executive summary
Broken access control on invoices
HighHow to fix it
How an attacker would chain it
Retest
Fixed. Checked again on the retest.
Signed letter
A penetration test is an authorized simulated attack on your systems, performed by people using the same techniques as real adversaries. Unlike a scan, which reports what might be wrong, a pentest proves what an attacker could actually do: which systems they would reach, which data they would take, and how far they would get before anyone noticed. Most organizations need one because a customer, insurer, or regulator is asking for it. The reason to want one is that it is far cheaper to find these problems than to have them found for you.
Annually is the baseline that most frameworks expect, including SOC 2, PCI DSS, and ISO 27001. You should also test after any significant change: a major release, a cloud migration, a new authentication system, or an acquisition. Organizations shipping continuously often move to a semi-annual cadence, with targeted testing around high-risk releases in between.
A vulnerability scan is automated. It compares your systems against a database of known issues and produces a list, usually with a meaningful number of false positives and no sense of what actually matters in your environment. A penetration test is performed by people. We validate findings by hand, chain several low-severity issues into a real attack path, and test the business logic unique to your application, which no scanner can evaluate because it has no idea what your application is supposed to do. Scanning is a healthy monthly habit. Testing is what tells you whether you are actually defensible.
Very rarely, and not by accident. We agree on rules of engagement before testing begins, including which systems are in scope, which techniques are off the table, and when testing runs. Denial-of-service testing is excluded by default. For fragile production systems we test during off-hours windows or against a staging mirror, and we keep a direct line open throughout so anything unexpected is handled within minutes.
Most engagements run one to three weeks of active testing, depending on scope. A single web application is typically five to seven days. A full internal and external network assessment for a mid-sized organization is usually two to three weeks. Reporting adds three to five business days after testing completes. We can start within a week. If you are working against a hard deadline, tell us on the scope call and we will plan around it.
A report in two parts. An executive summary written for people who do not work in security, covering business risk and what to do about it. A full technical report with every finding, reproduction steps, evidence, severity rating, and specific remediation guidance. With the Complete package you also get a retest of every fix, and an attestation letter you can share with customers, prospects, and auditors as proof the assessment took place.
Yes. It is one of our fastest-growing practice areas. We test prompt injection, both direct and indirect through retrieved content, plus tool and agent abuse, system prompt extraction, training data leakage, guardrail bypass, and excessive agency in systems where a model can take real actions. If your product gives a language model access to tools, data, or customer input, it has an attack surface most testing programs do not cover.
Pricing is fixed, and based on the size of what we test rather than hours burned. Answer a few questions and you get a fixed-price proposal in about 90 seconds, with no call needed. We confirm it with you on a short scope call, and once you sign, it is locked. The Complete package adds retesting, the attestation letter and help with fixes.
Type your website. Scope, timeline and a fixed price, in about 90 seconds. Free, and no sales call.
By getting a proposal, you agree to our Terms and Privacy Policy.
Rather talk to a person? Book a call