Skip to content

A penetration test your
auditor will accept

Continuous testing, run by AI and validated by people, delivered as the six documents an assessor actually asks for. If yours will not accept it, we join the call, fix what they tell us to fix, and test again at no cost.

Free, no account. Public records and your live certificate only β€” nothing is sent to your servers that an ordinary browser visit would not send.

What changes when a machine does the testing

Four things, and only one of them is cost. The others are the reasons teams who could afford a consultancy engagement still move.

The report stops going stale

A once-a-year engagement produces evidence that is accurate on the day it is written and drifts from that day onward, while your estate keeps changing. Testing on a continuous cadence is also what several standards ask you to evidence β€” a series of dated results, not a single report.

Annual engagement
Continuous

Hours instead of a booking slot

Most of the delay in a traditional engagement is not the testing. It is waiting for a slot, agreeing scope by email, and waiting again for the write-up. Here the testing starts when scope is agreed and the pack is written as the engagement runs, so a finished report arrives in hours.

That matters most for the trigger people forget: several frameworks make a material change its own reason to test, independent of the calendar. A test you can run the week you ship is a test you will actually run.

People still decide what counts

Every finding is reproduced on a second independent pass before it reaches your report. One that reproduces is promoted, with severity set by a qualified tester against your environment. One that does not is kept as informational with the limitation stated, rather than reported as confirmed or quietly dropped.

Exploitation itself waits for a named person to authorise it. The checkpoint sits exactly where change control and compliance need it to sit, and the authorisation is recorded in the scope document.

You price the year, not the engagement

Consultancy testing is priced per engagement and scoped to a window, which is why the second test of the year rarely happens. A subscription prices the year, so testing after a release costs you nothing extra and the cadence stops being a budgeting decision.

We will not quote you someone else's number for comparison. Send us your last engagement quote and its scope and we will tell you plainly what the same coverage costs here.

The auditor guarantee

The reason most people hesitate is not whether the testing is good. It is the risk of sitting in front of an assessor who waves the report away. So we carry that risk instead of you.

If your assessor will not accept the report

Tell us, and we join a call with you and them. We explain the methodology, the scope and the validation process in the terms they work in. Most objections end here, because they are questions rather than refusals.

We change what they ask us to change

If they need wider scope, deeper testing, different documentation or evidence presented another way, we do that. Their requirements are the specification, not our template.

Then we test again, at no cost

We rerun the engagement and reissue the pack. That repeats until they accept it. You pay nothing more for the extra engagements or for the time we spend with your assessor.

Where it stops, stated plainly

If the gap is something testing cannot close, we tell you that instead of retesting forever. We also do not promise you pass your audit: most outcomes turn on controls a penetration test never touches. What we guarantee is that our work is accepted as testing evidence for the control it was produced for.

Want to check before you spend anything? Build your mapping below and send it to your assessor. Their answer is the only one that counts, and we would rather you had it early.

Your frameworks, and the file you hand over

Pick what you are assessed against. This builds the evidence file for that combination: which clauses bind you, which of the six documents carries the evidence for each one, and what no testing provider can do for you.

your frameworks0 of 11

Pick a framework to build your evidence file

Each one you add shows the clauses it puts on you, which of the six delivered documents carries the evidence for each clause, and anything in that framework we cannot do for you.

Read a real report before you decide

Both of these came out of our own deliberately vulnerable test estate, unedited. They are the fastest way to judge whether the evidence would satisfy the person who reviews yours.

Pricing

Testing is unlimited inside your plan window, because a cadence you have to budget for every time is a cadence that slips.

Free

$0forever

Seeing what we find before you commit anything.

  • External exposure assessment of your estate
  • Findings with severity and remediation guidance
  • No card, no sales call required
Create a free account

Pro

Talk to us

One company testing its own estate on a continuous cadence.

  • Unlimited penetration tests within your plan window
  • All six evidence documents on every engagement
  • Human validation before any finding is released
  • Retest included until findings close
  • The auditor guarantee below
Start a 30-day trial

Business

Talk to us

Larger estates, tighter cadences, and segmentation testing.

  • Everything in Pro
  • Higher concurrent testing volume
  • Internal and segmentation testing
  • Run from servers you control
  • Named contact for your assessor
Talk to us

The questions people actually ask

+Will an auditor accept a penetration test that was run by AI?

Auditors assess the sufficiency of the evidence, not the brand of tool that produced it. What they look for is a documented methodology, a scope that matches the system under assessment, findings with proof that something was actually exploited rather than merely detected, a qualified and independent reviewer, and a record of remediation and retest. Every engagement delivers those as separate documents for that reason. The honest answer is also that your assessor is the only person whose opinion settles it, which is why the mapping on this page is built to be copied and sent to them before you pay us anything. If they say no, we would rather hear it then.

+What exactly does the auditor guarantee cover?

If your assessor reviews one of our reports and will not accept it as evidence for the control it was produced for, we do three things at no additional cost. We join a call with you and your assessor and explain the methodology in their terms. We make whatever changes to scope, depth or documentation they tell us they need. Then we run the engagement again and reissue the pack. That repeats until they accept it or they tell us the gap is something outside testing altogether, in which case we say so plainly rather than keep retesting. The guarantee covers our work being accepted as testing evidence. It does not promise you pass your audit, because most audit outcomes turn on controls a penetration test never touches.

+Is this a real penetration test or a vulnerability scan?

They are different activities and some standards separate them explicitly β€” PCI DSS puts scanning in Requirement 11.3 and penetration testing in 11.4, and scan output does not satisfy 11.4. A scanner reports what it matched against a signature. Our engagements go further: they authenticate, chain findings together into attack paths across the estate, and attempt exploitation to establish what an intruder could actually reach. Exploitation is the part that sits behind a human authorisation gate, because it is the point where testing stops observing and starts acting.

+Who validates the findings, and what do they actually change?

Findings are reproduced on a second independent pass before they reach your report. A finding that reproduces is promoted, with severity set by a qualified tester against your environment rather than by a generic score. A finding that does not reproduce is kept as informational with the limitation stated openly, instead of being reported as confirmed or quietly dropped. The validation and independence statement in your pack names who did that review and what they changed, which is the document an assessor asks for when they want to know a person was involved.

+How fast is the first report, and how often can we test?

A full engagement completes in hours rather than the weeks a scheduled consultancy engagement takes, because the testing runs as soon as scope is agreed instead of waiting for a booking slot. Testing as often as you like within your plan window is the point of the subscription: annual testing leaves a report that ages for eleven months while your estate changes underneath it, and a cadence is what several standards actually ask you to evidence.

+Is it safe to run against production?

Scope is enforced in code at every tool call rather than by a setting someone can forget. A target that is not in the signed scope is refused at the boundary and the request never reaches the network. Exploitation does not begin until a named person authorises it, and that authorisation is recorded in the scope document. Post-exploitation demonstrates what is reachable without extracting your data. If you would rather not test production at all, the Business plan runs from infrastructure you control.

+What happens to the findings and the evidence afterwards?

The six documents are yours to keep and to hand to anyone you need to. The testing history accumulates across engagements, which is the artifact that evidences a cadence rather than a single point in time β€” the thing a SOC 2 Type II observation window and a cyber insurance renewal both actually need.

Start with your own domain

The free check runs in seconds and asks for nothing. The first full engagement is free too, and a person agrees the scope with you before anything is tested.