Penetration testing

A pentest your engineers want to read.

Targeted testing of the web app, API, cloud or perimeter that actually matters, conducted by operators who have built and run security programmes. Findings prioritized by exploitability and business impact, not a wall of CVSS. A retest in the contract.

  • Reports written for engineering, not for the audit room.
  • Attestation letter customers and auditors will actually accept.
  • Retest in the price, not a follow-on quote.
  • OWASP ASVS · API Top 10
  • CIS Benchmarks
  • Attestation letter included
  • Retest in scope
When this is for you

The moments testing becomes urgent.

  • An enterprise buyer wants a third-party pentest report.

    Procurement will not move without it. The version they want references a methodology (ASVS, API Top 10), names the third-party tester, and is dated within twelve months. A scan output and a screenshot will not satisfy a serious security team.

  • Your auditor asked for "the most recent pentest".

    SOC 2, ISO 27001 and PCI all expect an annual external test of the in-scope system. The report becomes evidence in the audit and needs to map to the controls the auditor is examining.

  • You are about to launch a new product or major architecture change.

    Test before the customer does. A two-week engagement before launch finds the issues that a public release would surface in a much more expensive way.

  • You had a near-miss or a real incident.

    A targeted test of the systems and accounts involved, scoped tightly around the incident, produces a defensible answer for the board, for affected customers, and for the regulator if one is involved.

The engagement

Four phases. Honest timelines.

No mystery process. Each phase has a defined output, a fixed timebox, and a named owner on our side.

  1. 01

    Scoping & rules of engagement 1 week

    The target, the methodology, the in-scope and out-of-scope assets, the testing window, the communication channel and the escalation path. Written down, signed by both sides, attached to the engagement record.

  2. 02

    Active testing 1–2 weeks

    Reconnaissance, manual testing, targeted use of tools where they earn it. Critical-impact findings are reported the day they are found, not held back for the final report. Your engineering channel is in the loop the whole time.

  3. 03

    Reporting & walkthrough 1 week

    Full technical report with reproduction steps, prioritized by exploitability and business impact. Executive attestation letter for procurement. A live walkthrough with engineering to make sure every finding is understood before remediation starts.

  4. 04

    Retest & updated attestation 2–4 days, 4–8 weeks later

    Once your team has remediated, we re-verify the fixed findings, produce a delta report and an updated attestation that reflects the closed-out state. That is the version your auditor and your enterprise customer want.

Outcomes

What the engagement leaves on the file.

A report engineering will read

Reproduction steps, code-level context where it helps, and a prioritization that reflects what an attacker would actually exploit. Not a CVSS dump, an action list.

An attestation procurement accepts

A short executive letter naming the tester, the methodology, the scope and the date. The artifact your enterprise customer is asking for, in the format they expect.

Audit-grade evidence

The report maps to the controls your auditor is examining for SOC 2, ISO 27001, PCI or NIS2. Same artifact, multiple uses, no duplicate work.

A closed loop, not an open finding list

Retest in the contract, an updated attestation, and a working relationship for the next cycle. The findings do not sit in a tracker for the next twelve months.

From the practice
"A pentest report is only worth what gets fixed before it expires. We scope, test and report so the engineering team can finish what the engagement starts, and we come back to verify they did."

Purple Dragon Cybersecurity

Frequently asked

Common questions, direct answers.

What does a typical engagement scope look like?

For a startup the common scopes are external perimeter, web application (authenticated and unauthenticated), API, and cloud configuration (AWS, GCP or Azure). Internal network and segmentation work on request. We keep scopes tight: one well-tested target beats a wide-and-shallow sweep.

How long does a test take?

A focused web-app or API test is typically 5 to 10 working days of active testing, plus 3 to 5 days of reporting and walkthrough. Cloud configuration audits are 4 to 8 days. We block calendar in advance and run testing in business hours so your team can see what is happening.

Do you give us the report customers ask for?

Yes. The deliverable is a full technical report for engineering, plus a short executive attestation letter that names the methodology (OWASP ASVS, OWASP API Security Top 10, CIS Benchmarks for cloud), the scope, the dates and the high-level result. The attestation is the artifact you forward to procurement, the technical report is the one you fix from.

Is a retest included?

One retest of the fixed findings is included in every engagement, scheduled 4 to 8 weeks after delivery. The retest produces a delta report and an updated attestation, the version your auditor and your enterprise customers want to see.

Do you do red-team or threat-led testing?

For most startups the answer is no, not yet. Red-team and threat-led testing produce value once the basics are demonstrably in place; before that they tell you what you already know. We will say so explicitly during scoping if a different format would serve you better.

Scope a pentest

A 30-minute scoping call. We confirm whether a pentest is what you need, and if so what shape it should take.

Talk to a security operator.

Tell us what you're trying to ship, what's stalled, or which buyer security review is up next. We work with companies across the EU, EEA and US, and we reply within one business day.

Get in touch