A report engineering will read
Reproduction steps, code-level context where it helps, and a prioritization that reflects what an attacker would actually exploit. Not a CVSS dump, an action list.
Targeted testing of the web app, API, cloud or perimeter that actually matters, conducted by operators who have built and run security programmes. Findings prioritized by exploitability and business impact, not a wall of CVSS. A retest in the contract.
Procurement will not move without it. The version they want references a methodology (ASVS, API Top 10), names the third-party tester, and is dated within twelve months. A scan output and a screenshot will not satisfy a serious security team.
SOC 2, ISO 27001 and PCI all expect an annual external test of the in-scope system. The report becomes evidence in the audit and needs to map to the controls the auditor is examining.
Test before the customer does. A two-week engagement before launch finds the issues that a public release would surface in a much more expensive way.
A targeted test of the systems and accounts involved, scoped tightly around the incident, produces a defensible answer for the board, for affected customers, and for the regulator if one is involved.
No mystery process. Each phase has a defined output, a fixed timebox, and a named owner on our side.
The target, the methodology, the in-scope and out-of-scope assets, the testing window, the communication channel and the escalation path. Written down, signed by both sides, attached to the engagement record.
Reconnaissance, manual testing, targeted use of tools where they earn it. Critical-impact findings are reported the day they are found, not held back for the final report. Your engineering channel is in the loop the whole time.
Full technical report with reproduction steps, prioritized by exploitability and business impact. Executive attestation letter for procurement. A live walkthrough with engineering to make sure every finding is understood before remediation starts.
Once your team has remediated, we re-verify the fixed findings, produce a delta report and an updated attestation that reflects the closed-out state. That is the version your auditor and your enterprise customer want.
Reproduction steps, code-level context where it helps, and a prioritization that reflects what an attacker would actually exploit. Not a CVSS dump, an action list.
A short executive letter naming the tester, the methodology, the scope and the date. The artifact your enterprise customer is asking for, in the format they expect.
The report maps to the controls your auditor is examining for SOC 2, ISO 27001, PCI or NIS2. Same artifact, multiple uses, no duplicate work.
Retest in the contract, an updated attestation, and a working relationship for the next cycle. The findings do not sit in a tracker for the next twelve months.
"A pentest report is only worth what gets fixed before it expires. We scope, test and report so the engineering team can finish what the engagement starts, and we come back to verify they did."
Purple Dragon Cybersecurity
For a startup the common scopes are external perimeter, web application (authenticated and unauthenticated), API, and cloud configuration (AWS, GCP or Azure). Internal network and segmentation work on request. We keep scopes tight: one well-tested target beats a wide-and-shallow sweep.
A focused web-app or API test is typically 5 to 10 working days of active testing, plus 3 to 5 days of reporting and walkthrough. Cloud configuration audits are 4 to 8 days. We block calendar in advance and run testing in business hours so your team can see what is happening.
Yes. The deliverable is a full technical report for engineering, plus a short executive attestation letter that names the methodology (OWASP ASVS, OWASP API Security Top 10, CIS Benchmarks for cloud), the scope, the dates and the high-level result. The attestation is the artifact you forward to procurement, the technical report is the one you fix from.
One retest of the fixed findings is included in every engagement, scheduled 4 to 8 weeks after delivery. The retest produces a delta report and an updated attestation, the version your auditor and your enterprise customers want to see.
For most startups the answer is no, not yet. Red-team and threat-led testing produce value once the basics are demonstrably in place; before that they tell you what you already know. We will say so explicitly during scoping if a different format would serve you better.
A 30-minute scoping call. We confirm whether a pentest is what you need, and if so what shape it should take.
Tell us what you're trying to ship, what's stalled, or which buyer security review is up next. We work with companies across the EU, EEA and US, and we reply within one business day.