Skip to content
Penetration testingBlack box from $700

We find the way in.

Manual penetration testing by CREST, OSCP and OSWE-certified testers. Every finding comes with a working proof, published to your portal the day it is confirmed.

Human-verified findings 90-day retest included

Certified expertise. Human accountability.

  • CREST CRT, Registered Penetration Tester
  • OSCP, Offensive Security Certified Professional
  • OSWE, Offensive Security Web Expert
  • BSCP, Burp Suite Certified Practitioner
  • CRTO, Certified Red Team Operator
  • CRTP, Certified Red Team Professional

[ 01 / How it runs ]

Two ways to test.
The right depth for you.

Choose continuous scanning between releases or a full manual engagement. We help you match the depth to your risk.

AI-powered pentesting

Continuous scan

01

Automated discovery, exploitation of known classes, and AI triage. A tester reviews the queue before anything reaches you. Built for the gap between engagements, when your codebase keeps moving.

  • Results within 24 hours
  • Every finding human-reviewed before release
  • Re-runs on each release or on a schedule
  • False positives removed before you see them

From

$399/ scan

Pricing

Our assessment guarantee

No high or critical findings?
We refund the invoice.

For qualifying grey box and white box assessments with full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee.

Excludes black box, scans and retests. Terms confirmed in your engagement letter before testing begins.

[ 02 / Coverage ]

Everything you own that an attacker can reach.

Thirteen engagement types across four families. If your estate spans several of them, we run one combined engagement and one report rather than four invoices.

Testing models

03 services

Applications

03 services

Infrastructure

05 services

Adversarial

02 services

[ 03 / Engagement ]

Six steps, in this order, every time.

No stage of a penetration test should be a surprise to the people paying for it. Here is the whole thing, including the parts most providers leave out of the proposal.
  1. 01

    Scope

    A short call, then a written scope with a fixed price. If the scope does not change, the number does not change.

    1-2 days
  2. 02

    Recon

    Automated discovery maps your attack surface and clears the noise, so the tester starts the engagement already oriented.

    AI-accelerated
  3. 03

    Test

    A named, certified tester works the target by hand, chaining findings until each one has a working proof rather than a maybe.

    3-15 days
  4. 04

    Report

    Findings appear in your portal as they are confirmed. Your team can start fixing on day two instead of waiting for a PDF.

    Live
  5. 05

    Debrief

    A working session with your engineers. We walk the attack paths, answer questions, and agree what gets fixed first.

    90 minutes
  6. 06

    Retest

    Once you have fixed things, we verify every finding again and reissue the report and letter of attestation.

    Included, 90 days

[ 04 / Platform ]

Findings arrive while we are still testing.

The six-week PDF is a habit, not a requirement. Confirmed findings publish to your tenant the moment they are verified, so remediation starts on day two rather than after the engagement ends.

EngagementACME · Grey box · Q3
Testing in progress · day 4 of 8
4 of 4 findings
Example findings as they appear in the Vaptiq reporting platform
IDSeverityFinding
VPQ-0142Critical
VPQ-0139High
VPQ-0131High
VPQ-0128Medium

Illustrative data · select a row to see what your team sees

Live findings

Published as they are confirmed, with reproduction steps and evidence attached.

Talk to your tester

Comment on any finding and get an answer from the tester who wrote it, not a support queue.

[ 05 / Who tests ]

Certifications you can check, on people you can name.

Every engagement is led by a tester holding at least one of these. You get their name before the test starts and their signature on the report when it ends.
CREST CRTRegistered Penetration Tester
OSCPOffensive Security Certified Professional
OSWEOffensive Security Web Expert
BSCPBurp Suite Certified Practitioner
CRTOCertified Red Team Operator
CRTPCertified Red Team Professional
Tested againstOWASP ASVSOWASP MASVSOWASP API Top 10OWASP Top 10 for LLMsPTESNIST SP 800-115MITRE ATT&CKCVSS v4.0CIS Benchmarks

[ 06 / What we look for ]

The kind of thing an attacker is actually looking for.

Representative examples, not case studies. This is the class of issue we hunt for, how we prove it, and exactly what lands in your report, with a working proof rather than a scanner flag.

Access control

Critical

Tenant-isolation bypass on document export

One account reaching another tenant's data. We prove the full path, then hand you the exact request to reproduce and fix.

Authentication

Account takeover

Predictable password-reset tokens across environments

A token you can guess is an account takeover waiting to happen. We show the guess, the takeover, and where the entropy went wrong.

Attack surface

Unknown exposure

Internet-facing assets missing from the asset register

You cannot defend what you have not counted. We map what is actually exposed and assign ownership in the debrief.

5–10 daysTypical start time from scope confirmation
100%Every finding shipped with a working proof, never a raw scanner flag
90 daysFree retest window included on every engagement

[ 07 / Questions ]

The questions people ask before they sign.

If yours is not here, send it to [email protected] and you will get an answer from a tester.

No. AI does reconnaissance, enumeration and first-pass triage, the mechanical work that used to eat the first two days of every engagement. Exploitation, chaining, impact analysis and the report itself are done by a certified tester whose name is on the document. We would rather be slower than pretend otherwise.

Find out what is reachable, before somebody else does.

Thirty minutes on a call is usually enough to scope an engagement and give you a fixed price. No pipeline, no sales engineer. You talk to someone who tests.