Penetration Testing Services
Continuous external security testing for your website and infrastructure — built in. Enter your domain, hit Scan, get a prioritized security report you can act on.
A clear picture of your security posture
We probe your public-facing infrastructure the way an attacker would, then hand you a clear, ranked list of what to fix. Each issue comes with concrete evidence, a severity score, and step-by-step remediation guidance.
Live Security Score
A live security posture score that updates with every scan, giving you an always-current view of your exposure.
Severity Rankings
Findings ranked Critical, High, Medium, Low, Info — so you know exactly what to fix first.
Plain-English Explanations
Clear explanations of every issue and how to fix it — written in plain English with concrete, step-by-step remediation guidance.
AI Executive Summary
An AI-generated summary suitable for stakeholders and board reports — technical findings translated into business language.
Audit-Ready PDF Reports
Exportable PDF reports with finding evidence and remediation status — exactly what an auditor or compliance review expects.
Scan Comparisons
Side-by-side scan comparisons so you can prove progress over time — what was fixed, what’s new, what regressed.
Remediation Workflow
A built-in remediation workflow to track who fixed what and when, with notes and resolution dates for your audit trail.
What we check
Coverage expands with scan depth — Passive reads without probing, Active adds attack-surface enumeration, Deep adds exhaustive cipher and injection analysis.
Domain & DNS Health
Registration, name servers, SPF/DKIM/DMARC email security, and certificate authority lock-in.
Network Exposure
Open ports, exposed services, and banner leaks that reveal version and configuration details to attackers.
TLS & Encryption
Certificate validity, weak protocols, cipher suite weaknesses, and HSTS posture across all endpoints.
Security Headers
HSTS, CSP, frame-options, content-type-options, and the full set of HTTP response security headers.
Web Application Weaknesses
Exposed admin paths, source-control leaks, debug pages, open redirects, and host-header injection vulnerabilities.
JavaScript Secrets
Hardcoded API keys, cloud credentials, and internal URLs accidentally shipped in your front-end bundle. We also scan historical snapshots.
CMS-Specific Issues
Known-vulnerable plugins and outdated cores for WordPress, Drupal, Joomla, and Magento installations.
API Exposure
Swagger and GraphQL endpoints left in production, introspection enabled, and unauthenticated API surface.
Cloud Storage
Accidentally-public S3, GCS, and Azure buckets tied to your brand — a common source of data breaches.
Subdomain Takeover Risk
Dangling DNS records pointing at unclaimed services — a vector attackers use to impersonate your brand.
CORS & JWT Auth Flaws
Wildcard CORS origins, dangerous JWT algorithm choices, and auth configuration errors.
Known CVEs
Automatically correlated against the software versions we detect, cross-referenced against the latest vulnerability databases.
CORS Misconfiguration
Active and Deep — detects arbitrary origin reflection, null origin bypass, and credential leakage via CORS headers.
CRLF Injection
Active and Deep — tests header injection via URL path and query string parameters.
Cache Poisoning
Active and Deep — detects unkeyed header reflection confirmed by cache HIT on second request.
WAF Detection
Active and Deep — fingerprints Cloudflare, Sucuri, F5, Imperva, Akamai, or unknown WAF via attack pattern probes.
Rate Limiting
Active and Deep — tests login and API endpoints for missing rate limit enforcement.
SSRF Probe
Active and Deep — injects cloud IMDS URLs (AWS, GCP, Azure) and loopback addresses into URL-like parameters and headers to detect server-side request forgery.
HTML & Content Injection
Active and Deep — tests URL parameters and body values for reflected HTML injection, attribute injection, CSS injection, and JavaScript context injection.
TLS Deep Analysis
Deep only — full cipher suite analysis: SSLv2/DROWN, SSLv3/POODLE, BEAST, SWEET32 (3DES), FREAK/EXPORT, LOGJAM (DHE-EXPORT), NULL cipher support, and absence of Perfect Forward Secrecy.
SQL Injection
Active and Deep — error-based, boolean-blind, and time-based blind SQLi probes across URL parameters, form fields, headers, and JSON body values.
Cross-Site Scripting (XSS)
Active and Deep — reflected XSS testing across script tag, attribute break, JavaScript context, and DOM sink injection vectors.
Template Injection (SSTI)
Active and Deep — server-side template injection probes for Jinja2, Twig, Freemarker, ERB, and Pug template engines.
Local File Inclusion (LFI)
Active and Deep — path traversal and LFI probes via URL parameters and headers; detects reading of /etc/passwd, web server configs, and application source files.
XML External Entity (XXE)
Active and Deep — XXE injection in XML-accepting endpoints, testing for file retrieval, SSRF-via-DTD, and out-of-band exfiltration.
File Upload Abuse
Active and Deep — tests upload endpoints for script extension bypass, double-extension upload, and MIME-type bypass; confirms retrieval to verify RCE risk with no false positives on SPA catch-all routes.
HTTP Request Smuggling
Active and Deep — CL.TE, TE.CL, and TE.TE desync probes. Baseline-diffed against canary requests to confirm desync and minimize false positives.
Default Credentials
Deep only — tests detected admin panels (Jenkins, phpMyAdmin, Grafana, Adminer, Kibana, Tomcat Manager, Airflow, Traefik, RabbitMQ) for default or weak credential acceptance.
Session Management
Deep only — analyzes cookie entropy, Secure/HttpOnly/SameSite flag presence, session token predictability, and fixation risk.
OAuth Misconfiguration
Deep only — tests OAuth flows for missing state parameter (CSRF), open redirect_uri, and insufficient redirect-URI validation.
Insecure Direct Object References (IDOR)
Deep only — IDOR enumeration on API endpoints using sequential ID manipulation, UUID guessing, and horizontal privilege escalation probes.
GraphQL Deep Analysis
Deep only — introspection abuse, batch query amplification, query-depth and complexity exploitation, and field-level authorization probes.
WebSocket Security
Deep only — Origin header validation, cross-site WebSocket hijacking (CSWSH), and message injection probes on detected WebSocket endpoints.
Dependency Confusion
Deep only — detects exposed package manifest files and internal package names that could be squatted in public registries for supply-chain compromise.
Prototype Pollution
Deep only — client-side prototype pollution probes via query parameters and JSON body values, testing for gadget-chaining to DOM-based XSS.
Monthly
1 scan per month across your chosen profile. Full OWASP findings, CVSS scores, PDF report, dashboard access.
Best for: teams with a monthly release cycle
Weekly
1 scan per week — catch regressions between every release. PDF per scan, regression diff view, dashboard access.
Best for: teams shipping weekly or running CI/CD pipelines
Daily
1 scan per day for continuous monitoring. Priority findings alerts, regression diff view, PDF per scan, dashboard access.
Best for: high-velocity teams shipping multiple times per day
Built for compliance
Every scan produces the documentation an auditor expects — timestamped, attributable, and exportable. Findings move through a documented remediation workflow with notes and resolution dates.
ISO/IEC 27001
Vulnerability management evidence covering control A.8.8, with a documented remediation workflow and resolution dates.
SOC 2
Vulnerability monitoring evidence for CC7.1 and security event analysis for CC7.3 — exactly what your Type I or Type II audit needs.
OWASP ASVS
Independent verification records aligned with OWASP Application Security Verification Standard requirements.
PCI DSS
Regular external scan evidence demonstrating continuous vulnerability management for cardholder data environment compliance.
Privacy first
Scan results are stored on our platform only — never routed through or shared with third-party scanner services. Findings are encrypted at rest and visible only to your authorized users.
Why customers pick us
Zero Setup
Type a domain, hit Scan. Fully agentless and self-contained — up and running from a single URL.
No Third-Party Scanners
Scans run on our platform and results stay there — never sent to external scanner services or shared with third parties.
Always Current
Scan whenever you want — pre-deploy, post-deploy, on a schedule. Scans run immediately on demand, with results available in minutes.
Stakeholder-Ready
The AI executive summary translates technical findings into business language without you writing it.
Track Progress
Cross-scan comparison shows what you’ve fixed and what’s new — tangible evidence of improvement over time.
One Tool, Full Picture
Replaces a stack of point tools — DNS scanner, SSL checker, header analyzer, subdomain enumerator, secret scanner, CVE lookup.
Full-spectrum testing, with the integrations your team uses
External scans are the foundation. We also deliver the advanced capabilities your security program needs beyond the automated surface scan.
Internal Network Pentesting
Authenticated tests against your internal systems, network segmentation review, wireless security, and lateral-movement assessments — covering the internal threat surface that external scans leave untouched.
Mobile App Pentesting
OWASP MASVS-aligned testing of iOS and Android apps. Reverse-engineering analysis, runtime instrumentation, secure-storage and transport audits, IPC and deep-link review.
Ticketing & Webhook Integrations
Findings auto-routed into your team’s ticketing system. Severity-based alerts via webhook, email, or your on-call tool. Automated retest fires when you mark tickets as fixed.
Manually Verified Findings
Every finding is manually verified by a human before it reaches you. If a finding turns out to be a false positive, the report is corrected and your scan credit is refunded.
Frequently asked questions
What is penetration testing and what does it cover?
Penetration testing (pen testing) is the practice of probing your external attack surface the way a real attacker would. Our scanner runs one of three profiles depending on depth selected. The Passive profile (17 modules) performs read-only reconnaissance: DNS, TLS certificates, HTTP headers, CSP, HSTS, DMARC/SPF/DNSSEC, JavaScript inspection, clickjacking, CSRF, and internal-IP disclosure. The Active profile (44 modules) adds port scanning, subdomain enumeration, CMS fingerprinting, CORS misconfiguration, WAF detection, rate limiting, and active injection testing: SQL injection (error/boolean/time-based blind), reflected XSS (script/attribute/JS/DOM contexts), SSTI, LFI, XXE, file-upload abuse, HTTP Request Smuggling (CL.TE / TE.CL / TE.TE), and SSRF. The Deep profile (53 modules) further adds default-credential testing against detected admin panels, session management analysis, OAuth misconfiguration testing, IDOR enumeration, GraphQL deep analysis, WebSocket security, dependency confusion, prototype pollution probes, and advanced TLS analysis (SSLv2/DROWN, POODLE, BEAST, SWEET32, FREAK, LOGJAM).
How much does penetration testing cost?
Our automated external scan service starts at €99 / month for monthly scans, €250 / month for weekly, and €500 / month for daily scans. Each subscription lets you choose from three scan profiles (Passive, Active, or Deep) before each scan. Full pricing is on our pricing page.
How is this different from a manual penetration test?
Manual pen tests are project-based (typically €5,000–€20,000+ for an external test) and happen once or twice a year. Our service is continuous — your external attack surface is scanned on a defined cadence so new vulnerabilities introduced by code changes are caught within days, not months. The two approaches are complementary: continuous automated coverage plus periodic manual depth.
How often should we run a penetration test?
ISO 27001 and SOC 2 both require regular vulnerability management — typically interpreted as monthly at minimum. For active development teams, weekly scans catch regressions before they sit unpatched for a full cycle. Daily scans suit regulated industries (PCI DSS, healthcare) where any new exposure in a released build needs to be identified quickly.
Do scan results stay on your platform or go to third parties?
Scan results are stored on our platform only — never routed through or shared with third-party scanner services. Findings are encrypted at rest and visible only to your authorized users. This is a deliberate architectural choice built into the product from day one.
What compliance frameworks does this help with?
ISO 27001 (A.8.8 vulnerability management), SOC 2 (CC7.1 and CC7.3 for security monitoring and event analysis), OWASP ASVS (application security verification), and PCI DSS (regular external vulnerability scanning for cardholder data environment compliance). Every scan produces a timestamped, exportable PDF report with the evidence an auditor expects.
Explore Specific Penetration Testing Services
Vulnerability Assessment Services
Structured assessment of your external attack surface — ranked findings, evidence, and remediation guidance.
Ethical Hacking Services
Authorized offensive testing — network, web application, and social engineering, performed by certified testers.
Pentest as a Service
Continuous testing on a subscription model — always-current findings without one-off engagement scheduling.
Try it on your own domain
Sign in, head to the Security Audit page, enter your URL — your first findings are minutes away.
See plans Send an Inquiry