Prev ISO 27001 / SOC 2 Next vCISO

Penetration Testing Services

Continuous external security testing for your website and infrastructure — built in. Enter your domain, hit Scan, get a prioritized security report you can act on.

A clear picture of your security posture

We probe your public-facing infrastructure the way an attacker would, then hand you a clear, ranked list of what to fix. Each issue comes with concrete evidence, a severity score, and step-by-step remediation guidance.

01

Live Security Score

A live security posture score that updates with every scan, giving you an always-current view of your exposure.

02

Severity Rankings

Findings ranked Critical, High, Medium, Low, Info — so you know exactly what to fix first.

03

Plain-English Explanations

Clear explanations of every issue and how to fix it — written in plain English with concrete, step-by-step remediation guidance.

04

AI Executive Summary

An AI-generated summary suitable for stakeholders and board reports — technical findings translated into business language.

05

Audit-Ready PDF Reports

Exportable PDF reports with finding evidence and remediation status — exactly what an auditor or compliance review expects.

06

Scan Comparisons

Side-by-side scan comparisons so you can prove progress over time — what was fixed, what’s new, what regressed.

07

Remediation Workflow

A built-in remediation workflow to track who fixed what and when, with notes and resolution dates for your audit trail.

What we check

Coverage expands with scan depth — Passive reads without probing, Active adds attack-surface enumeration, Deep adds exhaustive cipher and injection analysis.

Domain & DNS Health

Registration, name servers, SPF/DKIM/DMARC email security, and certificate authority lock-in.

Network Exposure

Open ports, exposed services, and banner leaks that reveal version and configuration details to attackers.

TLS & Encryption

Certificate validity, weak protocols, cipher suite weaknesses, and HSTS posture across all endpoints.

Security Headers

HSTS, CSP, frame-options, content-type-options, and the full set of HTTP response security headers.

Web Application Weaknesses

Exposed admin paths, source-control leaks, debug pages, open redirects, and host-header injection vulnerabilities.

JavaScript Secrets

Hardcoded API keys, cloud credentials, and internal URLs accidentally shipped in your front-end bundle. We also scan historical snapshots.

CMS-Specific Issues

Known-vulnerable plugins and outdated cores for WordPress, Drupal, Joomla, and Magento installations.

API Exposure

Swagger and GraphQL endpoints left in production, introspection enabled, and unauthenticated API surface.

Cloud Storage

Accidentally-public S3, GCS, and Azure buckets tied to your brand — a common source of data breaches.

Subdomain Takeover Risk

Dangling DNS records pointing at unclaimed services — a vector attackers use to impersonate your brand.

CORS & JWT Auth Flaws

Wildcard CORS origins, dangerous JWT algorithm choices, and auth configuration errors.

Known CVEs

Automatically correlated against the software versions we detect, cross-referenced against the latest vulnerability databases.

CORS Misconfiguration

Active and Deep — detects arbitrary origin reflection, null origin bypass, and credential leakage via CORS headers.

CRLF Injection

Active and Deep — tests header injection via URL path and query string parameters.

Cache Poisoning

Active and Deep — detects unkeyed header reflection confirmed by cache HIT on second request.

WAF Detection

Active and Deep — fingerprints Cloudflare, Sucuri, F5, Imperva, Akamai, or unknown WAF via attack pattern probes.

Rate Limiting

Active and Deep — tests login and API endpoints for missing rate limit enforcement.

SSRF Probe

Active and Deep — injects cloud IMDS URLs (AWS, GCP, Azure) and loopback addresses into URL-like parameters and headers to detect server-side request forgery.

HTML & Content Injection

Active and Deep — tests URL parameters and body values for reflected HTML injection, attribute injection, CSS injection, and JavaScript context injection.

TLS Deep Analysis

Deep only — full cipher suite analysis: SSLv2/DROWN, SSLv3/POODLE, BEAST, SWEET32 (3DES), FREAK/EXPORT, LOGJAM (DHE-EXPORT), NULL cipher support, and absence of Perfect Forward Secrecy.

SQL Injection

Active and Deep — error-based, boolean-blind, and time-based blind SQLi probes across URL parameters, form fields, headers, and JSON body values.

Cross-Site Scripting (XSS)

Active and Deep — reflected XSS testing across script tag, attribute break, JavaScript context, and DOM sink injection vectors.

Template Injection (SSTI)

Active and Deep — server-side template injection probes for Jinja2, Twig, Freemarker, ERB, and Pug template engines.

Local File Inclusion (LFI)

Active and Deep — path traversal and LFI probes via URL parameters and headers; detects reading of /etc/passwd, web server configs, and application source files.

XML External Entity (XXE)

Active and Deep — XXE injection in XML-accepting endpoints, testing for file retrieval, SSRF-via-DTD, and out-of-band exfiltration.

File Upload Abuse

Active and Deep — tests upload endpoints for script extension bypass, double-extension upload, and MIME-type bypass; confirms retrieval to verify RCE risk with no false positives on SPA catch-all routes.

HTTP Request Smuggling

Active and Deep — CL.TE, TE.CL, and TE.TE desync probes. Baseline-diffed against canary requests to confirm desync and minimize false positives.

Default Credentials

Deep only — tests detected admin panels (Jenkins, phpMyAdmin, Grafana, Adminer, Kibana, Tomcat Manager, Airflow, Traefik, RabbitMQ) for default or weak credential acceptance.

Session Management

Deep only — analyzes cookie entropy, Secure/HttpOnly/SameSite flag presence, session token predictability, and fixation risk.

OAuth Misconfiguration

Deep only — tests OAuth flows for missing state parameter (CSRF), open redirect_uri, and insufficient redirect-URI validation.

Insecure Direct Object References (IDOR)

Deep only — IDOR enumeration on API endpoints using sequential ID manipulation, UUID guessing, and horizontal privilege escalation probes.

GraphQL Deep Analysis

Deep only — introspection abuse, batch query amplification, query-depth and complexity exploitation, and field-level authorization probes.

WebSocket Security

Deep only — Origin header validation, cross-site WebSocket hijacking (CSWSH), and message injection probes on detected WebSocket endpoints.

Dependency Confusion

Deep only — detects exposed package manifest files and internal package names that could be squatted in public registries for supply-chain compromise.

Prototype Pollution

Deep only — client-side prototype pollution probes via query parameters and JSON body values, testing for gadget-chaining to DOM-based XSS.

€99 / month

Monthly

1 scan per month across your chosen profile. Full OWASP findings, CVSS scores, PDF report, dashboard access.

Best for: teams with a monthly release cycle

€500 / month

Daily

1 scan per day for continuous monitoring. Priority findings alerts, regression diff view, PDF per scan, dashboard access.

Best for: high-velocity teams shipping multiple times per day

Built for compliance

Every scan produces the documentation an auditor expects — timestamped, attributable, and exportable. Findings move through a documented remediation workflow with notes and resolution dates.

ISO/IEC 27001

Vulnerability management evidence covering control A.8.8, with a documented remediation workflow and resolution dates.

SOC 2

Vulnerability monitoring evidence for CC7.1 and security event analysis for CC7.3 — exactly what your Type I or Type II audit needs.

OWASP ASVS

Independent verification records aligned with OWASP Application Security Verification Standard requirements.

PCI DSS

Regular external scan evidence demonstrating continuous vulnerability management for cardholder data environment compliance.

Privacy first

Scan results are stored on our platform only — never routed through or shared with third-party scanner services. Findings are encrypted at rest and visible only to your authorized users.

Why customers pick us

Zero Setup

Type a domain, hit Scan. Fully agentless and self-contained — up and running from a single URL.

No Third-Party Scanners

Scans run on our platform and results stay there — never sent to external scanner services or shared with third parties.

Always Current

Scan whenever you want — pre-deploy, post-deploy, on a schedule. Scans run immediately on demand, with results available in minutes.

Stakeholder-Ready

The AI executive summary translates technical findings into business language without you writing it.

Track Progress

Cross-scan comparison shows what you’ve fixed and what’s new — tangible evidence of improvement over time.

One Tool, Full Picture

Replaces a stack of point tools — DNS scanner, SSL checker, header analyzer, subdomain enumerator, secret scanner, CVE lookup.

Full-spectrum testing, with the integrations your team uses

External scans are the foundation. We also deliver the advanced capabilities your security program needs beyond the automated surface scan.

Internal Network Pentesting

Authenticated tests against your internal systems, network segmentation review, wireless security, and lateral-movement assessments — covering the internal threat surface that external scans leave untouched.

Mobile App Pentesting

OWASP MASVS-aligned testing of iOS and Android apps. Reverse-engineering analysis, runtime instrumentation, secure-storage and transport audits, IPC and deep-link review.

Ticketing & Webhook Integrations

Findings auto-routed into your team’s ticketing system. Severity-based alerts via webhook, email, or your on-call tool. Automated retest fires when you mark tickets as fixed.

Manually Verified Findings

Every finding is manually verified by a human before it reaches you. If a finding turns out to be a false positive, the report is corrected and your scan credit is refunded.

Frequently asked questions

What is penetration testing and what does it cover?

Penetration testing (pen testing) is the practice of probing your external attack surface the way a real attacker would. Our scanner runs one of three profiles depending on depth selected. The Passive profile (17 modules) performs read-only reconnaissance: DNS, TLS certificates, HTTP headers, CSP, HSTS, DMARC/SPF/DNSSEC, JavaScript inspection, clickjacking, CSRF, and internal-IP disclosure. The Active profile (44 modules) adds port scanning, subdomain enumeration, CMS fingerprinting, CORS misconfiguration, WAF detection, rate limiting, and active injection testing: SQL injection (error/boolean/time-based blind), reflected XSS (script/attribute/JS/DOM contexts), SSTI, LFI, XXE, file-upload abuse, HTTP Request Smuggling (CL.TE / TE.CL / TE.TE), and SSRF. The Deep profile (53 modules) further adds default-credential testing against detected admin panels, session management analysis, OAuth misconfiguration testing, IDOR enumeration, GraphQL deep analysis, WebSocket security, dependency confusion, prototype pollution probes, and advanced TLS analysis (SSLv2/DROWN, POODLE, BEAST, SWEET32, FREAK, LOGJAM).

How much does penetration testing cost?

Our automated external scan service starts at €99 / month for monthly scans, €250 / month for weekly, and €500 / month for daily scans. Each subscription lets you choose from three scan profiles (Passive, Active, or Deep) before each scan. Full pricing is on our pricing page.

How is this different from a manual penetration test?

Manual pen tests are project-based (typically €5,000–€20,000+ for an external test) and happen once or twice a year. Our service is continuous — your external attack surface is scanned on a defined cadence so new vulnerabilities introduced by code changes are caught within days, not months. The two approaches are complementary: continuous automated coverage plus periodic manual depth.

How often should we run a penetration test?

ISO 27001 and SOC 2 both require regular vulnerability management — typically interpreted as monthly at minimum. For active development teams, weekly scans catch regressions before they sit unpatched for a full cycle. Daily scans suit regulated industries (PCI DSS, healthcare) where any new exposure in a released build needs to be identified quickly.

Do scan results stay on your platform or go to third parties?

Scan results are stored on our platform only — never routed through or shared with third-party scanner services. Findings are encrypted at rest and visible only to your authorized users. This is a deliberate architectural choice built into the product from day one.

What compliance frameworks does this help with?

ISO 27001 (A.8.8 vulnerability management), SOC 2 (CC7.1 and CC7.3 for security monitoring and event analysis), OWASP ASVS (application security verification), and PCI DSS (regular external vulnerability scanning for cardholder data environment compliance). Every scan produces a timestamped, exportable PDF report with the evidence an auditor expects.

Try it on your own domain

Sign in, head to the Security Audit page, enter your URL — your first findings are minutes away.

See plans    Send an Inquiry

Request Info — Penetration Testing

QUICK REPLY · 24-48 HOURS

AGENT CHAT
System: Secure connection established. Awaiting input...