What a real pentest looks like
The word "pentest" covers a lot of sins. On one end: an automated scanner, a PDF template, and a report full of findings nobody verified. On the other: a human operator who understands your system, chains vulnerabilities, and tells you what an actual attacker would do with them. Here's how to tell the difference — and what our engagements look like.
The checkbox scan
You know it when you see it. The scope is vague. The "testing" is a vulnerability scanner with default settings. The report lists CVEs with CVSS scores copied from a database, no evidence of exploitation, and remediation advice that reads like a vendor whitepaper. It takes two to three weeks and tells you nothing you couldn't have learned from running the scanner yourself.
The real thing
A real pentest is human-led from start to finish. Our workflow:
Scoping that means something. We agree on targets, rules of engagement, and what a finding looks like — before testing starts. You know exactly what's covered and what isn't.
Recon and mapping. We map your attack surface: endpoints, APIs, authentication flows, infrastructure. Our own tooling compresses the mechanical part — what used to take four hours of manual recon now takes thirty supervised minutes — so operator time goes where it matters.
Exploitation by a human. The operator chains findings, confirms exploitability, and throws out false positives. A scanner can't tell you that the low-severity info leak plus the misconfigured CORS policy equals account takeover. A person can.
A report you'd act on. Every finding has evidence, impact in your context, and concrete remediation steps. Plus an executive summary your leadership will actually read.
A retest. Thirty days later, we verify the fixes. Findings without verification are just suggestions.
Web, APIs, networks, LLM systems
Traditional surface — auth bypass, injection, broken access control, exposed APIs — plus AI surface: prompt injection, jailbreaks, data leakage through model outputs, insecure tool calling. If you ship an AI product, a classic pentest alone leaves a whole class of bugs untested. We do both in one engagement.
Full engagements run three to ten days and start at $3,000. If you're preparing for a funding round, a launch, or a customer security review, book a scoping call and we'll map your scope in thirty minutes.
Need a pentest, an AI security assessment, or a custom security build?
Human-led testing, production AI builds, and the full loop in between. Book a free 30-minute scoping call.
Book a scoping call