Skip to content
CyberVanta

Penetration testing

Manual testing of your applications and networks, with proof of impact and a fix for every finding.

Dark water surface, photographed close

What the engagement covers.

Web applications

Authentication, session handling, access control, injection, business logic abuse, and the parts a scanner cannot reason about.

APIs

REST and GraphQL endpoints tested for broken object-level authorization, mass assignment, rate limiting gaps, and data exposure.

Mobile applications

iOS and Android clients, local storage, certificate pinning, and the backend calls they make.

External infrastructure

Everything reachable from the internet: exposed services, forgotten hosts, mail and DNS configuration, and credential reuse.

Internal networks

Assumed-breach testing from a standard workstation. Active Directory paths, lateral movement, and what a phished employee's laptop reaches.

Authenticated and unauthenticated

We test as an anonymous visitor, as each role you give us, and as a customer trying to reach another customer's data.

How it runs.

  1. Scope

    Targets, roles, test accounts, exclusions, and windows agreed in writing. Rules of engagement signed before anything is touched.

  2. Test

    Consultants work the scope by hand. Critical findings are reported the day they are confirmed, not held for the report.

  3. Report

    Reproduction steps, evidence, risk rating, and a concrete fix for every finding, plus a summary written for leadership.

  4. Retest

    After fixes ship, every finding is verified again and the report is updated. This is included, not billed separately.

What you receive.

  • Technical report with reproduction steps and evidence
  • Executive summary with business impact
  • Remediation guidance per finding, ranked by exploitability
  • Retest report and closure letter for auditors and customers

Who it is for.

  • Products preparing for SOC 2, ISO 27001, or PCI DSS assessment
  • Teams shipping a new customer-facing platform or API
  • Companies asked by a customer to provide a recent pentest report

Questions about penetration testing.

How long does a penetration test take?

Most web or API engagements take one to three weeks of testing, followed by a week for reporting. Internal network tests are usually two weeks. We confirm the estimate during scoping and hold the dates.

Do you test in production or staging?

Either. Production gives the truest result; staging is safer when downtime is costly. If we test staging, we confirm parity with production first and note any differences in the report.

What do you need from us to start?

A list of targets, test accounts for each role, a technical contact for the testing window, and signed authorization. We provide the templates.

Scope a penetration testing engagement.

Tell us about the system and the deadline. You will get a fixed-price proposal after one scoping call.