Skip to content

FAQ

Questions people actually ask before buying a pentest.

If something is not covered here, ask us on a scoping call. We would rather answer it properly than have you guess.

General

General questions

What is a penetration test, and why does it matter?

A penetration test is a time-boxed, authorised attempt to break into your systems the way a real attacker would, followed by a written account of what worked. It matters because it tells you which weaknesses are actually exploitable in your environment, rather than which ones a tool flagged as theoretically present.

How often should we test?

Annually is the common baseline, and after any significant change to authentication, authorization, or your externally reachable surface. A test is a snapshot of one moment. If you rewrote your login flow last month, last year's report no longer describes your application.

We do not hold sensitive data. Why would anyone attack us?

Most attacks are not targeted. Automated scanning finds your systems because they are reachable, not because of what they contain. Your infrastructure has value as a foothold, a mail relay, a host for someone else's content, or a route into a customer with deeper pockets than you.

What is the difference between a vulnerability scan and a penetration test?

A scan compares what it can see against a list of known issues and produces output. A penetration test uses scanning as one input, then a person tries to exploit what was found, chains findings together, and tests the logic no scanner understands. If a report reads like tool output, you paid for a scan.

How does a bug bounty compare to a penetration test?

They answer different questions. A bounty gives broad, ongoing, unpredictable coverage from many researchers, paid per finding. A penetration test gives systematic, scoped, scheduled coverage with guaranteed completion and a written deliverable you can hand to an auditor. Mature programmes run both.

Do you work with startups and small businesses?

Yes, and it is most of what we do. A three-person team means we can scope an engagement that fits a twelve-person company without pretending it needs an enterprise budget.

How do we get started?

Book a scoping call. We will ask what you have built, what worries you, and what your constraints are, then propose a scope and a fixed price. Scoping calls are free and we do not require you to have answers ready.

Pricing

Pricing questions

What does a penetration test cost?

Engagements start at $2,500 CAD. That is a real starting figure rather than a teaser, and it covers a focused assessment of a single application or a small external perimeter. Larger scopes cost more, and you get a fixed price in writing before any work begins.

What drives the cost of an engagement?

Scope and time, almost entirely. The number of distinct roles, the number of endpoints or hosts, whether source code is available, and whether a retest is included. We quote a fixed price after scoping, so the figure you approve is the figure you pay.

What is included in the price?

Testing, the full written report, a walkthrough call to go through the findings with your developers, and one retest of the affected areas after you have remediated. Nothing in that list is an upsell.

Does the retest cost extra?

No. One retest of the findings from the engagement is included. We would rather confirm the fixes landed than sell you a second engagement to find out.

Do you charge for scoping?

No. Scoping calls are free, and so is the proposal. If the scope we recommend is smaller than the one you asked about, we will tell you that rather than quote the larger number.

What if you find nothing serious?

You still get the full report, the grade, and the positive observations section recording which controls held up under testing. That is a useful document to hand a customer or an auditor, and it is a legitimate outcome rather than a failed engagement.

Testing process

Testing process questions

What can you test?

Web applications, mobile applications on iOS and Android, APIs including REST, GraphQL and SOAP, and internal and external networks. If what you have built does not fit neatly into one of those, describe it on a scoping call and we will tell you honestly whether we are the right firm for it.

Should we test production or pre-production?

Production gives the truest result, because pre-production environments differ from production in exactly the ways that cause findings. Where production testing is genuinely too risky, we test a pre-production environment that mirrors it and record the difference as a limitation in the report.

Do you test for denial of service?

No. Denial of service is excluded from every engagement by default. It proves something everyone already knows, and the cost of proving it is an outage. If you specifically need resilience testing, that is a separate conversation with its own controls.

Do we need to demonstrate the system before testing starts?

It helps considerably and takes about thirty minutes. Walking us through the workflows and roles means we spend the engagement testing your business logic rather than reverse-engineering how the application is meant to be used.

How are vulnerabilities reported?

Each finding gets a CVSS vector, a CWE classification, the affected endpoints or hosts, full reproduction steps, evidence, and remediation guidance written against your stack. Critical findings are reported immediately during the engagement rather than held until the report.

Do you fix the vulnerabilities you find?

We do not implement fixes in your codebase. Testing a system we built would compromise the independence that makes the report worth having. We do give remediation guidance specific enough to act on, and we will talk your developers through any finding.

What do you need from us to start?

Written authorisation, the in-scope targets, test accounts for each role, and a named technical contact. For white box work, repository access as well. We supply the authorisation template.

Confidentiality

Confidentiality questions

How is our data handled during a test?

We collect the minimum needed to prove a finding, and evidence is redacted where a screenshot would otherwise carry real personal or financial data. Engagement material is held encrypted, and is destroyed on request once the retest is complete.

How do we know your testing is traceable?

All testing originates from a declared IP range that is named in the report. Anything from that range during the testing window was us. Anything else was not, which makes your logs readable during and after the engagement.

How can we trust an outside team with this access?

Reasonably, you should not trust it on assurance alone. Every engagement runs under a signed authorisation that names the scope, the window and the exclusions, testing comes from a declared IP range, and the report states plainly what was not tested. Those are the things that make the work auditable.

Will you sign our NDA?

Yes. We will also sign your vendor security questionnaire and your data processing agreement, and we would rather do that before the scoping call than after.

Who sees the report?

You do. We do not publish client names, and case studies on this site are anonymised to the point where the client is not identifiable. If you want to be named as a reference, that is your decision to offer rather than ours to ask for.

After the test

After the test questions

What happens once testing finishes?

You get the report, then a walkthrough call where we go through the findings with whoever is going to fix them. That call is usually where the most value lands, because it is where the report stops being a document and becomes a work plan.

What is the retest?

Once you have remediated, we test the affected workflows again and issue a retest summary confirming what is closed and what is still open. It is included in the engagement, and it is the only way to know a fix actually worked rather than appeared to.

How long do we have to remediate before the retest?

There is no clock we enforce. Most teams are ready within four to eight weeks. Tell us when you are ready and we will book it.

Can we share the report with customers or auditors?

Yes, it is your document. The report is structured so the executive summary and grade can be shared with a non-technical audience without exposing reproduction steps, which is usually what a customer or auditor actually needs to see.

When should we test again?

After significant change to authentication, authorization or your external surface, and otherwise annually. If you are shipping continuously, an annual test plus a retest after major releases is a reasonable rhythm.

Find out what an attacker would find first.