Before a sensitive launch
Assess a portal, API, or critical feature before broad exposure.
Penetration testing is an authorized assessment that simulates attack techniques against a defined scope to demonstrate exploitable vulnerabilities. It combines information gathering, technical testing, impact validation, and a remediation report. A pentest provides a targeted point-in-time view; it cannot prove that no vulnerability exists.
In one sentence
A pentest demonstrates, within an authorized scope, how a weakness can become a real impact.
Key points
Term at a glance
Testing may cover an application, API, infrastructure, wireless network, or human scenario according to the engagement. The tester looks for realistic paths: one weakness, a chain of misconfigurations, or a business-logic bypass. Proof is limited to avoid unnecessary harm.
Scope determines value. Domains, addresses, accounts, data, environments, permitted techniques, and emergency contacts must be explicit. Testing a third-party system or leaving scope without permission creates technical and legal exposure.
A pentest is a point-in-time assessment. A code change can introduce a flaw the next day. It complements but does not replace patching, secure configuration, AppSec testing, monitoring, and incident response. Findings need owners, deadlines, and a remediation process.
Define objectives, assets, exclusions, accounts, data, techniques, windows, contacts, and stop conditions.
Map the surface, evaluate controls, and safely seek exploitable combinations.
Retain minimal reproducible evidence, assess reach, and remove test artifacts.
Prioritize findings, explain remediation, and confirm that the weakness and close variants are fixed.
During a client portal pentest, a tester finds that a standard account can call a hidden administration route. They read only one authorized demonstration record, capture the request, and stop exploitation. The report links the authorization flaw to its impact, recommends a centralized server control, and includes a retest after remediation.
Assess a portal, API, or critical feature before broad exposure.
Test new architecture, authentication, integration, or migration that changes the attack surface.
Provide an independent assessment with documented scope, method, findings, and treatment.
Test how several defences hold up together against realistic scenarios beyond scanning.
A pentest answers a precise question about a surface at a point in time. Value comes from remediation, reduced risk, and lessons fed into development. When comparing proposals, examine method, time, expertise, report depth, and retesting rather than address count alone. The linked service page presents delivery; this page provides selection criteria.
An audit may review governance, configuration, evidence, and compliance. A pentest actively attempts to exploit weaknesses within an authorized scope. One engagement can combine them, but objectives and evidence differ.
Black-box gives the tester little information, grey-box provides accounts or context, and white-box opens more architecture and code. The choice follows the threat and time; more information often enables deeper coverage.
There is risk. Scoping, load limits, backups, monitoring, available contacts, and stop rules reduce it. Destructive techniques should be excluded or explicitly authorized in a suitable environment.
Need to test an application or infrastructure? We can define a safe scope, execute scenarios, and verify remediation.
Scope a pentest