Looking for a penetration test? Fixed-scope engagements for SOC 2, ISO 27001 & HIPAA.Get a quote today →
Request a Quote
Process

How an engagement runs, start to finish

Four stages, one dedicated team throughout. No hand-off between a scoping call and the people actually testing your application.

Typical Timeline
Scoping to StartWithin a Week
Testing Window1–3 Weeks
Report DeliveryWithin 5 Business Days
RetestScheduled After Fixes Ship

What happens at each stage

Timelines below are typical for a single web application or API. They adjust based on scope and your deadline.

01

Scoping

Day 1–2

A call to walk through the application, the compliance driver behind the engagement, and any deadline you're working against. From there you get a written proposal with scope, price, and a start date.

  • What's in scope: application, API surface, environments, and any exclusions
  • What triggered the engagement: SOC 2, ISO 27001, HIPAA, PCI-DSS, or a customer's security review
  • Access needed: test accounts, staging environment, and any relevant documentation
02

Testing

1–3 Weeks

Manual testing against the agreed scope: authentication, authorization, business logic, and injection classes, along with anything specific to how your application is built. This isn't scan and forward. Every finding is manually verified before it's reported.

  • Critical or high-severity findings are flagged as soon as they're confirmed, not held for the final report
  • Short check-ins available on request if you want visibility mid-engagement
03

Reporting

Within 5 Business Days of Testing

A written report covering scope, methodology, findings, and severity, with reproduction steps and remediation guidance for each issue. Formatted for direct submission to an auditor or compliance platform, not just internal reading.

  • Delivered with a walkthrough call for your engineering team
  • Findings explained in terms of what they mean for the application, not just a CVSS score
04

Retesting

Scheduled Once Fixes Are Deployed

Once your team has addressed the findings, each one is retested and confirmed closed. You get updated documentation showing what was fixed and verified: the evidence an auditor typically asks for.

  • Included in the original engagement scope, not billed as a separate project

No surprises, either direction

What we need to start

  • A few paragraphs on what the app does and who uses it. Not a slide deck, just enough that we're not guessing on day one
  • Login for every user role that exists, including admin. If there's a role we can't test, it's a role that doesn't get tested
  • Staging access, or a heads-up if we're testing against production
  • One person we can message directly when something comes up, not a ticket queue

What you get back

  • A fixed price before we touch anything. No surprise invoice at the end
  • A message the moment something critical turns up, not buried on page 40 of a PDF two weeks later
  • A report your auditor can use as is, no reformatting on your end
  • A retest, already covered in the original price, once fixes ship

Ready to scope an engagement?

Send over your application, compliance requirement, and timeline, and you'll get a proposal back directly.