Penetration Testing as a Service (PTaaS Pilot)

A repeating pentest programme pilot for web apps and APIs with clear finding boundaries; all retests within the agreed scope included.

PTAAS-01Duration: Indicative 7–10 business days, depending on agreed scope and accessSecurity

Outcome

A reviewable report instead of a tool login: findings CVSS-rated, PoC per finding, remediation priorities.

Who it is for

B2B teams (5–200 employees) with production web apps/APIs and a security or compliance budget.

Deliverables

  • Scope definition (in-scope apps), agreed in writing
  • Authenticated test access (own test accounts)
  • Automated scan suite + manual probing sessions
  • Report: exec summary, finding matrix, PoC evidence, remediation priorities
  • 60-min debrief Q&A
  • All retests of reported findings within the agreed scope (included, across multiple fix rounds)

In scope

  • 1 web app or 1 API bundle up to 25 endpoints
  • External + authenticated testing
  • Retests of all reported findings within the agreed scope

Out of scope

  • Onsite/physical testing
  • Social engineering
  • Production database exports

Prerequisites

  • Least-privilege test accounts
  • Data processing agreement (DPA) before data access
  • Signed rules of engagement (RoE) before start

Acceptance

  • Acceptance via delivered finding matrix with PoC notes per item and residual-risk estimate.

Human approvals

  • CISO/owner confirms scope + RoE
  • Human reviews PoC evidence before report release

Frequently asked questions

Are retests really included?

Yes. All retests of reported findings are included within the scope agreed in writing. New systems or functions outside that scope are a separate engagement.

How do you handle third-party zero-days?

Coordinated disclosure: vendor bulletin plus bypass recommendation in the report; no exploit publication.

Can the report be used as certification or audit evidence?

The report is structured for audit use (scope, method, evidence, timestamps) and can serve as evidence. Whether an auditor or certification body accepts it is that body's own decision; this is not promised.