Penetration testing

Find the gaps before someone else does.

Web application and API testing, scoped properly and quoted as a fixed price. You get a report your auditor and your enterprise customers will accept.

Fixed price per scopeCREST-certified lead testerRetest included

Two ways to run it

Usually the right choice

Grey-box

Testing with working accounts across each role, but no access to your source code. Nothing leaves your environment, and it is the form of test that due-diligence reviewers and certification bodies expect to see.

Source-code assisted

The same coverage with read access to the repositories. Less effort to reach the same depth, so it costs less — worth it if you are comfortable granting that access.

What is included, every time

  • Testing against the OWASP Top 10, plus the LLM Top 10 where an application has AI features
  • Authentication, authorisation and cross-tenant segregation tested across every role
  • A retest of all high and critical findings once you have fixed them
  • A findings walkthrough with the tester who did the work, not an account manager
  • An executive summary written to stand on its own in front of a board or a customer
  • An external summary and attestation letter for due-diligence packs

On pricing. We quote a fixed price for a defined scope, not a day rate. A day rate makes the cost of your test a function of how long it takes us, which is the wrong incentive and the wrong conversation. You should know the number before you commit.

How an engagement runs

1. Scoping

A short form and usually one call: the routes, the roles, the integrations, and what you actually need the report to prove.

2. Pre-engagement

A non-production environment, accounts for each role, an API export, and any WAF allow-listing. None of it onerous, but worth starting early.

3. Testing

A defined window. Critical findings are raised with you as they are found, not held back for the report.

4. Report and retest

Report about a week after testing, then a walkthrough. Retest of high and critical findings once you have remediated.

Testing is carried out by CREST-certified testers working to Summit's engagement terms.

Send us the application and we will scope it.

A short conversation is usually enough to work out whether we can help, and what it would cost.