Penetration Testing
We attack your systems the way a funded adversary would, then hand you the exact path they took — with a fix for every step of it.
- Typical duration
- 2–4 weeks
- Primary audience
- IT & Dev Teams
- You leave with
- A prioritised, reproducible list of what is actually exploitable — and proof it is closed.
Three phases, start to finish.
- 01 Scope and rules of engagement What is in play, what is off-limits, and who we call if we find something that cannot wait. Agreed and signed before anyone touches a system. External, internal, web, API, mobile and cloud targets agreed in writing Named escalation path for critical findings, in hours or out Test windows set around your release and change calendar
- 02 Manual exploitation Testers work the target by hand and chain what they find the way a funded adversary would. A scanner is where we start, never what we hand you. Every finding proven by exploitation, not inferred from a version banner Attack paths chained end to end rather than listed in isolation Daily progress notes, and a same-day call on anything critical
- 03 Report, walkthrough and re-test You get the exact path we took with a fix for every step of it — then we come back and prove the fixes hold. CVSS plus real-world business impact for every finding Live walkthrough with the engineers who have to do the work Free re-test of every remediated finding within 90 days
How we scope
Scoping is a technical conversation, not a questionnaire. We want to know where your architecture is unusual, which systems have never been tested, and what you would least like us to find. That conversation typically saves two to three days of rediscovery, which is time we spend on depth instead.
What the report contains
- An executive summary that a non-technical reader can act on
- Every finding with CVSS v3.1, business impact, and full reproduction steps
- Working proof of concept where one can be produced safely
- Remediation guidance scoped in engineer-hours, not in adjectives
- A retest appendix you can hand straight to an auditor
Re-testing
Every remediated finding is re-tested at no additional cost within 90 days of report delivery. We issue a closure letter that references the original finding IDs, which is the artifact your ISO 27001 or SOC 2 auditor will ask for.
Penetration Testing: the questions we get asked.
How much does a penetration test cost in Canada?
Cost follows scope, not company size. A single web application is a different engagement from a multi-region cloud estate with an internal network in it. Tell us what you want tested and you will get a written cost band before any discovery call — no scoping questionnaire, no gated quote. Most engagements run two to four weeks of tester time.
Is this the same as a VAPT?
It covers the same ground. VAPT — vulnerability assessment and penetration testing — is the term more common in procurement documents than in testing itself: the assessment half is the scanning and enumeration, the penetration testing half is the manual exploitation. If your tender asks for VAPT, this is the line that answers it.
What is the difference between a penetration test and a vulnerability scan?
A scan lists what might be wrong by matching versions against a database. A penetration test proves what is actually wrong by exploiting it, and chains findings the way an attacker would. We run scanners as a starting point; we do not hand you their output as a deliverable.
Will testing take our systems down?
Denial-of-service techniques are out of scope unless you specifically ask for them and sign for them. Test windows are set around your release and change calendar, and you get a named escalation contact who can stop the test at any point.
Is the re-test really included?
Yes. Every remediated finding is re-tested at no additional cost within 90 days of report delivery, and you get a closure letter citing the original finding IDs — the artifact your ISO 27001 or SOC 2 auditor will ask for.
Other lines of work
All servicesTell us what triggered the search. We will scope to that.
We reply to every assessment request within one business day.
