Follow your penetration test from day one

Every penetration test includes access to the Exploitr platform at no extra cost. Findings and attack paths appear as we confirm them, and your team tracks remediation in one place.

Pentest report platform's vulnerability overview, showing mean time to remediate, reopen rate, and remediation velocity over time

Working alongside your team

Every engagement is delivered by an experienced consultant working in the Attack Surface Center alongside your team. You can see what we've found as we go, with the evidence, the steps to confirm and reproduce the issue, and the remediation guidance for each finding.

Your developers can start fixing while we're still testing, we can verify those fixes before we've finished, and your security team always knows the current status without waiting for an email. By the time the written report is delivered, it confirms what you already knew.

How our engagements run

  • Scope, authorisation, and contracts agreed
  • Security testing services are delivered
  • Reports are created and populated alongside testing
  • Daily check-ins, with critical vulnerability notices
  • We debrief the engagement with you and your team

Before testing

Scoping is a conversation

We don't ask you to set up an engagement in the platform. Scoping starts with a call, with the consultant who will be delivering the testing.

Once the scope and authorisation are in place, we'll prepare your access so it's ready before testing starts. There's nothing for your team to configure, and no onboarding project.

  • You'll speak to the consultant, not a sales person

    The person scoping your engagement is the one who'll be delivering it.
  • A fixed, written quote

    The scope is stated clearly, with a fixed price.
  • We'll say if you don't need it

    If a narrower testing scope would suit your requirement, that's what we'll recommend.
  • No setup required

    We'll prepare your account once the scope is signed off. You can start inviting your team ready to review the findings.
  • Reports set up in advance

    The scope is recorded in the platform, with the reports set up ahead of the scheduled testing window.
During testing

Your report, written as we test

A critical issue discovered on the first day of testing is logged in your dashboard there and then, with the evidence, reproduction steps, and remediation guidance attached.
  • Every issue is validated by hand: The consultant confirms each issue before it appears in the report. Nothing is auto-populated from a scanner.
  • Full technical detail: Severity, CVSS v4.0 and v3.1 scores, and the affected asset, port and URL.
  • Evidence attached to every issue: Requests, responses, and screenshots sit alongside the finding, so your developers can reproduce it without needing to request more information.
  • Retest status from the outset: Each vulnerability carries its own status, so you can see what's open, what's been fixed, and what's waiting on a retest.
Pentest report vulnerability detail showing CVSS scores, affected asset, and attached evidence
  • Written remediation guidance: Each finding provides a recommendation written by the consultant for your environment, rather than pasted from a template.
  • Mapped to MITRE ATT&CK: Where applicable, findings are linked to the relevant MITRE ATT&CK technique, so your security team can line the results up against their existing detection coverage.
  • Read it in the platform, or export it: Work through the report in the browser, or download the PDF for offline review.
  • Collaborative vulnerability management: No forwarding PDFs, CSVs, or spreadsheets. Your whole team works in one place to prioritise and track remediation.
Pentest report finding details showing technical description, remediation guidance, and MITRE ATT&CK technique mapping
Connecting findings

How separate issues combine

Individual findings rarely tell the whole story. Where several issues can be chained together across your environment, we map the route an attacker would take and show you the shortest way to break it.
  • See the route, not just the list: Each path is drawn from its entry point through to its outcome, showing where it crosses a network boundary.
  • Find where paths converge: Assets carrying more than one attack path are highlighted, so you can see where a single fix can affect several routes at once.
Attack path map showing entry points and assets where multiple paths converge
  • Every stage is evidenced: Each step in the path links back to the finding and the asset it relates to, along with the preconditions an attacker would need to reach it.
  • Minimal viable remediation: We identify the smallest set of fixes that could mitigate the attack path, so you can see the quickest route to reducing the risk.
Attack path stages with the minimal viable remediation highlighted

After testing

The engagement doesn't end when the report is delivered

Everything we report stays available in the platform after testing finishes, along with the tools your team needs to track what happens next.
  • Report within 2 business days

    Executive summary and full technical findings, exportable whenever you need it for a customer, board, or auditor review.
  • Attestation of testing

    Offered as standard on every engagement. Download it as a PDF once the assessment is completed.
  • Remediation tracking

    Assign tasks, update vulnerability statuses, and keep a record of who fixed what and when.
  • Your access doesn't expire

    The report, the findings, the attack paths, and the remediation history stay available to your team indefinitely.
  • Request a retest from the finding

    Fix an issue, request the retest from the finding, and add any context for the tester. Included on remotely delivered web application, API, and external network engagements.

Common questions

Questions about the platform

No. Access to view your reports, manage your vulnerabilities and assets is included with every Exploitr engagement at no extra cost, and it isn't priced separately in your pentest quote.

No. The written report is the main deliverable. If your team already works somewhere else and the platform would only add a step, you can simply download the report and ignore the rest.

No. Add as many people from your team as the results are relevant to, whether that's two developers or your whole engineering, security, and leadership group.

The findings will show in the same organisation account. Your history builds across engagements rather than starting from an empty dashboard each time, so you can see how your remediation efforts are trending between tests.

This applies across every service we offer, so a web application test and an internal network test sit alongside each other.

Your next test, with all of this included

Tell us what's in scope and we'll come back with a proposal that fits your requirements. Our pricing is fixed and published, so you know roughly where you stand before you ask.