Penetration Testing Services
Offensive security testing for your applications, APIs, and networks.

Application Security Testing
Offensive security testing for your applications and APIs
Web Application Penetration Testing
API Penetration Testing
Website Security Testing
Mobile Application Security Testing
Desktop Application Security Testing
Network & Infrastructure Penetration Testing
Test your network perimeter and internal trust boundaries
Network penetration testing overviewExternal Network Penetration Testing
Internal Network Penetration Testing
Wi-Fi Security Assessment
Vulnerability Assessment
Specialist Testing Services
Offensive security testing for specialist requirements
Pentest as a Service (PTaaS)
OSINT Reconnaissance
Embedded Device & IoT Security Testing
Password Auditing
Ready to scope your next penetration test?
Key Deliverables
What's included in every engagement?
Executive Report
Technical Report
Debrief Session
Retesting
Attack Surface Center Access
Consultant-led From Start to Finish
Pentest Requirements
Which type of penetration test do you need?
You're preparing for ISO 27001 certification or renewal
Your ISMS audit will expect evidence of independent security testing. We'd typically recommend an external network penetration test as a starting point, combined with web application testing if you have customer-facing systems in scope.You're working towards PCI DSS compliance
PCI DSS Requirement 11.4 mandates penetration testing of your cardholder data environment at least annually and after significant change. We scope CDE-focused engagements to meet PCI DSS requirements and provide evidence-ready reporting for your QSA.You're launching or significantly updating a web application or API
Pre-launch is the right time to test. Application penetration testing identifies authentication flaws, data exposure risks, and business logic vulnerabilities before they reach production - using the same techniques a real attacker would apply.You've never had a penetration test before or aren't sure what you need
That's what scoping calls are for. Tell us about your environment, compliance obligations, and specific concerns. We'll recommend an assessment that fits your risk profile and budget, and provide a fixed quote within 1 business day.
Our Approach
Offensive security led by consultants, not scanners
Every engagement is scoped individually, priced transparently, and delivered directly by our lead consultant from the very beginning.
Our penetration testing methodology draws from OWASP WSTG and NIST SP 800-115, with adversary-informed techniques aligned to the MITRE ATT&CK framework and NCSC guidance.
Whether your goal is meeting a compliance requirement, validating a pre-launch application, or understanding your real-world risk exposure, the focus is on findings that are genuine and exploitable.
Common Questions
Penetration testing & offensive security - frequently asked questions
Everything you need to know about how our offensive security assessments are scoped, priced, and delivered before you request a quote.
All testing is carried out by our in-house consultants, and nothing is outsourced or subcontracted. Your assigned consultant will be confirmed before testing begins and remains your direct point of contact from scoping through to debrief.
Our lead consultant holds OSCP (Offensive Security Certified Professional) and OSCE (Offensive Security Certified Expert) certifications from Offensive Security.
Pricing is based on scope, complexity, and your organisation's context. We publish realistic price ranges so you can quickly assess fit before requesting a quote.
For bespoke engagements, we tailor methodology and consultant time to your objectives. Each quote factors in:
- Scope of testing (e.g., number of IPs, applications, or cloud resources)
- Technical and architectural complexity
- Testing methodology (black box, grey box, white box, or blended)
- Depth of exploitation, reporting, and retest support required
To ensure accurate pricing by not over or under-scoping an assessment, we aim to learn as much about your business and the target(s) as possible.
A scoping call reduces back-and-forth over email, allows for quick walkthroughs of applications or infrastructure, and gives us the context we need to tailor an offensive assessment to your specific risk concerns.
We're able to support scoping discussions via email if preferred.
Most engagements run between 3-5 days of active testing, but could take longer depending on the type of assessment and the complexity of your environment. An internal network pentest may take between 4-8 days, whilst a basic company website assessment may take 1-2 days.
With Exploitr, we provide live access to our findings throughout testing via Attack Surface Center, so you don't have to wait for the final report to start understanding your risk.
To get accurate timelines, schedule a free scoping call to discuss your testing requirements with no obligation.
Retesting is available and can be bundled or quoted separately. For certain assessments, including external network, web application, and API penetration testing, we include free spot-check retesting of remediated findings at no additional charge.
Yes, we can provide an attestation letter confirming that the penetration test was conducted according to the agreed scope and methodology. This can be useful for compliance purposes or to provide assurance to stakeholders.
An attestation of penetration testing is included as standard for all of our engagements.
We can test any part of your environment that you want. We don't require you to test everything, and we don't believe in a one-size-fits-all approach.
We'd recommend including all relevant assets for network testing, and all user roles and critical functionality for application testing, but ultimately it's your choice.
During the scoping call, we'll discuss your environment and objectives in detail to help you determine the most effective scope for your engagement.
These terms describe how much information is shared with the tester before the engagement begins.
Black-box testing simulates an external attacker with no prior knowledge of your environment. It's useful for testing your external perimeter and detection capabilities, but may miss deeper issues due to limited context.
Grey-box testing provides the tester with partial information, which is typically credentials, architecture diagrams, or access to the application as an authenticated user. This is the most common approach for web application and API testing as it balances realism with thoroughness and efficiency.
White-box testing gives the tester full access to source code, architecture documentation, and credentials. This maximises coverage and is often used for compliance-driven engagements or where a deep audit of application security is required.
We'll recommend the most appropriate approach during your scoping call based on your objectives.
