Skip to content

Your pentest report has dozens of findings. Which ones actually matter?

Bring the report you already have. We work through it with your developers and check each fix holds before your tester comes back.

Request a scoping call

Free 30-minute scoping call.

A typical SaaS product. A pentest usually tests what faces the internet: the web app, the API and the AI features. Its report covers what it found there.

A finding that passes the retest but is still open

A fictional example of what can go wrong here.

  1. The report flags one endpoint

    The tester shows it handing back other customers’ records.

  2. The team patches that endpoint

    The retest no longer flags it, so the finding is marked fixed.

  3. The cause is elsewhere

    The missing check sits in shared code that ten other endpoints use.

  4. Ten endpoints are still open

    Other customers’ records can still be read through the ones the report didn’t name.

So we ask: Does each fix remove the cause, or only the example in the report?

For your engineer

Two files, after the patch

// api/invoices/[id].ts: patched for the report
const invoice = await findOwned("invoices", id, user.accountId);

// lib/records.ts: still used by ten other endpoints
export const findById = (table, id) => db(table).where({ id }).first();

What we check

The questions we start from. We agree the final list with you on the scoping call.

  • Does each finding actually apply to your product?
  • Which findings expose the most, so you fix them first?
  • Does the same weakness show up elsewhere in your code or settings?
  • Does each fix hold before the retest?

Best done when a report lands with a deadline, when developers dispute findings, or before the retest.

What you get, and what it costs

Fixed fee for the agreed scope, quoted before work starts.

We quote it after the scoping call, once we’ve seen the report: how many findings it has and which systems they touch. If the scope grows later, we price the extra before we start it.

Included

  • Working through the report with your developers, in the order we agree
  • Root causes, and where the same flaw shows up again
  • A check of each fix before your tester comes back
  • A walkthrough call with your engineers

Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Extra work added once we have started.

See what a report looks like

Before you enquire

What people ask us most.

What do you need from us?

The report and any tester notes, time with the developers making the fixes, and the retest date.

Where do you stop?

We work from the report you have. It isn’t a new penetration test, and your original tester still runs the retest.

Who does the retest?

Your original tester. We check the fixes beforehand, so you go into the retest knowing what should pass.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Got a retest date? Send us the deadline and roughly how many findings

When was the report issued, how many findings does it have, and when is the retest?

Request a scoping call

Include your country code. We only use it to follow up on your enquiry.

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team