Your pentest report has dozens of findings. Which ones actually matter?
Bring the report you already have. We work through it with your developers and check each fix holds before your tester comes back.
Request a scoping callFree 30-minute scoping call.
A finding that passes the retest but is still open
A fictional example of what can go wrong here.
The report flags one endpoint
The tester shows it handing back other customers’ records.
The team patches that endpoint
The retest no longer flags it, so the finding is marked fixed.
The cause is elsewhere
The missing check sits in shared code that ten other endpoints use.
Ten endpoints are still open
Other customers’ records can still be read through the ones the report didn’t name.
So we ask: Does each fix remove the cause, or only the example in the report?
For your engineer
Two files, after the patch
// api/invoices/[id].ts: patched for the report
const invoice = await findOwned("invoices", id, user.accountId);
// lib/records.ts: still used by ten other endpoints
export const findById = (table, id) => db(table).where({ id }).first();
What we check
The questions we start from. We agree the final list with you on the scoping call.
- Does each finding actually apply to your product?
- Which findings expose the most, so you fix them first?
- Does the same weakness show up elsewhere in your code or settings?
- Does each fix hold before the retest?
Best done when a report lands with a deadline, when developers dispute findings, or before the retest.
What you get, and what it costs
Fixed fee for the agreed scope, quoted before work starts.
We quote it after the scoping call, once we’ve seen the report: how many findings it has and which systems they touch. If the scope grows later, we price the extra before we start it.
Included
- Working through the report with your developers, in the order we agree
- Root causes, and where the same flaw shows up again
- A check of each fix before your tester comes back
- A walkthrough call with your engineers
Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Extra work added once we have started.
Before you enquire
What people ask us most.
What do you need from us?
The report and any tester notes, time with the developers making the fixes, and the retest date.
Where do you stop?
We work from the report you have. It isn’t a new penetration test, and your original tester still runs the retest.
Who does the retest?
Your original tester. We check the fixes beforehand, so you go into the retest knowing what should pass.
How do you handle confidential material?
Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.
Got a retest date? Send us the deadline and roughly how many findings
When was the report issued, how many findings does it have, and when is the retest?
What happens next
Sending an enquiry doesn’t commit you to anything. About the team
