Skip to content
Vaptiq logo mark — V orientationVAPTIQ
Black box from $700

We find the way in.

Manual penetration testing by CREST, OSCP and OSWE-certified testers. Every finding arrives with a working proof, published to your portal the day it is confirmed.

  • CREST CRTRegistered Penetration Tester
  • OSCPOffensive Security Certified Professional
  • OSWEOffensive Security Web Expert
  • BSCPBurp Suite Certified Practitioner
  • CRTOCertified Red Team Operator
  • CRTPCertified Red Team Professional
  • CREST CRTRegistered Penetration Tester
  • OSCPOffensive Security Certified Professional
  • OSWEOffensive Security Web Expert
  • BSCPBurp Suite Certified Practitioner
  • CRTOCertified Red Team Operator
  • CRTPCertified Red Team Professional

[ 01 / How it runs ]

Two ways to test.
They are not the same thing.

Most providers sell one and quietly deliver the other. We price them separately, describe them honestly, and tell you which one your situation actually calls for.

AI-powered pentesting

Continuous scan

01

Automated discovery, exploitation of known classes, and AI triage. A tester reviews the queue before anything reaches you. Built for the gap between engagements, when your codebase keeps moving.

  • Results within 24 hours
  • Every finding human-reviewed before release
  • Re-runs on each release or on a schedule
  • False positives removed before you see them

From

$399/ scan

Pricing

Manual engagement

Full penetration test

02

A certified tester works your target by hand for days, chaining findings until each one has a working proof. This is what auditors, enterprise buyers and your own board mean when they say penetration test.

  • Business logic and access control, tested by a human
  • Named tester, reachable throughout
  • Letter of attestation for customers and auditors
  • One free retest within 90 days

From

$700/ engagement

Services

[ New ]

No high or critical findings?
We refund the invoice.

For qualifying manual assessments where we have full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee back on your invoice. Confirmed in writing before we touch a packet.

Applies to grey box and white box engagements. Excludes black box, scans, and retests. Terms set in the engagement letter.

[ 02 / Coverage ]

Everything you own that an attacker can reach.

Twelve engagement types across four families. If your estate spans several of them, we run one combined engagement and one report rather than four invoices.

Testing models

03 services

Applications

03 services

Infrastructure

05 services

Adversarial

02 services

[ 03 / Engagement ]

Six steps, in this order, every time.

No stage of a penetration test should be a surprise to the people paying for it. Here is the whole thing, including the parts most providers leave out of the proposal.
  1. 01

    Scope

    A short call, then a written scope with a fixed price. If the scope does not change, the number does not change.

    1-2 days
  2. 02

    Recon

    Automated discovery maps your attack surface and clears the noise, so the tester starts the engagement already oriented.

    AI-accelerated
  3. 03

    Test

    A named, certified tester works the target by hand, chaining findings until each one has a working proof rather than a maybe.

    3-15 days
  4. 04

    Report

    Findings appear in your portal as they are confirmed. Your team can start fixing on day two instead of waiting for a PDF.

    Live
  5. 05

    Debrief

    A working session with your engineers. We walk the attack paths, answer questions, and agree what gets fixed first.

    90 minutes
  6. 06

    Retest

    Once you have fixed things, we verify every finding again and reissue the report and letter of attestation.

    Included, 90 days

[ 04 / Platform ]

Findings arrive while we are still testing.

The six-week PDF is a habit, not a requirement. Confirmed findings publish to your tenant the moment they are verified, so remediation starts on day two rather than after the engagement ends.

EngagementACME · Grey box · Q3
Testing in progress · day 4 of 8
4 of 4 findings
Example findings as they appear in the Vaptiq reporting platform
IDSeverityFinding
VPQ-0142Critical
VPQ-0139High
VPQ-0131High
VPQ-0128Medium

Illustrative data · select a row to see what your team sees

Live findings

Published as they are confirmed, with reproduction steps and evidence attached.

Talk to your tester

Comment on any finding and get an answer from the tester who wrote it, not a support queue.

[ 05 / Who tests ]

Certifications you can check, on people you can name.

Every engagement is led by a tester holding at least one of these. You get their name before the test starts and their signature on the report when it ends.
CREST CRTRegistered Penetration Tester
OSCPOffensive Security Certified Professional
OSWEOffensive Security Web Expert
BSCPBurp Suite Certified Practitioner
CRTOCertified Red Team Operator
CRTPCertified Red Team Professional
Tested againstOWASP ASVSOWASP MASVSOWASP API Top 10OWASP Top 10 for LLMsPTESNIST SP 800-115MITRE ATT&CKCVSS v4.0CIS Benchmarks

[ 06 / What we look for ]

The kind of thing an attacker is actually looking for.

Representative examples, not case studies. This is the class of issue we hunt for, how we prove it, and exactly what lands in your report — with a working proof, not a scanner flag.

Access control

Critical

Tenant-isolation bypass on document export

One account reaching another tenant's data. We prove the full path, then hand you the exact request to reproduce and fix.

Authentication

Account takeover

Predictable password-reset tokens across environments

A token you can guess is an account takeover waiting to happen. We show the guess, the takeover, and where the entropy went wrong.

Attack surface

Unknown exposure

Internet-facing assets missing from the asset register

You cannot defend what you have not counted. We map what is actually exposed and assign ownership in the debrief.

5–10 daysTypical start time from scope confirmation
100%Every finding shipped with a working proof, never a raw scanner flag
90 daysFree retest window included on every engagement

[ 07 / Questions ]

The questions people ask before they sign.

If yours is not here, send it to [email protected] and you will get an answer from a tester.

No. AI does reconnaissance, enumeration and first-pass triage, the mechanical work that used to eat the first two days of every engagement. Exploitation, chaining, impact analysis and the report itself are done by a certified tester whose name is on the document. We would rather be slower than pretend otherwise.

Because the recon that used to be billed by the hour is now largely automated, and because we do not run a sales team. $700 is a genuine small-scope external test with a real tester on it, not a scan with a logo on the front page. Larger scopes cost more, and you see the number before you commit.

Testers holding CREST CRT, OSCP, OSWE, BSCP, CRTO and CRTP. You are told which tester is assigned to your engagement before it starts, and you can talk to them directly through the platform while it runs.

Yes. Reports follow the structure auditors expect, findings carry CVSS v4.0 scores and reproduction steps, and every engagement includes a letter of attestation you can share with customers without handing over the full technical report.

An AI-powered scan runs within 24 hours of scope confirmation. A manual engagement typically starts within five to ten working days, and we hold slots for existing clients who need a retest before a launch.

Evidence lives in the platform, encrypted at rest, in a tenant only your team and the assigned testers can reach. You can export everything at any time, and we destroy engagement data on request or on the schedule agreed in your contract.

Find out what is reachable, before somebody else does.

Thirty minutes on a call is usually enough to scope an engagement and give you a fixed price. No pipeline, no sales engineer. You talk to someone who tests.