Service · Manual Pentest

A human pentest you pay for only if it finds something serious.

Senior testers work your application by hand for the whole engagement - business logic, authorization boundaries, chained abuse, the flaws no scanner has an opinion about. You get the full report either way. If it closes with no High or Critical finding, we do not invoice the engagement.

Fixed quote before testing · no subscription · one free retest within 90 days · report and evidence yours to keep

Engagement AP-2411 · final report
2
Findings at High or above
10 testing days · 4 roles · 2 tenants crossed
critical Cross-tenant order read · /api/v2/orders/{id} 9.1
high Support role mints admin invites 8.2
medium Refund workflow skips approval step 6.4
billing 2 findings ≥ High invoice issued

Had that last row read 0 findings ≥ High, it would read not invoiced.

No High or Critical · no invoice90-day free retest included4 reports + signed attestation letterNamed senior testers, no subcontracting
Why a human is still worth the days

Machines find the flaw. People find the rule that was never written down.

Our own engine proves injection, exposure and misconfiguration faster and more consistently than any human can, on every release. What it cannot do is decide that a refund should never exceed the original payment, or that a support agent is not supposed to see another tenant's invoices. Those are the findings that end up on the front of the report.

Business logic and workflow abuse

Multi-step flows completed out of order, prices and quotas manipulated between steps, approvals skipped, state machines walked backwards. Nothing is technically malformed - the application does exactly what it was told to do.

Chained escalation

A low-severity information leak, a weak reset link and one over-permissive role are three medium findings on their own. Chained, they are account takeover - and only a person patient enough to try the chain writes it up that way.

Authorization across every role and tenant

We provision a real account for each role, then systematically attempt every action from every one of them, across tenants. Broken object-level authorization is still the most common serious finding we report, and it is invisible to a single-account scan.

Severity a person can defend

A CVSS vector plus the captured proof, argued in front of your engineers on the walkthrough call. No inflated criticals to justify the invoice, and no quietly downgraded findings to make the report look clean.

The commercial promise

No High or Critical finding, no invoice.

Most pentests bill for effort. This one bills for outcome. If ten testing days on your application produce nothing rated High or Critical, you owe us nothing - and you keep the report, the evidence, the attestation letter and the retest anyway. We can offer that because the agentic baseline tells us before we quote whether the scope is worth a human week.

The fee is waived when

  • the engagement closes with no confirmed in-scope finding at CVSS v3.1 ≥ 7.0
  • a High or Critical we did report is successfully disputed by you on severity
  • we could not complete the agreed scope for a reason on our side

The guarantee does not cover

  • retests, continuous programmes and follow-on engagements - the first engagement on a scope is the one that carries it
  • an environment unavailable, unstable or reset for more than a quarter of the agreed window
  • scope reduced, credentials withheld or roles not provisioned after the rules of engagement were signed
  • blocking put in our path mid-test - a WAF, rate limit or IP ban with no allowlist agreed
  • pre-agreed pass-through costs such as travel or hardware, which are billed at cost either way

How a finding qualifies: in the agreed scope, confirmed with a reproduction we hand you, and rated CVSS v3.1 base score ≥ 7.0 with the vector printed in the report. One qualifying finding makes the engagement billable at the quoted fee - there is no per-finding pricing, and finding twenty does not cost more than finding one. If you dispute the rating on the finding that decides the invoice and we cannot reach agreement, the engagement is not invoiced.

How it runs

Six steps, fixed price, no time-and-materials surprise

Scoping to signed attestation, typically three to four weeks end to end.

01

Scope and rules of engagement

One call to agree the targets, the roles, the window and what is off-limits. You get a fixed quote and a signed authorization document before anything is touched - no time-and-materials surprise.

02

Agentic baseline first

The platform's crawl, active scan and Agentic Pentest run over the scope before a human starts. The machine clears the ground it is good at, so the tester's days are not spent re-finding a reflected XSS.

03

Reconnaissance and attack-surface map

Hosts, subdomains, endpoints, parameters, roles, tenants and third-party integrations, mapped by hand against what the crawl found. What the automation missed is usually where the interesting bug lives.

04

Manual exploitation

The engagement itself: authorization matrices across every role and tenant, business-logic and workflow abuse, chained escalation, and exploitation of anything the baseline only suspected. Everything captured as request, response and reproduction steps.

05

Report and walkthrough

A draft within three business days, then a live walkthrough with your engineers - not a PDF over the wall. Every finding leads with impact and the exact steps to reproduce it.

06

Free retest within 90 days

Fix, then tell us. We re-test every reported finding, mark what is closed, and reissue the report and attestation letter against the fixed state.

Agentic + manual

Run the machine continuously. Bring the humans in for the logic.

They are not competitors and you should not choose. The engine covers every release; the engagement covers what reasoning cannot be automated - and each makes the other cheaper.

Agentic Pentest (product) Manual Pentest (service)
Who does the testingThe agentic loop, continuouslySenior testers, by hand, for a fixed engagement
Best atInjection, exposure, misconfiguration, regression after every deployBusiness logic, authorization matrices, chained escalation, abuse of intended features
CadenceEvery release, unattendedPoint in time, then a retest
EvidenceDeterministic verdict - marker, timing or canaryCaptured request/response plus a written reproduction a developer can follow
DeliverableFindings in the platform, exportableFour reports plus a signed attestation letter
Priced byTarget URL, per yearEngagement - and only if it finds a High or Critical

Every manual engagement includes an Agentic Pentest pass over the same scope, run before the humans start. It is not an upsell - it is how we keep the human days on the findings that justify them.

Scope

What we test by hand

Scope is agreed in writing before anything is touched. Anything not listed here, ask - we will say honestly whether we are the right team for it.

Web applications

Authenticated multi-role testing of the whole application, not the login page - SPA, server-rendered or hybrid.

APIs

REST, GraphQL and gRPC: object-level and function-level authorization, mass assignment, tenancy boundaries, rate and quota abuse.

Business logic

Pricing, discounts, refunds, quotas, approval chains, multi-step workflows - the rules a scanner has no opinion about.

Authentication & sessions

SSO and OAuth/OIDC flows, MFA bypasses, password reset and invite chains, session fixation and token handling.

Cloud & Kubernetes

Exposed services, IAM and role escalation paths, metadata access, cluster and workload configuration reachable from the app.

Internal & network

On request: internal network, Active Directory and workstation-to-domain paths, with an on-site or VPN-based tester.

Mobile applications

Android and iOS clients together with the backend they talk to - storage, transport, certificate handling and API abuse.

AI and LLM features

Prompt injection, tool and function-call abuse, data leakage across tenants, and the authorization boundary behind the model.

Deliverables

Four reports, because four different people have to read one

The same engagement, written four ways - so the board, the engineer, your customer and your auditor each get the document they actually need.

Technical report

Every finding with impact, CVSS v3.1 vector, the request and response that proves it, reproduction steps and a concrete fix - written for the engineer who has to close it.

Executive summary

Two pages for people who will not read the other forty: what was tested, what the real business exposure is, and what to do first.

Customer-safe report

The same conclusions with your stack, hostnames and internal details removed - the version you send to a prospect's security questionnaire.

Auditor pack & attestation

Scope, methodology, dates, tester names, findings and post-retest remediation status, plus a signed attestation letter for SOC 2, ISO 27001 and PCI DSS.

Also in the pack

  • Every finding as a captured request and response, with sensitive values masked
  • Reproduction steps a developer can follow without asking us a question
  • A concrete fix per finding - the code or configuration change, not "validate input"
  • Findings importable into apPosture, deduplicated against your existing posture
  • A named tester and a signed attestation letter on letterhead
  • A reissued report and letter after the free 90-day retest
Pricing

Fixed fee per engagement - conditional on the outcome

Quoted after the scoping call, fixed before testing starts, and only invoiced if the engagement produces a High or Critical finding. Prices are per engagement and exclude VAT.

Focused

from $4,900

Per engagement. One web application or one API, 5 testing days.

  • Up to 2 roles, single tenant
  • Agentic Pentest baseline pass
  • Full report set + attestation
  • Free retest within 90 days
  • No High or Critical → not invoiced
Scope this →

Programme

Custom

Multi-service platforms, mobile, internal network and Active Directory, or a recurring schedule.

  • Everything in Standard
  • Multi-application or multi-service scope
  • Mobile, internal and on-site testing
  • Recurring engagements on your release calendar
  • Continuous Agentic Pentest between engagements
  • Guarantee applies to the first engagement per scope
Talk to us →

A retest, a re-run of a scope already tested, and pre-agreed pass-through costs such as travel are billed normally - the guarantee covers the first engagement on a given scope, which is the one where you are taking the risk on us. Manual Pentest is sold standalone; it needs no apPosture licence. Platform customers can have the findings imported into their existing posture at no extra cost.

Safety

Rules of engagement, agreed in writing first

Nothing destructive

No denial-of-service, no load testing, no destructive verbs against live data, no exfiltration of real customer records. Proof is captured with benign markers and masked before it reaches the report.

Your window, your kill switch

Testing runs inside an agreed window from declared source addresses, with a named contact on both sides and one phone call that stops everything immediately.

Your data stays yours

NDA before scoping. Evidence encrypted at rest, held for the retest window and then destroyed on your instruction. Nothing about your engagement appears in a case study without written consent.

We test only what an authorized signatory has put in writing, and we ask who owns the infrastructure before we touch it - hosted platforms usually need their own authorization, and we will tell you when yours does.

❓ FAQ

The questions that decide it

What exactly does "no High or Critical, no invoice" mean?

If the engagement ends without at least one confirmed in-scope finding rated High or Critical - CVSS v3.1 base score 7.0 or above, with a reproducible proof of exploit - we do not invoice the engagement fee. Not a discount, not a credit: zero. You still receive the full report, the evidence pack, the attestation letter and the retest.

Does that not push you to inflate severity?

Every rating in the report carries its CVSS v3.1 vector and the request/response that proves it, so you can check the arithmetic yourself. You can dispute any rating. If we cannot agree on one that decides the invoice, the guarantee resolves in your favour and the engagement is not billed. We would rather lose a fee than hand you a report an auditor can pull apart.

How is this different from your Agentic Pentest product?

Agentic Pentest is software: an adaptive agentic loop inside the platform that probes, reads each response and adjudicates the result deterministically. It runs continuously and it is priced per target. Manual Pentest is people - senior testers working your application by hand for a fixed engagement. We run the agentic pass first, so the human days go on business logic and chained abuse rather than on what a machine already covered.

Can we buy a manual pentest without the platform?

Yes. It is a standalone engagement with no subscription, no licence and no platform commitment. The report and all evidence are yours to keep whether or not you go further with apPosture.

How long does it take?

A scoping call within two business days, a fixed quote after it, and testing usually starts inside two weeks. A focused engagement runs five testing days and a standard one ten; the draft report follows within three business days of testing ending, and the walkthrough call within a week.

Do you test production or staging?

Staging, when it mirrors production. If it has to be production we agree a testing window, request-rate limits and an exclusion list in the rules of engagement first. No denial-of-service, no destructive verbs, no exfiltration of real customer data - proof is captured with benign markers and masked in the report.

What do you need from us?

In-scope hosts and applications, a test account for every role and tenant we should cross, an allowlist for our source addresses if a WAF sits in the path, a technical contact who can answer questions during the window, and signed authorization from someone entitled to give it.

Will the report pass a SOC 2, ISO 27001 or PCI DSS audit?

That is what the auditor pack is written for: declared scope, methodology, dates, tester names, every finding with its CVSS vector and evidence, remediation status after the retest, and a signed attestation letter on letterhead. Auditors ask for the same seven things every time; they are all in there.

Is the retest included?

Yes. One full retest of every reported finding, any time within 90 days of the report, at no extra cost. The retest updates the report and the attestation letter so you can hand an auditor the fixed state rather than the broken one.

Who actually does the testing?

Named senior testers from our own team, listed in the report. No undisclosed subcontracting, and no junior running a scanner under a senior's name.

What if you find nothing at all?

You pay nothing, and you still get a report that documents exactly what was tested, how, and what held. That document is itself the evidence an auditor asks for. We will also say plainly where the scope was too narrow to conclude much - a clean report on two endpoints is not a clean report on your product.

apPosture

Book a scoping call - and only pay if we find something

One call to agree the scope, a fixed quote after it, and no invoice unless the engagement closes with a High or Critical finding.