Senior testers work your application by hand for the whole engagement - business logic, authorization boundaries, chained abuse, the flaws no scanner has an opinion about. You get the full report either way. If it closes with no High or Critical finding, we do not invoice the engagement.
Fixed quote before testing · no subscription · one free retest within 90 days · report and evidence yours to keep
Had that last row read 0 findings ≥ High, it would read not invoiced.
Our own engine proves injection, exposure and misconfiguration faster and more consistently than any human can, on every release. What it cannot do is decide that a refund should never exceed the original payment, or that a support agent is not supposed to see another tenant's invoices. Those are the findings that end up on the front of the report.
Multi-step flows completed out of order, prices and quotas manipulated between steps, approvals skipped, state machines walked backwards. Nothing is technically malformed - the application does exactly what it was told to do.
A low-severity information leak, a weak reset link and one over-permissive role are three medium findings on their own. Chained, they are account takeover - and only a person patient enough to try the chain writes it up that way.
We provision a real account for each role, then systematically attempt every action from every one of them, across tenants. Broken object-level authorization is still the most common serious finding we report, and it is invisible to a single-account scan.
A CVSS vector plus the captured proof, argued in front of your engineers on the walkthrough call. No inflated criticals to justify the invoice, and no quietly downgraded findings to make the report look clean.
Most pentests bill for effort. This one bills for outcome. If ten testing days on your application produce nothing rated High or Critical, you owe us nothing - and you keep the report, the evidence, the attestation letter and the retest anyway. We can offer that because the agentic baseline tells us before we quote whether the scope is worth a human week.
How a finding qualifies: in the agreed scope, confirmed with a reproduction we hand you, and rated CVSS v3.1 base score ≥ 7.0 with the vector printed in the report. One qualifying finding makes the engagement billable at the quoted fee - there is no per-finding pricing, and finding twenty does not cost more than finding one. If you dispute the rating on the finding that decides the invoice and we cannot reach agreement, the engagement is not invoiced.
Scoping to signed attestation, typically three to four weeks end to end.
One call to agree the targets, the roles, the window and what is off-limits. You get a fixed quote and a signed authorization document before anything is touched - no time-and-materials surprise.
The platform's crawl, active scan and Agentic Pentest run over the scope before a human starts. The machine clears the ground it is good at, so the tester's days are not spent re-finding a reflected XSS.
Hosts, subdomains, endpoints, parameters, roles, tenants and third-party integrations, mapped by hand against what the crawl found. What the automation missed is usually where the interesting bug lives.
The engagement itself: authorization matrices across every role and tenant, business-logic and workflow abuse, chained escalation, and exploitation of anything the baseline only suspected. Everything captured as request, response and reproduction steps.
A draft within three business days, then a live walkthrough with your engineers - not a PDF over the wall. Every finding leads with impact and the exact steps to reproduce it.
Fix, then tell us. We re-test every reported finding, mark what is closed, and reissue the report and attestation letter against the fixed state.
They are not competitors and you should not choose. The engine covers every release; the engagement covers what reasoning cannot be automated - and each makes the other cheaper.
| Agentic Pentest (product) | Manual Pentest (service) | |
|---|---|---|
| Who does the testing | The agentic loop, continuously | Senior testers, by hand, for a fixed engagement |
| Best at | Injection, exposure, misconfiguration, regression after every deploy | Business logic, authorization matrices, chained escalation, abuse of intended features |
| Cadence | Every release, unattended | Point in time, then a retest |
| Evidence | Deterministic verdict - marker, timing or canary | Captured request/response plus a written reproduction a developer can follow |
| Deliverable | Findings in the platform, exportable | Four reports plus a signed attestation letter |
| Priced by | Target URL, per year | Engagement - and only if it finds a High or Critical |
Every manual engagement includes an Agentic Pentest pass over the same scope, run before the humans start. It is not an upsell - it is how we keep the human days on the findings that justify them.
Scope is agreed in writing before anything is touched. Anything not listed here, ask - we will say honestly whether we are the right team for it.
Authenticated multi-role testing of the whole application, not the login page - SPA, server-rendered or hybrid.
REST, GraphQL and gRPC: object-level and function-level authorization, mass assignment, tenancy boundaries, rate and quota abuse.
Pricing, discounts, refunds, quotas, approval chains, multi-step workflows - the rules a scanner has no opinion about.
SSO and OAuth/OIDC flows, MFA bypasses, password reset and invite chains, session fixation and token handling.
Exposed services, IAM and role escalation paths, metadata access, cluster and workload configuration reachable from the app.
On request: internal network, Active Directory and workstation-to-domain paths, with an on-site or VPN-based tester.
Android and iOS clients together with the backend they talk to - storage, transport, certificate handling and API abuse.
Prompt injection, tool and function-call abuse, data leakage across tenants, and the authorization boundary behind the model.
The same engagement, written four ways - so the board, the engineer, your customer and your auditor each get the document they actually need.
Every finding with impact, CVSS v3.1 vector, the request and response that proves it, reproduction steps and a concrete fix - written for the engineer who has to close it.
Two pages for people who will not read the other forty: what was tested, what the real business exposure is, and what to do first.
The same conclusions with your stack, hostnames and internal details removed - the version you send to a prospect's security questionnaire.
Scope, methodology, dates, tester names, findings and post-retest remediation status, plus a signed attestation letter for SOC 2, ISO 27001 and PCI DSS.
Quoted after the scoping call, fixed before testing starts, and only invoiced if the engagement produces a High or Critical finding. Prices are per engagement and exclude VAT.
Per engagement. One web application or one API, 5 testing days.
Per engagement. Application and its API, all roles and tenants, 10 testing days.
Multi-service platforms, mobile, internal network and Active Directory, or a recurring schedule.
A retest, a re-run of a scope already tested, and pre-agreed pass-through costs such as travel are billed normally - the guarantee covers the first engagement on a given scope, which is the one where you are taking the risk on us. Manual Pentest is sold standalone; it needs no apPosture licence. Platform customers can have the findings imported into their existing posture at no extra cost.
No denial-of-service, no load testing, no destructive verbs against live data, no exfiltration of real customer records. Proof is captured with benign markers and masked before it reaches the report.
Testing runs inside an agreed window from declared source addresses, with a named contact on both sides and one phone call that stops everything immediately.
NDA before scoping. Evidence encrypted at rest, held for the retest window and then destroyed on your instruction. Nothing about your engagement appears in a case study without written consent.
We test only what an authorized signatory has put in writing, and we ask who owns the infrastructure before we touch it - hosted platforms usually need their own authorization, and we will tell you when yours does.
If the engagement ends without at least one confirmed in-scope finding rated High or Critical - CVSS v3.1 base score 7.0 or above, with a reproducible proof of exploit - we do not invoice the engagement fee. Not a discount, not a credit: zero. You still receive the full report, the evidence pack, the attestation letter and the retest.
Every rating in the report carries its CVSS v3.1 vector and the request/response that proves it, so you can check the arithmetic yourself. You can dispute any rating. If we cannot agree on one that decides the invoice, the guarantee resolves in your favour and the engagement is not billed. We would rather lose a fee than hand you a report an auditor can pull apart.
Agentic Pentest is software: an adaptive agentic loop inside the platform that probes, reads each response and adjudicates the result deterministically. It runs continuously and it is priced per target. Manual Pentest is people - senior testers working your application by hand for a fixed engagement. We run the agentic pass first, so the human days go on business logic and chained abuse rather than on what a machine already covered.
Yes. It is a standalone engagement with no subscription, no licence and no platform commitment. The report and all evidence are yours to keep whether or not you go further with apPosture.
A scoping call within two business days, a fixed quote after it, and testing usually starts inside two weeks. A focused engagement runs five testing days and a standard one ten; the draft report follows within three business days of testing ending, and the walkthrough call within a week.
Staging, when it mirrors production. If it has to be production we agree a testing window, request-rate limits and an exclusion list in the rules of engagement first. No denial-of-service, no destructive verbs, no exfiltration of real customer data - proof is captured with benign markers and masked in the report.
In-scope hosts and applications, a test account for every role and tenant we should cross, an allowlist for our source addresses if a WAF sits in the path, a technical contact who can answer questions during the window, and signed authorization from someone entitled to give it.
That is what the auditor pack is written for: declared scope, methodology, dates, tester names, every finding with its CVSS vector and evidence, remediation status after the retest, and a signed attestation letter on letterhead. Auditors ask for the same seven things every time; they are all in there.
Yes. One full retest of every reported finding, any time within 90 days of the report, at no extra cost. The retest updates the report and the attestation letter so you can hand an auditor the fixed state rather than the broken one.
Named senior testers from our own team, listed in the report. No undisclosed subcontracting, and no junior running a scanner under a senior's name.
You pay nothing, and you still get a report that documents exactly what was tested, how, and what held. That document is itself the evidence an auditor asks for. We will also say plainly where the scope was too narrow to conclude much - a clean report on two endpoints is not a clean report on your product.

One call to agree the scope, a fixed quote after it, and no invoice unless the engagement closes with a High or Critical finding.