Penetration Testing
Black-box and grey-box pen tests on web apps, APIs, and cloud infrastructure. Aligned with PTES, NIST, and OWASP methodologies. Includes a full re-test after fixes.
Or book a 30-min call to talk it through.
Overview
Adversarial testing on your live systems.
- Discipline
- Security
- Starts from
- $2,400 USD
- Senior-led
- Always
- Post-launch support
- 30 days included
What you get
Everything we ship.
Scoping + rules of engagement
Manual exploitation by senior testers
CVSS-scored findings report
Free re-test within 30 days
Ideal for
Who this is for.
Annual compliance
Pre-launch hardening
After major refactors
Investment
Three ways to start.
Choose the tier closest to your scope — we'll confirm the exact fit on a discovery call. All prices are fixed-fee in USD; we never bill by the hour for delivery work.
Basic
One pen test, one application.
Annual compliance, a one-time check before launch, or after a major refactor.
2 weeks
Includes
- Scoping call and rules of engagement document
- Black-box external testing on one web application or API
- Manual exploitation by senior testers (no scanner spam)
- CVSS-scored findings with proof-of-concept
- Executive summary plus technical detail report
- Free re-test within 30 days
Not included
- —Mobile application testing
- —Cloud configuration review
- —Social engineering or red-team exercises
Standard
RecommendedA thorough adversarial assessment.
Pre-Series A diligence, fintech compliance, or systems with significant attack surface.
3–4 weeks
Includes
- Everything in Basic
- Grey-box testing with credentialed user roles
- Mobile application testing if applicable (iOS + Android)
- Cloud / infrastructure configuration review
- API authentication and authorisation deep-dive
- Business logic abuse testing
- Two re-tests within 60 days
- Briefing call with your engineering leadership
Enterprise
Continuous adversarial pressure.
Mature SaaS, fintech, and platforms where security is regulatory.
Custom
Quarterly, retainer
Quoted after a discovery call. Typical engagements start at $25,000 per quarter.
Includes
- Everything in Standard
- Quarterly penetration tests on a rotating schedule
- Red-team exercises — including social engineering if scoped
- Bug bounty programme triage and management
- Continuous attack-surface monitoring
- Detailed compliance reports for auditors
- On-call incident response
- Annual external CISO-as-a-service review
Prices in USD; we accept GHS at today's rate. Final scope is always confirmed in writing before any contract is signed.
Considering us?
Let's build it together.
Tell us a little about your project. We'll come back with a written scope and an honest estimate within 48 hours.
Want to write it down properly? Use the detailed brief
