Penetration test
Independent security testing
What it is
A penetration test is an authorised attack on your product by an outside security firm, looking for weaknesses before someone else finds them. The firm tests your application, APIs and infrastructure, then delivers a report of findings ranked by severity. Enterprise buyers usually ask for a summary letter or report from a test in the last twelve months.
It is independent evidence that your security holds up, and a standard item in both security questionnaires and SOC 2 audits.
What it takes
About 2–4 engineer-weeks to build in-house.
Book two to six weeks ahead. The test itself takes one to three weeks, and fixing findings takes as long as it takes.
Answer these first
- Security: What's in scope: web app, APIs, infrastructure, mobile?
- Engineering: Who is free to fix findings in the weeks afterwards?
- Security: Do we test production, or a staging copy?
- Legal: What do we share with customers: the full report, a summary or a letter?
- Sales: Which deals need the report, and by when?
- Finance: Once a year, or continuous testing and a bug bounty?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.