Documentation

Premium Assessments

How to run a live $297 Penetration Test or $497 Comprehensive Pentest: pay, consent, verify, optionally schedule, then receive HTML and PDF.

Who This Topic Is For

Teams ordering verified automated evidence-backed penetration testing.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You own the target or are authorized to test it.
  • You can complete hosted-file or DNS hostname verification.
  • If authenticated testing is needed, save a healthy scanner login profile first.
  • For Comprehensive Pentest extra hosts, you can prove control of each selected sibling hostname.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

This is not Watch and not a credit scan

A pentest is a paid engagement after consent and hostname verification. Website Watch keeps running on its own cadence and does not replace the pentest report.

Reports have no score circle

Use do-this-week lists and color-coded severity. Team and Enterprise can brand the HTML and PDF through White-Label Reports, then copy a 14-day client link from the pentest workspace.

Refund window ends when engines start

Full refund remains available until engines start. After that, request stop instead of a refund. Use included retests to prove closure.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Choose the live pentest level and pay.

    Order Penetration Test at $297 or Comprehensive Pentest at $497 from premium assessments. Both are self-serve automated evidence-backed testing, not a human consultant engagement and not a PCI DSS, SOC 2, or ISO 27001 certificate.

  2. Confirm authorization consent.

    Testing does not start until you confirm you are authorized to assess the target. Full refund remains available until engines start.

    After engines start, use request stop instead of a refund.

  3. Verify the primary hostname.

    Complete hosted-file or DNS verification so Vulnify can prove control of the primary hostname before any active testing.

  4. Attach login profiles when you need authenticated checks.

    A saved healthy scanner login profile enables account takeover, object-level authorization, privilege escalation, and logout session checks.

    If you skip a login profile, those families are not tested. Comprehensive Pentest can use a second profile for the two-role matrix; it is recommended and not required.

    Without it, role B columns stay Not tested.

  5. On Comprehensive Pentest, verify extra hosts or continue primary-only.

    After primary verify, the workspace lists discovered sibling hosts.

    Toggle up to five extra hosts, start verify, then complete DNS or the hosted file. Or skip remaining hosts and continue with the primary hostname only.

    Plan confirmation stays blocked until verified selections or that explicit continue. Extra hosts stay out of scope until you prove control.

  6. Optionally add an API spec or repository zip (Comprehensive).

    Paste an OpenAPI or Swagger spec so API and BOLA checks hit documented operations. Upload a repository zip (max 20 MB) if you want secret scanning on that archive.

    Both are optional.

  7. Confirm the engagement plan, then start now or schedule.

    Review the automated check plan before the worker starts.

    You can start immediately or set a start window with timezone and blackout periods. Active engines do not run until the confirmed start.

    Reports are usually ready 30 to 60 minutes after testing starts.

  8. Review HTML, PDF, and included retests.

    Pentest reports have no 0-100 score circle and no PCI, SOC 2, or ISO badges.

    Use the do-this-week list, numbered remediation, and color-coded severity (Critical red, High orange, Medium amber, Low blue, Info gray). Copy ticket text, export CSV or Markdown, and use the included retest entitlement (one on $297, two on $497).

    Comprehensive also includes an attack-surface appendix, authorization matrix, a detailed, actionable PDF for security specialists and developers, and an auditor-ready evidence pack that is not a certificate. Sample reports: /penetration-test/sample-report and /penetration-test/sample-comprehensive-report.

    Team and Enterprise agencies copy a client link from the pentest workspace after White-Label Reports is saved.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

$297 after Watch found drift

Watch emailed a new exposed path. The team triaged, then ordered a $297 Penetration Test for verified automated evidence. Watch kept the daily pulse during the engagement.

Watch stayed the change detector. The pentest produced HTML, PDF, and one included retest.

Branded pentest send on Team

Harbor Labs saves a PNG logo, hides Vulnify, completes the pentest, then Copy client link with Prepared for set to the retailer.

The client opens a 14-day branded /r/ view. They do not log in to the pentest workspace.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • The ordered tier is either $297 Penetration Test or $497 Comprehensive Pentest.
  • Authorization consent is recorded before testing.
  • Primary hostname verification is complete before testing.
  • Authenticated families are only expected when a healthy login profile was attached.
  • Comprehensive extra-host gate is complete (verified selections or continue primary-only) before plan confirmation.
  • Deliverable is HTML and PDF with finding-level remediation plus the included retest count for that tier.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Expecting a human tester or a compliance certificate

Both live pentest levels are automated evidence-backed testing. There is no analyst-led review and no PCI DSS, SOC 2, or ISO 27001 certification stamp.

Common failure mode

Plan confirmation stays blocked on Comprehensive

Verify the selected extra hosts, or choose continue with the primary hostname only, before confirming the engagement plan.

Common failure mode

Authorization findings did not appear

Attach a healthy login profile before the plan is confirmed. Without it, account takeover, object-level authorization, privilege escalation, and logout session handling are not tested.

Common failure mode

Looking for a pentest score circle

Pentest reports do not use a 0-100 score. Prioritize using severity-colored findings and the do-this-week list. Dashboard credit scans still use a score.

Common failure mode
FAQ

Premium Assessments FAQs

Common questions for this topic.

No. Recurring credit scans stay on the dashboard. A Penetration Test or Comprehensive Pentest is a one-time verified automated engagement after pay, consent, hostname verification, and plan confirmation.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.