Who This Topic Is For
Teams ordering verified automated evidence-backed penetration testing.
How to run a live $297 Penetration Test or $497 Comprehensive Pentest: pay, consent, verify, optionally schedule, then receive HTML and PDF.
Teams ordering verified automated evidence-backed penetration testing.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
A pentest is a paid engagement after consent and hostname verification. Website Watch keeps running on its own cadence and does not replace the pentest report.
Use do-this-week lists and color-coded severity. Team and Enterprise can brand the HTML and PDF through White-Label Reports, then copy a 14-day client link from the pentest workspace.
Full refund remains available until engines start. After that, request stop instead of a refund. Use included retests to prove closure.
Follow these steps in order for a reliable and repeatable outcome.
Order Penetration Test at $297 or Comprehensive Pentest at $497 from premium assessments. Both are self-serve automated evidence-backed testing, not a human consultant engagement and not a PCI DSS, SOC 2, or ISO 27001 certificate.
Testing does not start until you confirm you are authorized to assess the target. Full refund remains available until engines start.
After engines start, use request stop instead of a refund.
Complete hosted-file or DNS verification so Vulnify can prove control of the primary hostname before any active testing.
A saved healthy scanner login profile enables account takeover, object-level authorization, privilege escalation, and logout session checks.
If you skip a login profile, those families are not tested. Comprehensive Pentest can use a second profile for the two-role matrix; it is recommended and not required.
Without it, role B columns stay Not tested.
After primary verify, the workspace lists discovered sibling hosts.
Toggle up to five extra hosts, start verify, then complete DNS or the hosted file. Or skip remaining hosts and continue with the primary hostname only.
Plan confirmation stays blocked until verified selections or that explicit continue. Extra hosts stay out of scope until you prove control.
Paste an OpenAPI or Swagger spec so API and BOLA checks hit documented operations. Upload a repository zip (max 20 MB) if you want secret scanning on that archive.
Both are optional.
Review the automated check plan before the worker starts.
You can start immediately or set a start window with timezone and blackout periods. Active engines do not run until the confirmed start.
Reports are usually ready 30 to 60 minutes after testing starts.
Pentest reports have no 0-100 score circle and no PCI, SOC 2, or ISO badges.
Use the do-this-week list, numbered remediation, and color-coded severity (Critical red, High orange, Medium amber, Low blue, Info gray). Copy ticket text, export CSV or Markdown, and use the included retest entitlement (one on $297, two on $497).
Comprehensive also includes an attack-surface appendix, authorization matrix, a detailed, actionable PDF for security specialists and developers, and an auditor-ready evidence pack that is not a certificate. Sample reports: /penetration-test/sample-report and /penetration-test/sample-comprehensive-report.
Team and Enterprise agencies copy a client link from the pentest workspace after White-Label Reports is saved.
These scenarios show how the workflow looks in practice, including the result you should see.
Watch emailed a new exposed path. The team triaged, then ordered a $297 Penetration Test for verified automated evidence. Watch kept the daily pulse during the engagement.
Harbor Labs saves a PNG logo, hides Vulnify, completes the pentest, then Copy client link with Prepared for set to the retailer.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
Both live pentest levels are automated evidence-backed testing. There is no analyst-led review and no PCI DSS, SOC 2, or ISO 27001 certification stamp.
Verify the selected extra hosts, or choose continue with the primary hostname only, before confirming the engagement plan.
Attach a healthy login profile before the plan is confirmed. Without it, account takeover, object-level authorization, privilege escalation, and logout session handling are not tested.
Pentest reports do not use a 0-100 score. Prioritize using severity-colored findings and the do-this-week list. Dashboard credit scans still use a score.
Use these links to continue your workflow without losing context.
Open Pricing to continue this workflow.
Open Pentest Methodology to continue this workflow.
Open Help: Premium And Partners to continue this workflow.
Open $297 Sample Report to continue this workflow.
Open $497 Sample Report to continue this workflow.
Open Premium Assessments Portal to continue this workflow.
Open Website Watch to continue this workflow.
Open White-Label Reports to continue this workflow.
Common questions for this topic.
Continue to the best next page based on where you are in your workflow.