Sample report

What a $497 Comprehensive Pentest report looks like

This is a fictional shop.example.com report. It shows extra engines, an attack-surface appendix, ticket-ready findings, and two included retests. It is not a real customer engagement and not a PCI DSS, SOC 2, or certified pentest.

How to read this sample

  • Usually 30 to 60 minutes after testing starts.
  • Full refund until testing starts. After engines start, use request stop instead of a refund.
  • Up to five extra verified hosts tested, a two-role matrix when two profiles are supplied, and an auditor-ready evidence pack (not a certificate).
  • This is an automated, evidence-backed assessment. It is not a PCI DSS, SOC 2, ISO 27001, or certified penetration test, and it is not a human consultant letter.

What this $497 report includes

  • Everything in the $297 Penetration Test
  • Extra engines: GraphQL, JWT, template injection, NoSQL, XXE, and public-repo secret scanning
  • Up to 5 extra verified hosts tested after you prove control
  • Two-role authorization matrix when two profiles are supplied
  • Attack-surface appendix in the report
  • Detailed, actionable PDF plus HTML for specialists and developers
  • Two included targeted retest cycles
  • Ticket-ready remediation
  • Auditor-ready evidence pack (not a certificate)

Prefer the catalog write-up? Read the pentest methodology.