SecureBlockLog in
Kickoff in 48 hours

Book a real penetration test the way you buy anything else.

Scope it in two minutes, see a fixed price on the spot, and have OSCP- and CREST-certified testers on your stack within 48 hours. Reports drop straight into SOC 2, ISO 27001, PCI DSS and HIPAA evidence requests.

Manual testing, not a scanFree retest includedResults in 10 business days
app.secureblock.com/order
2
3
4
5
Scope details
Web application
staging.acme.com
API
42 endpoints · OAuth
Cloud environment
2 AWS accounts
Your fixed price
$11,600
Testing windowAug 17 – 28
ReportSep 1
RetestIncluded
SOC 2 ready
Evidence accepted forSOC 2ISO 27001PCI DSSHIPAATester certificationsOSCPCRESTOSCE

We scoped on a Tuesday and testing started that Thursday. The report went straight into our SOC 2 evidence folder untouched — our auditor had zero follow-ups.

Dana Okonjo
CTO, Ledgerpath
SOC 2 Type II · 2026

The findings read like they were written by someone who had actually used the product.

Marcus Reid · Head of Security, Fernwood

Retest was included and turned around in three days, so we closed the audit finding in the same quarter.

Priya Nandakumar · VP Engineering, Certiv
How it works

From “we need a pentest” to scheduled in one sitting.

No RFP, no three-week sales cycle, no scoping spreadsheet.

STEP 01
Scope it yourself

Pick your asset types and answer four questions. Two minutes, no call required.

STEP 02
Get a fixed price

A transparent quote with the scope multiplier and retest shown line by line.

STEP 03
Lock in dates

Pay now or approve after a scoping call. Either way the window is reserved.

STEP 04
Testing begins

Certified testers work manually. Findings appear in-platform as they are confirmed.

STEP 05
Report and retest

Evidence-ready report in 10 business days, then a free fix-verification retest.

Coverage

Every surface you ship, tested by hand.

Pick one asset type or all six — the scope drives the price, and nothing is bundled that you don't need.

Platform

Your pentest doesn't end in a PDF.

Every engagement runs through the SecureBlock platform — findings, conversations with your testers, retests and evidence exports, all in one place.

Reports live in the platform

Findings land as they are confirmed — not as a PDF three weeks later. Export evidence the moment your auditor asks.

Talk to the testers directly

Comment on any finding and the tester who wrote it answers. No ticket queue, no account manager in between.

Manage the whole engagement

Scope, schedules, credentials, retest requests and team access — one place, with a full audit trail.

app.secureblock.com/engagements/SB-2026-4417
Findings
Live · Day 6 of 10
high
Authenticated IDOR on /api/v2/invoices
Retest requested
medium
Session fixation on password change
Fix verified
low
Missing HSTS preload on marketing subdomain
Open
Discussion — IDOR on /api/v2/invoices
MK
Marta · lead tester
Repro attached. The check is missing server-side — the tenant id in the JWT is never compared to the resource owner.
DO
Dana · your team
Fixed in #4821, deployed to staging. Can you retest?
Reply to Marta…
Methodology

Depth you can audit, not just claim.

Every engagement follows OWASP WSTG, PTES and NIST SP 800-115, executed by testers who hold OSCP, CREST CRT or OSCE.

OWASP WSTGPTESNIST SP 800-115MITRE ATT&CK
Day 0
Kickoff call

Scope confirmed, credentials exchanged, NDA in place.

Day 1–10
Active testing

Manual testing. Confirmed findings published as they land.

Day 12
Report delivered

Evidence-ready report with remediation per finding.

Within 90 days
Free retest

We verify your fixes and reissue the report.

Sample findings — Acme web applicationSB-2026-4417
criticalCVSS 9.1SB-01
Unauthenticated tenant data exposure on /export
app.acme.comDay 2
Remediation — Require an authenticated session and scope exports to the caller's tenant id.
highCVSS 8.1CVE-2024-21762
Authenticated IDOR on /api/v2/invoices
staging.acme.comDay 3
Remediation — Enforce object-level authorization server-side; reject cross-tenant identifiers.
lowCVSS 3.7SB-14
Missing HSTS preload on marketing subdomain
www.acme.comDay 6
Remediation — Add the preload directive and submit the domain.
Compliance

Which report do I need?

Pick your framework and we'll show the scope and cadence auditors expect.

Required scope
External web app + API in scope of the trust services criteria
Frequency
Annually
Retest
Expected by auditors
Type II auditors ask for evidence that findings were remediated — the free retest covers it.
Pricing

Fixed price, quoted in two minutes.

These are typical engagements. Your instant quote prices your exact scope, line by line.

Essential
$8,400

One web app or API, single role.

  • 5 testing days
  • Evidence-ready report
  • Free retest within 90 days
  • Email support
StandardMost common
$14,900

Multi-role app plus its API.

  • 10 testing days
  • Interim findings in-platform
  • Free retest within 90 days
  • Kickoff + debrief calls
Comprehensive
From $26,000

Multiple surfaces, cloud and network.

  • 15+ testing days
  • Cloud and infra included
  • Two retests
  • Named lead tester
FAQ

Questions buyers actually ask.

Still unsure? Ask an engineer in chat — not a sales rep.

Standard lead time is two to three weeks from checkout; expedited engagements start within 48 hours of the kickoff call. Active testing runs 5–15 business days depending on scope, and the report lands two days after testing ends.

Know where you stand before your auditor does.