Why buy this
Why buy this
Including the part where we tell you not to.
You could run these tools yourself
The scanners underneath are open source and free. You will have thought of this already, so let us take it seriously. Here is what you would also have to build and keep running:
- Somewhere to run them on a schedule, with credentials and evidence stored safely.
- Deduplication across runs, so the same finding is one item with a history rather than forty rows every week.
- Triage, so a thousand informational results become the six things worth doing.
- Change detection — a new subdomain, a new open port, a changed service version, an expiring certificate. This is the part nobody builds for themselves, and the part that actually finds things.
- Evidence with credentials redacted, retention that expires, and a record of what each run covered.
- The integrations, so findings arrive where the work already happens.
- The authorization discipline: verified control, re-verification, and consent before anything that attacks.
If you have an engineer who enjoys this and one application that rarely changes, running the tools yourself is a perfectly good answer. We would rather say that than pretend otherwise.
The case, in three parts
A pentest is a photograph; your attack surface is a film
The report is accurate the week it is written. The subdomain someone spins up in March is not in it. Continuous testing is a different product from an annual engagement, not a cheaper one.
The thing you cannot do manually is notice
Certificate transparency sweeps, DNS change monitoring, port and version differences, lookalike domains. This is how you find the forgotten staging box, which is where incidents actually start.
Findings only matter when they reach whoever fixes them
Tickets in the tracker you already use, alerts to the pager already carried, a gate that can block a deploy, and verification that a fix worked without waiting a week.
Compared with the alternatives
We compare approaches rather than naming competitors — a fairer comparison, and one we can stand behind.
| What is being compared | An annual pentest | Running the tools yourself | This |
|---|---|---|---|
| Cadence | Once or twice a year | Whenever someone remembers | On a schedule, continuously |
| Notices new exposure | No — accurate the week it was written | Only if you built that part | Yes, that is the point |
| Depth | Deepest — a person who thinks | As deep as your time allows | Broad and repeatable, not creative |
| Effort to run | Scoping, scheduling, a report to read | Ongoing, and it is your weekend | Set it up once |
| Best at | Business logic and creative attack chains | Cost, and total control | Noticing what changed, week after week |
Who this is not for
If one of these is you, we would rather you knew now.
- You need a human penetration test for a compliance sign-off or a customer questionnaire. That is a different service and we do not offer it.
- You need a certification or an attestation. We are not an auditor.
- You want someone to fix the findings. We find and explain; the fixing is yours.
- You have one brochure site that has not changed in three years. The free check may be all you need, and that is a fine outcome.
- You are a large enterprise with an established vulnerability-management programme. We are not built to slot into that yet.
What it costs
TBD Pricing is still being settled and we would rather publish nothing than publish a number we then change. Run the free check, and get in touch if you want the rest.