[{"data":1,"prerenderedAt":160},["ShallowReactive",2],{"marketing-page-how-we-work":3},{"id":4,"content":5,"extension":152,"key":153,"meta":154,"seo":155,"stem":158,"__hash__":159},"marketingPages\u002Fpages\u002Fhow-we-work.yml",{"hero":6,"handover":13,"stages":37,"standards":76,"deliverable":97,"finalCta":147},{"eyebrow":7,"title":8,"description":9,"supporting":10,"primaryCta":11,"secondaryCta":12},"How Pensure works","What you get from us","Every Pensure test runs the same way: agreed scope, real attack techniques against your live system, and a report that tells you what to fix first.","No day rates. No open-ended scoping. You know the price and the process before you start.","Plan a test","See plans and pricing",{"eyebrow":14,"title":15,"description":16,"yourPart":17,"ourPart":27},"Who does what","You give us a target. We do the rest.","Traditional testing asks you to write a scope document, sit through kick-off calls and chase a quote. We have removed most of that.",{"label":18,"duration":19,"durationSuffix":20,"items":21,"optionalLabel":25,"optionalDescription":26},"Your part","2 minutes","of your time, total.",[22,23,24],"The target — a URL, a domain or an IP range.","Confirmation that you are authorised to have it tested.","A contact we can reach if we find something urgent mid-test.","Only if you want authenticated areas covered","Test credentials for the logged-in areas. Sourcing these is the one step that may take longer than two minutes.",{"label":28,"summary":29,"items":30},"Our part","Everything after that.",[31,32,33,34,35,36],"Confirming the scope in writing before any traffic is sent.","Mapping what is actually reachable from the internet.","Attempting real exploitation, then chaining findings into a full attack path.","Verifying every material finding so you are not handed false positives.","Writing the report in language both your engineers and your customers can use.","Retesting your fixes so you have evidence the issue is closed.",{"eyebrow":38,"title":39,"description":40,"items":41},"The method","Seven stages, every test.","The same sequence runs whether you buy Core or Core Plus. Core is AI-powered and fully automated. Core Plus adds hands-on testing by a specialist penetration tester.",[42,47,52,57,61,66,71],{"title":43,"tags":44,"description":46},"Scoping",[45],"Written scope","We confirm the target in writing: domains, IP ranges, authenticated areas, and anything off limits.",{"title":48,"tags":49,"description":51},"Reconnaissance",[50],"AI-powered","We map what is actually reachable - exposed services, subdomains, endpoints, technologies and versions.",{"title":53,"tags":54,"description":56},"Exploitation",[50,55],"Safe by design","We attempt real exploitation, safely and within the agreed window. A theory is not a finding until it is proven.",{"title":58,"tags":59,"description":60},"Attack chaining",[50],"Issues get joined into full attack paths - not “a misconfiguration”, but how someone reaches your customer data.",{"title":62,"tags":63,"description":65},"Finding verification",[64],"Evidence-backed","Every material finding must be supported by technical evidence before write-up, so your remediation time goes straight to what is real.",{"title":67,"tags":68,"description":70},"Reporting",[69],"Both audiences","An executive summary for the people asking for assurance, technical detail for the people doing the fixing.",{"title":72,"tags":73,"description":75},"Remediation and retesting",[74],"Retest included — confirm scope","We tell you what to fix first. Once you have fixed it, we retest to confirm the issue is closed.",{"eyebrow":77,"title":78,"description":79,"items":80},"Methodology","Aligned to the standards\nyour reviewers already know.","Our method follows recognised industry testing standards, and every finding is scored on a consistent severity scale - so a security questionnaire or an auditor can be answered straight from the report.",[81,85,89,93],{"icon":82,"title":83,"description":84},"i-lucide-shield-check","OWASP Top 10","The categories reviewers expect to see covered.",{"icon":86,"title":87,"description":88},"i-lucide-list-checks","OWASP ASVS depth","Core is Level 1-informed. Core Plus is Level 2-aligned. Full Level 3 verification is tailored.",{"icon":90,"title":91,"description":92},"i-lucide-gauge","CVSS severity scoring","Comparable across tests and across vendors.",{"icon":94,"title":95,"description":96},"i-lucide-map-pin","Australian delivery team","Testing and reporting are managed in Australia.",{"eyebrow":98,"title":99,"description":100,"callouts":101,"report":114,"disclaimer":142,"banner":143},"The deliverable","What lands in your inbox.","One report, written for two audiences: the people who have to fix the findings, and the people who have to be satisfied they were addressed.",[102,105,108,111],{"title":103,"description":104},"Executive summary","The page you forward to a customer, an insurer or a board.",{"title":106,"description":107},"Prioritised findings","Ranked by what an attacker could actually reach, not by scanner score.",{"title":109,"description":110},"Reproduction and evidence","Your engineers can confirm each finding themselves rather than take our word for it.",{"title":112,"description":113},"Remediation and retest","Specific to your stack, then retested to confirm the issue is closed.",{"title":115,"meta":116,"summaryLabel":103,"severities":117,"findingsLabel":134,"findings":135},"Penetration Test Report","Core Plus · Prepared for [Client] · [Date]",[118,122,126,130],{"level":119,"count":120,"label":121},"critical",1,"Critical",{"level":123,"count":124,"label":125},"high",3,"High",{"level":127,"count":128,"label":129},"medium",5,"Medium",{"level":131,"count":132,"label":133},"low",8,"Low","Findings, in fix order",[136,138,140],{"level":119,"label":121,"title":137},"Cross-tenant data access via unvalidated object reference",{"level":123,"label":125,"title":139},"Session token not rotated on privilege change",{"level":127,"label":129,"title":141},"Verbose error responses disclose stack details","This is an example layout. Severity counts and finding titles are examples, not results.",{"title":144,"description":145,"plansCta":12,"contactCta":146},"Ready to see what your report would cover?","Compare what Core and Core Plus include, or talk it through with us before you commit.","Contact us",{"eyebrow":148,"title":149,"description":150,"cta":151},"Ready when you are","Now you know how it works.","Start with your URL. We confirm the scope with you before any testing begins — and the price is the price.","Start a test","yml","how-we-work",{},{"title":156,"ogTitle":156,"description":157,"ogDescription":157},"How we work | Pensure","How Pensure runs a penetration test in {market}: scoping, reconnaissance, exploitation, attack chaining, validation, reporting and retesting.","pages\u002Fhow-we-work","kcEHlERgmAMo1OCwTi_RCU6iogVL9Zeou6lqQ1bbyC8",1788789306326]