Technical guide
Testing past the WAF without dropping your guard
Use the platform runbooks for Vercel, Cloudflare, Akamai and AWS WAF to create a narrow, temporary path for authorised testing.
Open the WAF runbooksResources
Practical material for Singapore small and growing businesses planning a penetration test, explaining exposure and preparing evidence for customers, tenders, insurers and audits.
Frequently asked questions
Practical answers about scope, testing safeguards, reporting and data handling.
The process starts with you providing a URL or domain name. We will confirm the target and environment, then schedule a testing window. Once testing begins, we will work through the agreed scope and provide a report with findings and recommendations. To get started, click Plan a test.
You can see more about plans and pricing here.
Yes. The launch flow starts with one public HTTPS target and can record website, API and authentication coverage decisions. Broader or more complex scope can be discussed through the same Plan a test process.
We can do a black-box test with no credentials, or a grey-box test with credentials that you provide. For a more comprehensive assessment, it is recommended to test with user credentials.
We strongly recommend testing on a non-production environment, however production can be considered where the target, authorisation, safeguards and testing window are appropriate. The target and environment are confirmed before testing begins.
Penetration testing helps identify exploitable weaknesses in the agreed target so your team can reduce exposure. It does not prevent every cyber incident, and it is one part of a broader security programme.
Technical guide
Use the platform runbooks for Vercel, Cloudflare, Akamai and AWS WAF to create a narrow, temporary path for authorised testing.
Open the WAF runbooksPlanning guide
A short guide to choosing the right application, API or digital asset for a first penetration test.
Read the scoping guideBuyer guide
Use the report output, evidence and remediation context to compare what different testing offers actually provide.
Read the report guideTrust and data
Review how Pensure approaches data handling, authorised scope and the information needed before testing begins.
Read Trust & DataFirst-time buyer guide
Turn an urgent request from a customer, insurer or procurement team into a clear and controlled plan.
Read the buyer guideBuyer guide
Understand what each approach does well, where the difference matters and when you may need both.
Compare the approachesOfficial resource · Singapore
Current government or national cyber security evidence for Singapore small and growing businesses.
Open Cyber Security Agency of SingaporeOfficial resource · Singapore
Current government or national cyber security evidence for Singapore small and growing businesses.
Open Cyber Security Agency of Singapore