Pensure
Plan a test

How Pensure works

What you get from us

Every Pensure test runs the same way: agreed scope, real attack techniques against your live system, and a report that tells you what to fix first.

No day rates. No open-ended scoping. You know the price and the process before you start.

Who does what

You give us a target. We do the rest.

Traditional testing asks you to write a scope document, sit through kick-off calls and chase a quote. We have removed most of that.

Your part

2 minutesof your time, total.

  • The target — a URL, a domain or an IP range.
  • Confirmation that you are authorised to have it tested.
  • A contact we can reach if we find something urgent mid-test.

Only if you want authenticated areas covered

  • Test credentials for the logged-in areas. Sourcing these is the one step that may take longer than two minutes.

Our part

Everything after that.

  • Confirming the scope in writing before any traffic is sent.
  • Mapping what is actually reachable from the internet.
  • Attempting real exploitation, then chaining findings into a full attack path.
  • Verifying every material finding so you are not handed false positives.
  • Writing the report in language both your engineers and your customers can use.
  • Retesting your fixes so you have evidence the issue is closed.

The method

Seven stages, every test.

The same sequence runs whether you buy Core or Core Plus. Core is AI-powered and fully automated. Core Plus adds hands-on testing by a specialist penetration tester.

  1. Scoping

    • Written scope

    We confirm the target in writing: domains, IP ranges, authenticated areas, and anything off limits.

  2. Reconnaissance

    • AI-powered

    We map what is actually reachable - exposed services, subdomains, endpoints, technologies and versions.

  3. Exploitation

    • AI-powered
    • Safe by design

    We attempt real exploitation, safely and within the agreed window. A theory is not a finding until it is proven.

  4. Attack chaining

    • AI-powered

    Issues get joined into full attack paths - not “a misconfiguration”, but how someone reaches your customer data.

  5. Finding verification

    • Evidence-backed

    Every material finding must be supported by technical evidence before write-up, so your remediation time goes straight to what is real.

  6. Reporting

    • Both audiences

    An executive summary for the people asking for assurance, technical detail for the people doing the fixing.

  7. Remediation and retesting

    • Retest included — confirm scope

    We tell you what to fix first. Once you have fixed it, we retest to confirm the issue is closed.

Methodology

Aligned to the standards
your reviewers already know.

Our method follows recognised industry testing standards, and every finding is scored on a consistent severity scale - so a security questionnaire or an auditor can be answered straight from the report.

  • OWASP Top 10

    The categories reviewers expect to see covered.

  • OWASP ASVS depth

    Core is Level 1-informed. Core Plus is Level 2-aligned. Full Level 3 verification is tailored.

  • CVSS severity scoring

    Comparable across tests and across vendors.

  • Australian delivery team

    Testing and reporting are managed in Australia.

The deliverable

What lands in your inbox.

One report, written for two audiences: the people who have to fix the findings, and the people who have to be satisfied they were addressed.

  1. Executive summary

    The page you forward to a customer, an insurer or a board.

  2. Prioritised findings

    Ranked by what an attacker could actually reach, not by scanner score.

  3. Reproduction and evidence

    Your engineers can confirm each finding themselves rather than take our word for it.

  4. Remediation and retest

    Specific to your stack, then retested to confirm the issue is closed.

This is an example layout. Severity counts and finding titles are examples, not results.

Ready to see what your report would cover?

Compare what Core and Core Plus include, or talk it through with us before you commit.

Ready when you are

Now you know how it works.

Start with your URL. We confirm the scope with you before any testing begins — and the price is the price.

Start a test