SERVICEEXPERT PENTEST

Know what’s reallyexploitable.

Trident’s security experts, accelerated by our agents, take your web apps, APIs, source code and cloud apart once, then walk you through what an attacker could actually do. Scoped on a call, about two weeks of testing, and one retest within 30 days.

  • Know what’s exploitable, and what to fix first
  • Ready to show your customer
  • Ready for your auditor tooSOC 2 · ISO 27001 · HIPAA · PCI DSS

Validated Critical findings reach you within four hours, during testing.

01WHO IT’S FOR

One expert check,read three ways.

Run it before a launch, before a big customer deal, after a major change, or simply to know where you stand. The report is written for everyone who reads it.

ENGINEERING

Know what to fix first

Every validated finding with the steps to reproduce it and the line that caused it, ranked by what an attacker reaches first, then walked through with your team in a 60-minute readout.

What they get

  • Findings with evidence
  • Prioritised remediation plan
  • 60-minute readout
CUSTOMERS

Ready to show your customer

Enterprise buyers ask for your latest pentest during a security review. Send the attestation with the questionnaire, and the executive summary when they want more.

What they get

  • Testing attestation
  • Executive summary
AUDITORS

Ready for your auditor, too

When a framework asks for a recent penetration test, the same report covers it: scope, methodology, testing dates, every finding with evidence, and a written retest status.

  • SOC 2
  • ISO 27001
  • HIPAA
  • PCI DSS

What they get

  • Full report
  • Retest status

The attestation confirms the assessment occurred; it is not a certification.

02HOW IT RUNS

Scoped on a call.Reported in writing.

Every engagement runs on a Statement of Work and a Penetration Testing Services Agreement. Together they set the scope, the rules of engagement and the authorisation to test.

Schedule
Before
Week 1
Week 2
Week 3
Up to 30 days after the report
Scoping call
SOW and services agreement signed
Access readiness review
Accounts, contact and scope confirmed
Kickoff
Testing begins
Primary testing window
About two weeks
Validated Critical findings reach you within four hours
Final report and readout
60-minute live session
Remediation retest
One retest, status per finding
  1. 01

    Access readiness

    Signed documents, the scope inventory, an engineering contact and test accounts, confirmed before testing starts.

  2. 02

    Kickoff

    Targets, exclusions, monitoring and how we reach you are agreed. Testing begins.

  3. 03

    Testing

    About two weeks across web and API, source, cloud and attack paths between them.

  4. 04

    Report and readout

    The written report and remediation plan, walked through in a 60-minute live session.

  5. 05

    Retest

    One retest within 30 days of the report, with a written status for every finding.

03THE REPORT

A report you can act on,and share.

Findings your engineers can reproduce, a summary for leadership, and an attestation for the customer who asks. Acme is fictional; the pages are what your report holds.

  1. 01CoverLeadership, customers
  2. 02Executive summaryLeadership, customers
  3. 03Scope and methodologySecurity leads
  4. 04Finding ACME-01Engineering
  5. 05Finding ACME-02Engineering
  6. 06Remediation planEngineering
  7. 07Testing attestationAuditors, partners
  8. 08Retest statusEveryone
04WHAT YOU RECEIVE

What you holdat the end.

The first five are written into the Statement of Work before testing starts. The dashboard keeps all of them in one place.

  • Penetration testing report

    Executive summary, scope and methodology, risk themes, a finding per validated issue with reproducible evidence, and a prioritised remediation plan.

  • Testing attestation

    A partner-shareable letter that confirms the authorised scope, the testing dates and the completion status.

    It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.

  • Retest status update

    One retest within 30 days of the report. Each finding is marked remediated, partially remediated, not remediated or not retested.

  • 60-minute readout

    A live walkthrough of the report and a remediation-prioritisation session with your engineers.

  • Critical findings within four hours

    Validated Critical findings reach you during testing, within four hours. They don’t wait for the report.

  • Engagement dashboard

    Timeline, scope, documents and what we still need from you, in one place in Trident.

05WHAT WE TEST

Four layers,tested as one system.

  • Web apps and APIs

    Black-box, authenticated with the test accounts you supply: routes, inputs, roles and the business logic between them.

  • Source code

    White-box review over read-only GitHub access. Findings point to the file and the line.

  • Cloud configuration

    A read-only role on AWS, Azure, GCP or Kubernetes: exposure across assets, containers, identities and secrets.

  • Attack paths across layers

    A weakness in one layer joined to another, then validated end to end.

06METHODOLOGY

The methodologywe follow.

Coverage follows published testing standards, and the report names each one. It is also the first thing an auditor asks.

  • NIST SP 800-115Technical guide to security testing and assessment
  • OWASP WSTG v4.2Web Security Testing Guide
  • OWASP ASVS v5.0.0Application Security Verification Standard
  • OWASP API Security Top 10 (2023)The most critical API security risks
  • CIS cloud benchmarksConfiguration baselines for AWS, Azure, GCP and Kubernetes

These references guide coverage. They are not a certification.

07YOUR ENGAGEMENT

Every date and document,in one place.

The engagement lives in your Trident dashboard: the timeline, the scope with its exclusions, the paperwork, the report, and what we still need from you.

AAcme
Engagement
Overview
Repositories
Cloud
Documents
Settings
Acme
Testing
Cloud, source-code and web-application penetration test ·
ACME-2026-01
Questions
contact@tridentsecurity.io
Testing window
12 – 23 Jan 2026
Report due
30 Jan 2026
in 13 days
YOUR PENTEST
Timeline
Dates in UTC
Access readiness review
9 Jan
Kickoff, testing begins
12 Jan
Primary testing window
12 – 23 Jan
In progress
Validated Critical findings are reported within four hours.
Final report and readout
30 Jan
Up next
Remediation retest
Within 30 days of the report
Get set up
Ready
Confirm the production domains and subdomains in scope
Confirmed
Grant read-only GitHub access to the three repositories
Confirmed
Grant read-only AWS access and supply the account inventory
Confirmed
Provide at least two test accounts at distinct privilege levels (over Slack, never in this dashboard)
Designate an engineering contact who can answer questions and pause testing
Tell us about blackout periods, fragile services and IP allowlists
08AFTER THE REPORT

Start with a pentest.Keep it continuous.

A report is a snapshot of one moment. When you want every release covered, the same platform keeps testing after the retest.

Acme · 2026
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
One-time pentest
January
Test
Report
Retest
Keep it continuous
Every pull request
Reviewed as it opens
Pentests
On your schedule
Cloud
Read-only, always mapped

One-time pentest

When you want to know where you stand.

  • Scoped on a call with the team that builds Trident
  • About two weeks of testing across web, source and cloud
  • Report, testing attestation and a 60-minute readout
  • One retest within 30 days of the report

Continuous

For every release after it.

  • Pentests on your schedule, every finding with its proof
  • Every pull request reviewed, with the fix to commit
  • Your cloud mapped read-only across AWS, Azure, GCP and Kubernetes
  • Retest in one click after a fix

[09]FAQ+

Questions,before the call.

Still have a question?BOOK A CALL

Your production web apps and APIs (black-box, authenticated with test accounts you supply), source repositories over read-only GitHub access, your cloud configuration through a read-only role, and the attack paths that join them.

A report with reproducible evidence for every validated finding and a prioritised remediation plan, a 60-minute readout with your engineers, a testing attestation you can share, and one retest within 30 days.

About two weeks of testing from kickoff. The final report and the readout follow about a week later, and the retest happens within 30 days of the report.

Trident’s security experts lead the engagement and Trident’s agents do the heavy lifting. Every finding is reproduced from a clean session before it is reported, and the same team walks you through the report.

The signed Statement of Work and services agreement, the domains, repositories and cloud accounts in scope, read-only GitHub and cloud access, at least two test accounts at different privilege levels, an engineering contact who can pause testing, and any blackout windows.

It sets out scope, methodology, dates and every validated finding with evidence, so it covers a framework’s penetration-testing ask. Whether it meets a specific control is your auditor’s call; the attestation is not a certification.

Validated Critical findings reach you within four hours during testing, so you can start fixing before the report arrives.

Each engagement is scoped on a call and quoted for your apps, repositories and cloud. There are no public prices.

[10]GET STARTED+

Get an expertsecurity check.

Know what is actually exploitable, fixed in order. Scoped on a call, with a report you can share.

  • SOC 2 audited by Sensiba LLP
  • Read-only cloud access