Penetration testing,
scoped to you.

You tell us what is in scope over email. Human testers then work through it by hand, and you get a report your engineers can act on. Every fix is retested free. Pricing is custom per scope. The same people who build our open-source tooling do the work.

What every engagement includes

Methodology stays the same regardless of scope. Only depth and cadence change.

manual testing
Hands-on testing by a human tester across the OWASP Top 10, authentication, access control, and business logic.
free retests
Fix a finding and we re-verify it at no extra cost. You only close a ticket once we confirm the issue is actually gone.
developer-ready reports
Every finding ships with reproduction steps, impact, and a concrete fix, written for the engineers who remediate it.
a direct line
Talk to the tester who found the bug. There is no ticket queue and no account manager in between.
One-off assessment

A fixed scope, attacked once, reported end to end.

  • Scope set with you over email
  • Manual OWASP Top 10 + business-logic testing
  • Free retest of every fix
  • One developer-ready report
  • Typical start: within one week
Get a quote →
Red team

A scheduled, goal-driven exercise against everything you run.

  • Goal-driven adversary simulation
  • Internal + external surface
  • Social and physical vectors on request
  • Full narrative report + debrief
  • Custom-branded reporting
Get a quote →

Every engagement is priced per scope. Email us what you want tested and you get a written quote within two business days. NDA, one-off, and unusual scopes are all standard.

How scoping works

Three steps, all over email. No sales call required.

01 - describe
Email us the apps, domains, or APIs you want tested, whether you need authenticated testing, and your timeline. Two sentences is enough.
02 - quote
We reply within two business days with a written scope and price. If something is ambiguous we ask one round of questions, by email, not a discovery call.
03 - kickoff
You confirm, we start. Typical kickoff is within one week of scope sign-off. Findings reach you as they are verified, not in a batch at the end.

Frequently asked

How much does a penetration test cost?

Pricing is custom per engagement and depends on scope: number of apps or domains, authenticated vs unauthenticated testing, API and cloud surface, and cadence. Email contact@santh.dev with your scope and you get a written quote within two business days.

Who does the testing?

The same people who build Santh's open-source security tooling. A human tester works through your applications manually across the OWASP Top 10, authentication, access control, and business logic.

Do you retest fixes?

Yes. Every finding includes a free retest. A ticket is only closed once we re-verify the issue is actually gone.

Can you test under NDA or on a one-off basis?

Yes. One-off assessments, custom scopes, and testing under NDA are all standard. Describe your situation in the first email and we scope around it.

What do we get at the end?

A developer-ready report: every finding ships with reproduction steps, impact, and a concrete fix written for the engineers who remediate it. You also get a direct line to the tester who found the bug.

How fast can an engagement start?

Quotes go out within two business days of your email. Kickoff is typically within one week of scope sign-off, depending on current queue.