Secuur / Services / Penetration testing
05 · Human-led testing

A tester who thinks. Not a scanner with a cover page.

Automated scanning is excellent at breadth and useless at intent. It will never chain a low-severity information leak into a valid session, notice that two roles share a tenant identifier, or realise that the password-reset flow can be walked backwards. That work needs a person, and it is what a penetration test is actually for.

readiness-scan
https://
What it is

Penetration testing.

A Secuur penetration test is scoped, time-boxed and adversarial. We agree the targets, the rules of engagement and the objectives in writing, then a tester works the scope by hand — using automation for coverage, but reserving judgement for the parts that require it. The output is not a tool export with a logo on the front.

Every finding carries the request that produced it, the response that proved it, and the specific fix. Findings are ordered by what we would actually exploit first, not by a CVSS number, because a medium-severity bug that hands over an admin session matters more than three highs that need physical access to a datacentre.

What you get

Six things this actually does.

01

Web application & API

Authenticated testing across every role, with authorisation boundaries and business logic as the primary focus.

02

External network

Everything reachable from the internet: exposed services, default and reused credentials, unpatched edge software, misconfiguration.

03

Cloud configuration

AWS, Azure and GCP — IAM over-permissioning, public storage, exposed metadata services, unencrypted data at rest.

04

Attack chaining

Individually-minor issues combined into a realistic path to impact, which is how real compromises actually happen.

05

Written for two audiences

An executive summary your board can read, and a technical body your engineers can act on without a translation meeting.

06

Retest included

When you have fixed the findings we re-run each proof and issue an updated report showing what closed.

The Secuur difference

The finding no other pen-test report contains

Standard methodologies check that TLS is present, that the certificate is valid and that no deprecated protocol versions are offered. All of that can pass while every session on the endpoint remains harvestable — because none of it looks at the key-exchange group, which is the part quantum computers break.

  • Every in-scope TLS endpoint is graded A–F on its negotiated key exchange, with the OpenSSL evidence included in the report appendix.
  • Long-lived secrets found in scope are assessed against harvest exposure: a credential that stays valid for years on a harvestable channel is a finding, not a footnote.
  • The report includes the remediation path — hybrid X25519MLKEM768 at the edge — not just the observation.
How it runs

Three steps, start to evidence.

01

Scope

Targets, objectives, rules of engagement, testing window and emergency contacts agreed and signed before anything starts.

02

Test

Hands-on testing across the agreed window. Anything critical is reported to you the day we find it, not held for the report.

03

Report & retest

Full report with an engineer walkthrough, then a free retest once your fixes are in place.

Deliverables

What lands in your hands.

  • Signed scope and rules-of-engagement document
  • Executive summary and technical findings report
  • Reproduction steps and raw evidence per finding
  • Remediation-ordered priority list
  • Attestation letter suitable for customers and auditors
  • Free retest and updated report after remediation
Questions

Straight answers.

How is a penetration test different from a vulnerability scan?

A vulnerability scan is automated, broad and identifies known issues. A penetration test adds a human who chains findings together, tests business logic and authorisation, and demonstrates real impact. Scanning tells you what is exposed; a pen test tells you what an attacker would do with it.

Do you test production systems?

Only where you ask us to and with a written scope. We prefer staging for anything destructive. When production is in scope we exclude destructive operations, use dedicated accounts and throttle rates to protect availability.

Will we get something we can give to a customer or auditor?

Yes. Alongside the technical report you receive an attestation letter stating the scope, the testing window and the remediation status — the document customers and auditors normally ask for.

How long does a test take?

It depends entirely on scope. A single web application is typically a one-week engagement; a broad external network plus cloud configuration runs longer. We size it during scoping and quote a fixed window before you commit.

Related services

Often bought together.

Every engagement starts the same way

Know your grade.
Then pick your service.

The scan is free and takes 20 seconds. It also tells us enough to scope penetration testing properly instead of guessing.