Skip to content
Red Vault
Layered clear panels and a red signal block beside a brushed-metal disc

Assess

Penetration Testing.

A scan says maybe. A test proves it.

See where your systems are exposed.

A penetration test shows how a weakness could become a business problem. Focus the work on the systems, data and decisions that matter to your organisation.

Conceptual architectural model: a carmine path threads through ivory walls and glass partitions to a metal core.
  • Before a product goes live

    Check whether sign-in, permissions and business workflows protect your users and their data before a release.

  • When a customer asks for assurance

    Give procurement and security reviewers evidence of what was tested, what was found and how you responded.

  • After your infrastructure changes

    Understand whether new services, remote access or network changes have opened a route into sensitive systems.

The scope follows your business risk. We agree the systems, test depth and deliverables before you commit.

Choose the right test for your environment.

Start with an application or network. We define the assets, access and boundaries with you, so the proposal makes clear what is covered.

Web applications & APIs

Can someone access another user’s data or exceed their permissions?

What we check
  • Authentication & access control
  • API endpoints & business logic
  • Separation between customer accounts
What we need
App URLs, API documentation and test accounts for the agreed roles.

External networks

Which exposed systems could give an attacker a way into your organisation?

What we check
  • Internet-facing hosts & services
  • Remote access
  • Exploitable configuration weaknesses
What we need
Domains, public IPs and permission to test any third-party systems.

Internal networks

How far could an attacker move from a compromised account or device?

What we check
  • Active Directory & permissions
  • Network separation
  • Paths to sensitive systems
What we need
An internal connection or testing location, plus the agreed starting accounts.

Manual validation, with business context.

Automated tools help identify potential weaknesses. Manual testing checks whether they are exploitable, connects related findings and examines the workflows a scanner cannot understand.

Web and API testing draws on the relevant parts of OWASP WSTG and OWASP API Security guidance.

Agreed boundaries

Mobile applications and cloud configuration reviews are scoped separately. Social engineering, denial-of-service testing and goal-based adversary simulation are outside this service.

Know what to fix first.

Evidence for your engineers. Context for your decision-makers. A practical route from a finding to a verified fix.

Conceptual detail of a red thread revealing a continuous route through stacked glass layers.
Business summary
The main attack paths, their business impact and the decisions that need attention. Written for leadership and security reviewers.
Technical findings
Affected assets, severity with rationale, supporting evidence and reproduction steps. Enough detail for engineers to understand and address each finding.
Prioritised remediation
Recommended fixes in risk order, with related weaknesses connected so your team can plan the work sensibly.
Re-test record
The outcome of checking the agreed fixes: resolved, partly resolved or still open, with supporting evidence and any remaining limitations.

How your penetration test works.

From agreeing the scope to checking the fixes, you know what happens next and what your team receives.

Before testing begins, we agree written authorisation, permitted techniques, testing windows, stop conditions, an escalation contact and how evidence will be handled.

Need a wider view? Explore our security assessment.

Before you book.

How much does a penetration test cost?

We quote for your scope: the applications, user roles, integrations and network assets to be tested. Send a short outline and any deadline. We agree the price and deliverables before work starts.

How long does it take?

It depends on scope and access. Your proposal sets the testing dates, report date and re-test window. Tell us about any launch or customer deadline so we can check availability.

Can you test a live system?

Where the scope and operating conditions allow it. We agree permitted techniques, testing windows, stop conditions and an escalation contact first, and discuss the risk of disruption before authorisation.

Can you test with or without user accounts?

Both can be appropriate. An unauthenticated test looks at what an external attacker can reach. Authenticated testing checks permissions and workflows from agreed user roles. For internal networks, we agree the starting foothold. Your proposal explains the approach and the access needed.

How is sensitive information handled?

We agree confidentiality, evidence collection, secure transfer and retention arrangements before testing. Where practical, we use test data and collect only what is needed to demonstrate a finding. Tell us about your information-handling requirements during scoping so they can be included in the engagement.

Is a re-test included?

Yes, for the agreed findings within the window in your proposal. We verify the fixes and document the result. New functionality or a changed architecture needs a new scope.

Will this meet a customer or audit requirement?

Share the requirement before booking, including any required accreditation or report format. We check whether we can meet it. A test provides evidence for its scope; it does not certify your organisation or guarantee every weakness has been found.

Do I need a test or a Cybersecurity Assessment?

A test examines a defined application or network for exploitable weaknesses. The assessment gives a broader view of security posture and priorities. Tell us what decision you need to make if you are unsure where to start.

Let’s scope your test.

Tell us what you want tested and any deadline. We’ll help define the work and come back with a proposal.

contact@redvault.co.uk

How we handle your details: Privacy policy.