Backbone Security · Self-serve pentesting

A real penetration test that runs itself.

Aegis proves you own the target, tests it like an attacker — authenticated, business-logic and all — and hands you a boardroom-grade report. No consultants, no scheduling, no six-week wait.

1/5 the price of the incumbents Touchless — ownership-verified, auto-approved Fail-closed by design

Verified controls

Attacks attempted · outcome recorded
  • supplier account /suppliers/bank-changesAuthorization-differential test, low-privilege identity Refused — redirected to portal
  • supplier account /approvalsAuthorization-differential test, low-privilege identity Refused
  • requester approve own requestSeparation-of-duties, business-logic tier Blocked
  • non-finance trigger paymentPrivilege escalation in workflow Blocked
  • tenant A session tenant B subdomainCross-tenant session replay Rejected — session re-bound
  • 31 boolean-SQLi probes every reachable parameterInert true/false logic, no destructive payloads No injection
  • 10 inert XSS canaries every reflecting inputUnique markers, no working exploit code No reflection

This is the section other reports don't have: not what broke, but what we attacked and found holding. It is the evidence a reviewer needs to accept a clean result — and it answers SOC 2 CC4.1 directly. How verified controls work →

DAST & business-logic Authenticated scanning SAST & secrets Dependencies & SCA Cloud & IaC posture Multi-tenant isolation
183Endpoints mapped
81Probes executed
0 / 0Critical / High
Same dayResult returned
$999vs $4,000 elsewhere
Touchless by design

From sign-up to signed report in four steps

Every gate is automated and fail-closed. A human never has to approve a safe scan — but nothing runs until ownership and rules of engagement are satisfied.

01

Verify ownership

Drop one DNS TXT record. Aegis confirms you control the target before anything is queued.

02

Accept the rules

Confirm scope, rate limits and emergency contact. Your acceptance is recorded, not a checkbox theatre.

03

Auto-approved & scanned

The policy engine approves and dispatches the scan to an isolated worker — no operator in the loop.

04

Download the report

Executive summary, severity chart, reproducible findings and remediation — ready to hand to an auditor.

The live Aegis customer portal sign-in screen, where you verify a domain and start an assessment
Step 1 — the live Aegis portal, where you verify a domain and start an assessment.
Cover page of an Aegis penetration test report, branded in navy and gold
Step 4 — the report you download at the end. A real one, not a mock-up.
Assessment tiers

Start safe. Go as deep as you're entitled to.

Each tier unlocks with your plan. Aggressive testing is a gated premium tier — separate written approval, a non-production target and a rollback window.

Included on every plan

Baseline

Low-rate, non-destructive checks on your public surface. Auto-runs the moment ownership and rules of engagement are satisfied.

  • Security headers & TLS posture
  • CSP / CORS analysis
  • Cookie security
  • API spec-drift detection
Included free
Growth & up

Authenticated

Aegis logs in as your roles and tests the surface real users see — where the real risk lives.

  • Authenticated crawl (multi-role)
  • Non-destructive active checks
  • Access-control differential testing
  • Injection probing (SQLi / XSS)
Most popular
Business & up · gated

Aggressive assurance

State-changing, business-logic attack simulation against a non-production target, with a rollback window and operator monitoring.

  • Reversible state-change testing
  • Privilege-escalation & IDOR
  • Multi-tenant isolation
  • Written approval + emergency stop
Talk to us
Which service do I need?

Answer two questions. We'll tell you.

No sales call. The right tier depends on what you're testing and what you're allowed to touch.

1 · What do you need to cover?

2 · What can we test against?

Pick an answer to each question

We'll recommend the tier that matches — and tell you what you need to have ready.

Before you start

Everything you need ready — known upfront

Nothing here is a surprise mid-flow. Have these in hand and a baseline runs in minutes.

01

A domain you control

You'll add one DNS TXT record to prove ownership. We never scan a target that hasn't been proven — no exceptions, no manual override.

All tiers
02

DNS access

Whoever manages your DNS (Cloudflare, Route 53, your registrar) needs to add the record. Takes a minute; propagation is usually fast.

All tiers
03

Your hosting provider informed

Most providers allow testing of your own resources, but their policy is yours to follow. See the matrix below — you'll confirm this before anything runs.

All tiers
04

A dedicated test account

For authenticated testing: a low-privilege account we can log in as. Never use a real customer or admin account. Rotate the password afterwards.

Authenticated +
05

A non-production target

State-changing tests write data. They run against staging or a disposable copy — never your live system. We enforce this in code.

Aggressive
06

A window & a contact

A testing window plus someone reachable while it runs. You keep an emergency stop that halts everything immediately.

Aggressive

Telling your hosting provider

Security testing traffic can look like an attack. Check your provider's current policy before you run — and if you're behind a WAF or rate limiter, allow-list our traffic so results aren't distorted by the edge blocking us.

ProviderTypical positionWhat you should do
DigitalOceanTesting your own Droplets is generally permitted under their AUP.Review the current AUP; keep testing to resources you own.
AWSCustomer-initiated testing of many services is permitted without prior approval; simulated DoS still requires it.Check the current customer support policy for penetration testing.
Microsoft AzurePre-approval generally not required; their Rules of Engagement apply.Read the Azure penetration testing Rules of Engagement.
Google CloudNo pre-approval generally required; the AUP applies.Confirm against the current Google Cloud AUP.
Cloudflare / any WAFYour origin is yours to test — their infrastructure is not in scope, ever.Allow-list the scan so the WAF doesn't mask real findings.
Shared hostingOften restricted, because neighbours share the machine.Get written permission first, or test a copy you control.

Policies change. This table is a starting point, not legal advice — verify your provider's current terms. Aegis never tests provider infrastructure (Cloudflare, DigitalOcean, AWS and the like); only the application at the target you have proven you own.

Pricing

Enterprise-grade coverage, startup pricing

Everything the big platforms do — at roughly a fifth of the cost. Start free; upgrade when you need depth.

Free

$0
See a real report on your site
  • 1 target
  • Unlimited baseline scans
  • Full HTML & PDF report
  • No card required
Start free

Pro

$149/mo USD
Authenticated testing unlocked
  • 3 targets
  • Baseline + Authenticated
  • Credential vault · monthly re-scans
  • API & service accounts
Choose Pro

Business

$249/mo USD
Aggressive & multi-tenant testing
  • 10 targets
  • + Aggressive assurance
  • Multi-tenant isolation testing
  • SSO · audit exports · residency
Choose Business

Go-Live Assessment

$999 one-off USD
The pentest your auditor asked for
  • One application, tested deeply
  • Authenticated + business logic
  • Audit-ready report
  • Free re-test after you fix
Book assessment

What the same assessment costs elsewhere

ProviderComparable productPrice
AegisGo-Live Assessment — automated, audit-ready report$999 one-off
AikidoStandard Pentest (AI-automated)$4,000
BreachLockPenetration testingfrom ~$5,000
AstraPentest plan, per target$5,999 / year
CobaltPTaaS engagement$2,000 – $50,000
Traditional consultancyHuman-led application pentest$5,000 – $15,000

Publicly listed prices, August 2026. We test the running application — authenticated, business logic and tenant isolation. We do not do source-code, dependency or container scanning; here's exactly when we're the wrong choice.

The deliverable

A report your auditor will actually accept

Confidentiality statement, executive summary, a severity distribution, a master findings table and — for every finding — description, business impact, step-by-step reproduction and remediation. Plus something the incumbents don't give you: a Verified Controls section proving what we attacked and found safe.

Built as audit evidence. The report is structured to answer ISO 27001 A.8.8 (technical vulnerability management) and SOC 2 CC7.1 / CC4.1 — scope, methodology, dated findings, remediation and control verification. See the control mapping →

Generate your first report
Aegis penetration test report showing the severity distribution chart and the master findings table with findings AEG-1 to AEG-6, plus a detailed finding with description and business impact
An actual Aegis report — real findings from a live assessment.
Trust

Built to fail closed

Ownership-verified

No target is ever scanned until DNS ownership is independently proven. Private and reserved networks are refused by policy.

Tenant-isolated

Every assessment belongs to one tenant. Cross-tenant access is impossible by construction, and scans run in isolated workers.

Non-destructive default

Aggressive, state-changing testing is off unless you explicitly authorise it against a non-production target. Emergency stop always available.

Automated service terms

What this is — and what it isn't

Aegis is unsupervised automation. We'd rather be plainly honest about that than bury it in a PDF.

You authorise every test

You confirm you own the target or are authorised to test it, and you accept the rules of engagement before anything runs. Ownership is proven by DNS, and that record is your authorisation. Testing systems you do not own is unlawful in most jurisdictions and is a breach of these terms.

Automated, not a human pentester

Findings are produced by automation. It will not replicate a skilled human attacker's creativity, and no automated test proves the absence of vulnerabilities. A clean report means the tests we ran found nothing — not that your system is secure.

Testing carries inherent risk

Security testing sends real traffic. Even non-destructive checks can surface latent faults, trip rate limits or fill logs. Aggressive tiers write data by design. You are responsible for backups, a rollback plan and choosing an appropriate window — which is why aggressive testing is restricted to non-production targets.

Limitation of liability

The service is provided "as is", without warranty of any kind. To the maximum extent permitted by law, Backbone Solutions is not liable for indirect, incidental or consequential loss — including downtime, lost data, lost revenue or reputational harm — arising from use of the service. Total liability is limited to the fees you paid in the preceding twelve months.

Not a compliance certification

Reports support a defensible security process and can be shared with auditors under NDA. They are not a certification against SOC 2, ISO 27001, PCI DSS or any other standard, and are not legal advice. Your auditor decides what satisfies their requirements.

Your data

Findings and evidence belong to you, are encrypted at rest, and are scoped to your workspace alone. Evidence is redacted server-side before storage. You can export or delete your data at any time.

Summary only — the binding text is in the Terms of Service, Acceptable Use Policy and Rules of Engagement, which you accept at sign-up.

Go live with confidence

Your first pentest is minutes away, not months.

Verify a domain, accept the rules, and let Aegis do the rest. Free to start.