Baseline
Low-rate, non-destructive checks on your public surface. Auto-runs the moment ownership and rules of engagement are satisfied.
- Security headers & TLS posture
- CSP / CORS analysis
- Cookie security
- API spec-drift detection
Aegis proves you own the target, tests it like an attacker — authenticated, business-logic and all — and hands you a boardroom-grade report. No consultants, no scheduling, no six-week wait.
This is the section other reports don't have: not what broke, but what we attacked and found holding. It is the evidence a reviewer needs to accept a clean result — and it answers SOC 2 CC4.1 directly. How verified controls work →
Every gate is automated and fail-closed. A human never has to approve a safe scan — but nothing runs until ownership and rules of engagement are satisfied.
Drop one DNS TXT record. Aegis confirms you control the target before anything is queued.
Confirm scope, rate limits and emergency contact. Your acceptance is recorded, not a checkbox theatre.
The policy engine approves and dispatches the scan to an isolated worker — no operator in the loop.
Executive summary, severity chart, reproducible findings and remediation — ready to hand to an auditor.
Each tier unlocks with your plan. Aggressive testing is a gated premium tier — separate written approval, a non-production target and a rollback window.
Low-rate, non-destructive checks on your public surface. Auto-runs the moment ownership and rules of engagement are satisfied.
Aegis logs in as your roles and tests the surface real users see — where the real risk lives.
State-changing, business-logic attack simulation against a non-production target, with a rollback window and operator monitoring.
No sales call. The right tier depends on what you're testing and what you're allowed to touch.
We'll recommend the tier that matches — and tell you what you need to have ready.
Nothing here is a surprise mid-flow. Have these in hand and a baseline runs in minutes.
You'll add one DNS TXT record to prove ownership. We never scan a target that hasn't been proven — no exceptions, no manual override.
Whoever manages your DNS (Cloudflare, Route 53, your registrar) needs to add the record. Takes a minute; propagation is usually fast.
All tiersMost providers allow testing of your own resources, but their policy is yours to follow. See the matrix below — you'll confirm this before anything runs.
All tiersFor authenticated testing: a low-privilege account we can log in as. Never use a real customer or admin account. Rotate the password afterwards.
Authenticated +State-changing tests write data. They run against staging or a disposable copy — never your live system. We enforce this in code.
AggressiveA testing window plus someone reachable while it runs. You keep an emergency stop that halts everything immediately.
AggressiveSecurity testing traffic can look like an attack. Check your provider's current policy before you run — and if you're behind a WAF or rate limiter, allow-list our traffic so results aren't distorted by the edge blocking us.
| Provider | Typical position | What you should do |
|---|---|---|
| DigitalOcean | Testing your own Droplets is generally permitted under their AUP. | Review the current AUP; keep testing to resources you own. |
| AWS | Customer-initiated testing of many services is permitted without prior approval; simulated DoS still requires it. | Check the current customer support policy for penetration testing. |
| Microsoft Azure | Pre-approval generally not required; their Rules of Engagement apply. | Read the Azure penetration testing Rules of Engagement. |
| Google Cloud | No pre-approval generally required; the AUP applies. | Confirm against the current Google Cloud AUP. |
| Cloudflare / any WAF | Your origin is yours to test — their infrastructure is not in scope, ever. | Allow-list the scan so the WAF doesn't mask real findings. |
| Shared hosting | Often restricted, because neighbours share the machine. | Get written permission first, or test a copy you control. |
Policies change. This table is a starting point, not legal advice — verify your provider's current terms. Aegis never tests provider infrastructure (Cloudflare, DigitalOcean, AWS and the like); only the application at the target you have proven you own.
Everything the big platforms do — at roughly a fifth of the cost. Start free; upgrade when you need depth.
| Provider | Comparable product | Price |
|---|---|---|
| Aegis | Go-Live Assessment — automated, audit-ready report | $999 one-off |
| Aikido | Standard Pentest (AI-automated) | $4,000 |
| BreachLock | Penetration testing | from ~$5,000 |
| Astra | Pentest plan, per target | $5,999 / year |
| Cobalt | PTaaS engagement | $2,000 – $50,000 |
| Traditional consultancy | Human-led application pentest | $5,000 – $15,000 |
Publicly listed prices, August 2026. We test the running application — authenticated, business logic and tenant isolation. We do not do source-code, dependency or container scanning; here's exactly when we're the wrong choice.
Confidentiality statement, executive summary, a severity distribution, a master findings table and — for every finding — description, business impact, step-by-step reproduction and remediation. Plus something the incumbents don't give you: a Verified Controls section proving what we attacked and found safe.
Built as audit evidence. The report is structured to answer ISO 27001 A.8.8 (technical vulnerability management) and SOC 2 CC7.1 / CC4.1 — scope, methodology, dated findings, remediation and control verification. See the control mapping →
Generate your first report
No target is ever scanned until DNS ownership is independently proven. Private and reserved networks are refused by policy.
Every assessment belongs to one tenant. Cross-tenant access is impossible by construction, and scans run in isolated workers.
Aggressive, state-changing testing is off unless you explicitly authorise it against a non-production target. Emergency stop always available.
Aegis is unsupervised automation. We'd rather be plainly honest about that than bury it in a PDF.
You confirm you own the target or are authorised to test it, and you accept the rules of engagement before anything runs. Ownership is proven by DNS, and that record is your authorisation. Testing systems you do not own is unlawful in most jurisdictions and is a breach of these terms.
Findings are produced by automation. It will not replicate a skilled human attacker's creativity, and no automated test proves the absence of vulnerabilities. A clean report means the tests we ran found nothing — not that your system is secure.
Security testing sends real traffic. Even non-destructive checks can surface latent faults, trip rate limits or fill logs. Aggressive tiers write data by design. You are responsible for backups, a rollback plan and choosing an appropriate window — which is why aggressive testing is restricted to non-production targets.
The service is provided "as is", without warranty of any kind. To the maximum extent permitted by law, Backbone Solutions is not liable for indirect, incidental or consequential loss — including downtime, lost data, lost revenue or reputational harm — arising from use of the service. Total liability is limited to the fees you paid in the preceding twelve months.
Reports support a defensible security process and can be shared with auditors under NDA. They are not a certification against SOC 2, ISO 27001, PCI DSS or any other standard, and are not legal advice. Your auditor decides what satisfies their requirements.
Findings and evidence belong to you, are encrypted at rest, and are scoped to your workspace alone. Evidence is redacted server-side before storage. You can export or delete your data at any time.
Summary only — the binding text is in the Terms of Service, Acceptable Use Policy and Rules of Engagement, which you accept at sign-up.
Verify a domain, accept the rules, and let Aegis do the rest. Free to start.