Straight answers about penetration testing.
Including the ones vendors avoid — what it really costs, when automation isn't enough, and whether an auditor will accept the report.
Cost & value
It depends entirely on who does it:
| Option | Typical price |
|---|---|
| Traditional consultancy (human testers) | $5,000 – $15,000 per application |
| Automated AI pentest platforms | ~$4,000 per application |
| Continuous scanning platforms | $170 – $600 / month |
| Aegis | $999 one-off, or from $149/month |
The gap isn't magic — it's that scheduling, scoping calls and manual report-writing dominate the cost of a traditional engagement. Automating those is where the saving comes from.
Aegis, at $999 one-off or $149/month, is the most affordable audit-ready penetration test we're aware of.
Being precise about that claim: cheaper vulnerability scanners exist, and some (like OWASP ZAP) are free. What they don't produce is a penetration test report with evidence, business impact and remediation that an auditor will accept — and they don't sign in and test authorization logic. If all you need is a surface scan, use a free scanner; we'd rather tell you that than sell you something you don't need.
A consultancy engagement is mostly human time: scoping calls, scheduling, the test itself, then days of report writing. Aegis automates the testing and generates the report from the same evidence, so the marginal cost of an assessment is compute rather than consultant-days.
The honest trade-off: you don't get a human's creativity. See when we're the wrong choice.
Process & timing
Same day — usually hours. Prove domain ownership with a DNS TXT record, accept the rules of engagement, and testing begins automatically. There's no scheduling queue and no consultant to coordinate with.
A traditional engagement typically takes two to six weeks, most of it waiting.
- All tiers: a domain you control, and DNS access to add one TXT record.
- Authenticated tier: a dedicated low-privilege test account. Never a real customer or admin account — and rotate the password afterwards.
- Aggressive tier: a non-production target, a testing window, a rollback plan, and a contact reachable during the run.
Full detail on the readiness checklist.
Check their policy — it's your obligation, and you confirm it in the rules of engagement. Most providers (DigitalOcean, AWS, Azure, Google Cloud) permit testing of resources you own under their acceptable use policies; shared hosting is often restricted because neighbours share the machine.
Aegis never tests provider infrastructure — only the application at a target you've proven you own. That's enforced in code, not just policy.
One practical tip: if a WAF or rate limiter sits in front of your app, allow-list the testing. Otherwise the edge blocks us and the report reflects the WAF's behaviour rather than your application's real security.
Baseline and authenticated tiers are non-destructive and rate-limited, and safe against production. They send real traffic, so they can surface latent faults or trip rate limits — that's true of any security testing.
The aggressive tier writes data by design, which is exactly why it's restricted in code to non-production targets. An emergency stop is available at all times and halts further requests immediately.
Compliance & reports
First, a point of precision: there is no such thing as a "SOC 2 compliant report." Those frameworks certify organisations, not documents. What they require is evidence that you test for vulnerabilities and act on what you find — and a pentest report is that evidence. Any vendor selling you a "SOC 2 certified report" is describing something that doesn't exist.
The Aegis report is built to answer the specific controls:
| Control | Requires | Where |
|---|---|---|
| ISO 27001 A.8.8 | Technical vulnerability management | Findings + remediation + re-test |
| ISO 27001 A.8.29 | Security testing | Scope & methodology appendix |
| SOC 2 CC7.1 | Detect and monitor vulnerabilities | Scheduled re-scans, assessment history |
| SOC 2 CC4.1 | Ongoing control evaluation | Verified Controls section |
But your auditor decides. Some engagements — PCI DSS 11.4, government and defence procurement — specifically require a named, qualified human tester. If yours does, no automated product (ours or anyone's) satisfies it, and you should hire a consultancy. Ask them before buying; we'd rather lose the sale than have you fail an audit holding our report.
No, and we won't pretend otherwise. A report with no findings means the checks we ran — every one of them documented — didn't detect an issue. No automated test can prove the absence of vulnerabilities.
It's genuinely useful evidence of diligence. It is not a certificate of security, and you shouldn't represent it as one.
Yes. The report is yours, and it carries a confidentiality statement so it can be shared under NDA — which is how most enterprise security questionnaires expect it to be handled. You can export it as HTML, PDF or Markdown at any time.
Testing depth
A scan checks the surface for known issues — missing headers, outdated components, common misconfigurations.
A penetration test signs in and tries to abuse the application: can a low-privilege user reach admin data, can one customer read another's records, can a requester approve their own purchase? These are authorization and business-logic flaws, and they're the most common serious problems in modern applications — precisely because scanners can't find them.
Aegis does authenticated and authorization-differential testing, which is the part most automated tools skip.
Denial-of-service, load and stress testing (deliberately — the risk outweighs the finding); provider infrastructure; social engineering and phishing; physical security; source code, dependencies and containers (SAST/SCA — different discipline); and novel zero-day discovery, which needs human creativity.
Full list with reasoning: what we don't test.
Yes, and for aggressive testing you must. You still prove ownership of the domain the same way. Testing staging is often better: state-changing tests are safe there, so coverage is deeper.
Account & billing
Yes — one target, unlimited baseline scans, full report, no card required. It's a real assessment of your public surface, not a teaser.
Yes. Subscriptions cancel at the end of the current period from the billing portal in your dashboard. The $999 Go-Live Assessment is a one-off purchase — there's nothing to cancel.
Findings and evidence are yours; export them any time. On termination we delete or return your data, and evidence is redacted server-side before storage in the first place. You can also delete individual assessments whenever you like.
Still have a question?
Email a person — we answer within one business day on paid plans.