
Unlimitedpenetration testing.
Every discipline below, across your entire estate, run continuously for one annual fee. Use it as often as you need. There is no per engagement charge, because there is no per engagement.
Nine disciplines. One agreement.
Bought separately these are nine statements of work and nine invoices. Here they are the same engagement, and you decide how much of each you use.
- External penetration testingEverything you expose to the internet, tested continuously as it changes.
- Internal penetration testingWhat an attacker reaches once they are inside, whether by phish, supplier or stolen laptop.
- Web application testingAuthenticated and unauthenticated testing of your applications and their APIs.
- Red teamingObjective led, no announcement, measured against your detection and response rather than a checklist.
- Social engineeringPhishing, vishing and pretext delivery against real staff, with training that follows the failure.
- Cloud configuration reviewIdentity, permissions, storage and network posture across your cloud accounts.
- Attack surface monitoringDiscovery of assets you did not know you had, which is most of the interesting ones.
- Adversary simulationKnown threat actor tradecraft replayed against your controls to see what actually fires.
- Remediation retestingVerification that a fix worked. Included, and repeated until the finding is closed.
One agreement. Testing that never stops.
The same sequence a competent attacker follows, run against your estate on repeat rather than once.
- MapWe build and maintain a live picture of everything you expose: domains, hosts, cloud accounts, third party integrations, staff. It is rebuilt continuously, not captured once at kick off.
- TestManual testing against that surface, plus automated coverage between passes. New asset appears on Tuesday and it is tested on Tuesday. You do not raise a change request.
- EscalateWhere a finding is exploitable we prove it. Chained access, privilege escalation, lateral movement and impact, demonstrated rather than described in a severity table.
- ReportFindings reach you as they are confirmed, with reproduction steps and a fix. There is no six week wait for a document, because the document is not the deliverable.
- RetestYou fix it, we verify it, and it stays on the list until it is closed. Retesting is included, which removes the commercial reason to stop looking.
What changes when the meter stops running.
Traditional testing is priced per engagement, so every question costs money and every question therefore gets asked less often. Unlimited removes that.
- Scoped once, priced by the day, delivered as a report
- Scoped once, priced annually, delivered continuously
- Usually billed again. Included here.
- Usually out of scope until the next cycle. In scope on the day here.
- Usually a change request and a lead time. Included here.
- Usually the end of the engagement. Here it is a running record.
The ones that actually get asked.
Yes, within a scope agreed at the start: your estate, your applications, your people. Test as often as you want inside it. What is not unlimited is our capacity, so we cap how many clients we take on rather than capping what each one uses.
One annual fee, set by the size and complexity of your estate at the outset. It does not move because you asked for another test. Book a scoping call and you get the number.
Yes. Auditors and insurers want a dated, scoped, formal document, and you get one on the cadence you need. It is a by-product of the engagement rather than the reason for it.
That is a fair reason to keep an external annual test, and some clients do exactly that. Continuous testing catches the eleven months the annual test does not.
Immediately, by the route you choose, with reproduction steps. Critical findings are not held back for a scheduled report.
Yes. We operate across both, and testing is arranged to respect the rules that apply in each.
Find out what a scoping call costs you.
Nothing. Half an hour, an honest read on your exposure, and a fixed annual number if it is a fit.


