info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeServicesPenetration Testing

Penetration Testing

Manual, exploit-driven security testing for web applications, APIs, iOS and Android — reported with the evidence your SOC 2, PCI DSS, HIPAA and ISO 27001 auditors actually ask for.

0+
Offensive security specialists
0+
Company hall-of-fame acknowledgements
0
Regions served — USA, Canada, EU, India
0%
Findings manually verified
What We Test

Six testing services, one engagement

Most engagements combine two or three of these. Scope them together and you get a single report, a single remediation cycle and a single attestation letter.

Why Now

The compliance driver behind most US pentests

Nine times out of ten, a penetration test is booked because a framework, an auditor or a customer's vendor-risk questionnaire demands one. Here is where each one lands.

PCI DSS v4.0.1

Requirements 11.4.2 and 11.4.3 call for internal and external penetration testing at least once every 12 months and after any significant change, following a documented methodology, with exploitable findings corrected and retested.

SOC 2

Penetration testing is not named in the Trust Services Criteria, but it is the evidence most auditors expect against CC4.1 and CC7.1 monitoring activities — and the artifact enterprise buyers ask for before signing.

HIPAA Security Rule

§164.308(a)(1)(ii)(A) risk analysis and §164.308(a)(8) periodic technical evaluation both point to technical testing of systems handling ePHI. Our reports map findings to the safeguards they affect.

ISO/IEC 27001:2022

Annex A 8.8 technical vulnerability management and A 8.29 security testing in development and acceptance. Testing evidence supports both your Stage 2 audit and your annual surveillance.

NYDFS 23 NYCRR 500

Section 500.5 requires covered financial entities to conduct penetration testing at least annually, from both inside and outside the information system, with the results supporting the April certification of material compliance.

Customer security reviews

Enterprise procurement and vendor-risk teams routinely ask for a recent third-party pentest and an attestation letter. Ours is written to be shared with prospects without exposing exploit detail.

How We Work

What working with us looks like

Buying security testing across borders usually means chasing status and reading reports written for nobody in particular. We run the engagement the other way round: a named lead, a written update at the end of every test day, and a standing call slot that suits your calendar rather than ours.

  • Daily written updates
  • NDA and MSA before scoping
  • Named engagement lead
  • Fixed-price, fixed-scope quotes
  • Retest included, not billed extra
  • Attestation letter for auditors
  • Findings export for Jira
  • Encrypted evidence handling
Cetonix security testing team reviewing application findings
Methodology

How an engagement runs

Aligned to PTES, NIST SP 800-115 and the OWASP testing guides, with a documented methodology you can hand to an assessor.

01

Scope & rules of engagement

Applications, roles, environments, credentials, test windows and out-of-scope systems agreed in writing. NDA first, then a fixed quote.

02

Testing & exploitation

Reconnaissance, threat modeling and manual exploitation across every user role. Critical findings are reported the day we confirm them, not at the end.

03

Reporting

Executive summary for the board, technical findings with reproduction steps, evidence and CVSS scores, and remediation guidance written for your developers.

04

Retest & attestation

We retest your fixes, reissue the report with each finding resolved or open, and provide a signed attestation letter for auditors and customers.

Standards and frameworks we test against

  • OWASP Top 10
  • OWASP ASVS
  • OWASP WSTG
  • OWASP API Security Top 10
  • OWASP MASVS / MASTG
  • PTES
  • NIST SP 800-115
  • MITRE ATT&CK
  • CWE Top 25
Engagement Models

Test once, or test continuously

Annual compliance test

A point-in-time assessment timed to your audit window, with the report, retest and attestation letter your assessor needs. The usual starting point for SOC 2, PCI DSS and ISO 27001.

Continuous testing

SAST in pull requests and authenticated DAST against staging on every release, triaged by our analysts, with a manual pentest each year. For teams shipping weekly or faster.

Security testing retainer

A reserved block of testing days across the year for new features, acquisitions and customer-driven assessments, at an agreed day rate with priority scheduling.

A note on independence. Cetonix coordinates certification through accredited conformity assessment bodies; we do not issue certificates and we do not make certification decisions. Penetration testing is delivered by our own in-house team. Where we also arrange your certification audit, the same commercial party sits on both sides of the evidence — we disclose that in writing before you engage. Our impartiality policy sets out exactly how we handle it, and you are free to appoint a different provider for either side.
FAQ

Questions buyers ask us first

How quickly can you start, and how long does a test take?
Scoping usually takes one call. Most single web applications or mobile apps run five to ten working days of testing, with the draft report within three working days of test completion. Larger scopes and multi-application programs are planned against your compliance deadline, so tell us the audit date when you inquire.
Is the testing manual or automated?
Manual. Automated tooling is used for coverage and discovery, but every finding is manually verified and exploited before it reaches your report. You will not receive raw scanner output, and you will not be charged for false positives.
Do you include a retest?
Yes. Remediation retesting of reported findings is included within the 60-day retest window, and you receive an updated report showing each finding as fixed, partially fixed or open.
Will the report satisfy our SOC 2, PCI DSS or HIPAA auditor?
The report is written for that purpose: scope and rules of engagement, methodology, CVSS-scored findings with evidence, remediation guidance and retest results, plus a signed attestation letter you can hand to an auditor, a customer or a prospect's vendor-risk team.
Who performs the testing?
A dedicated offensive security team of 20+ specialists with acknowledgements in the security hall of fame of more than 50 companies. You get a named engagement lead for the duration of the project and a written update at the end of every test day. Our team works Indian Standard Time (UTC+5:30); we hold a standing call slot booked to suit your calendar, and critical findings are sent the moment they are confirmed rather than held for the next call.
How is our data handled?
An NDA is signed before scoping. Findings, evidence and credentials are held encrypted, access is limited to the assigned team, and test data is destroyed on request at the end of the retest window. Testing follows the rules of engagement you approve in writing, including time windows and out-of-scope systems.
Can you test in production?
Yes, with agreed rate limits, test accounts and a named contact reachable during the test window. Where production testing carries operational risk, we test a production-parity staging environment and validate the differences with you.

Book a scoping call with the testing team

Tell us what you are shipping — applications, APIs, mobile builds, compliance deadline — and we will come back with scope, timeline and a fixed quote.