Know you're secure every time you ship.
Pentest your website online and get a validated report the same day.
Every finding is graded by the strength of the evidence behind it, so you know what to fix now and what to confirm, at a fraction of the cost of a once-a-year engagement.
How an online pentest works — start one in minutes, no consultant to book.
No credit card required. 1 free pentest included. Cancel anytime.
The problem
Four gaps open up when security testing happens once a year and arrives as a list of maybes.
You ship every week. A pentest booked once or twice a year cannot keep up, so most changes go live untested.
Traditional engagements cost more than most teams can spend more than once a year, so proper testing simply does not happen often enough.
A raw vulnerability scan is a list of maybes. Without validation and triage, your team burns days chasing findings that were never exploitable.
POPIA, PCI DSS, and ISO reviews ask for recent, evidence-backed testing. A report from eleven months ago describes a system that has already changed.
Untested change is a compliance risk, not just a security one. Regulators worldwide, from GDPR (fines up to €20 million or 4% of global turnover) to POPIA and PCI DSS, expect recent, evidence-backed testing and penalise inadequate safeguards. Testing every release is how you show due diligence between audits.
The comparison
Same rigour as a booked engagement, without the wait, the cost, or the once-a-year blind spots.
Cost figures are typical market ranges for a comparable manual engagement.
How it works
Point PentestMe at a target and prove you may test it: for a domain, a quick DNS record or hosted file, or an authorisation letter we review. Scope is enforced from the first request.
Recon, enumeration, and vulnerability discovery run in parallel, the same phases a tester works through by hand.
Findings are triaged, deduplicated, and ranked by real risk, so you see what matters instead of raw noise.
A clear report with remediation guidance and a retest path, so every fix can be confirmed closed.
Online pentest
Plenty of tools will “pentest your website” free in thirty seconds. What they run is a vulnerability scan: a signature sweep that produces a list of potential issues, most of which turn out to be noise.
A scan hands you a flat list of possible issues. This works through a methodology, chains related weaknesses, safely proves what it can, and tells you plainly how strong the evidence is for everything else.
Verify control with a _pentestme TXT record or a file at /.well-known/pentestme-verification.txt. A server-side scope guard enforces it on every request.
Exploit validation confirms a vulnerability without destructive actions, higher-risk checks are gated behind explicit authorisation, and request rates stay measured.
Every finding carries its evidence tier — proven by safe exploitation, confirmed by observed behaviour, or flagged as potential and needing confirmation.
Coverage
Confirm your stack is covered. Attackers do not stay in one lane, and neither should your testing.
OWASP Top 10, injection, auth, access control, business logic.
Web Applications testingREST and GraphQL. BOLA and BFLA, auth, rate limits, spec-driven fuzzing.
APIs testingExternal and internal hosts, services, misconfig, datastore exposure.
Network testingAWS, Azure, and GCP posture. IAM, storage, and identity misconfig.
Cloud testingSPF, DKIM, DMARC, relay, and spoofing exposure.
Email testingSIP enumeration, weak auth, and telephony attack surface.
VoIP testingMethodology and trust
Automation is only useful if you can trust what it does and where it stops.
Web testing tracks against the OWASP WSTG checklist and engagements follow the PTES phases, so coverage is measured, not assumed.
Findings are triaged, deduplicated, and ranked before they reach you, so the report is signal rather than raw output.
A server-side scope guard and measured request rates keep testing inside authorised targets and gentle on production.
Findings are confirmed with safe proof-of-exploit checks, and higher-risk actions are gated behind explicit authorisation, so validation never damages your systems.
The deliverable
Every pentest produces an executive summary, a risk score, and a per-finding breakdown with supporting evidence (proof-of-exploit where it applies), severity, affected assets, and clear remediation steps.
Findings map to CVSS and MITRE ATT&CK, and the whole report is dated evidence that testing was performed, exactly what compliance and leadership ask for.

What you get
Web, API, network, cloud, email, and VoIP assessed from one platform, under one scope.
Every finding carries its evidence tier, so your team can act on what is proven and verify what is not, instead of triaging a flat list.
Run on demand or on a recurring schedule, and get alerted when a new issue appears after you ship.
Executive summary, ranked findings, remediation guidance, and a retest path in every report.
Findings mapped to OWASP WSTG, PTES, MITRE ATT&CK, and CVSS for consistent, defensible severity.
Role-based access and activity tracking so your security and engineering teams work from one source of truth.
Compliance
Findings are mapped to the standards your auditors and regulators care about, so a pentest doubles as compliance evidence.
Supports Requirement 11, regular testing of systems and networks.
Technical evidence for Annex A control validation and audits.
Findings mapped to the Trust Services Criteria for control validation.
A dated, evidence-backed report supporting reasonable technical safeguards.
Pricing
Simple monthly plans, no per-engagement quotes, no surprises. From R3 449 a month.
2 pentests / month
5 pentests / month
8 pentests / month
Every plan includes
Need more pentests or a custom scope?
Enterprise plans, multi-target scopes, and network or cloud engagements. Get an instant quote in under a minute.
Built on the standards professionals rely on
Pentest data encrypted, credentials never stored in the clear.
A server-side guard blocks internal, loopback and cloud-metadata hosts on every request.
Operated from South Africa under POPIA.
Safe proof-of-exploit checks, gated higher-risk actions.
Questions
Learn more
Run your first validated pentest today. No credit card, no consultant's diary, no quote to wait for.