Pentesting, reinvented.

On-demand penetration testing for web, API, network & cloud.

Know you're secure every time you ship.

Run a real penetration test on demand and get a validated report the same day.

Every finding is checked for real exploitability, not a list of maybes, at a fraction of the cost of a once-a-year engagement.

See a real sample report

No credit card required. 1 free pentest included. Cancel anytime.

Runs safely on production POPIA-aligned Built in South Africa
6
Attack surfaces
Web, API, network, cloud, email, VoIP
Same day
Report turnaround
From pentest to validated report
Validated
Every finding
Checked for real exploitability
Free
First pentest
Full assessment, no card required

The problem

The old testing model no longer fits how you build.

Four gaps open up when security testing happens once a year and arrives as a list of maybes.

Release cadence outpaces booked engagements

You ship every week. A pentest booked once or twice a year cannot keep up, so most changes go live untested.

Full manual engagements price teams out

Traditional engagements cost more than most teams can spend more than once a year, so proper testing simply does not happen often enough.

Scanner output is not a pentest

A raw vulnerability scan is a list of maybes. Without validation and triage, your team burns days chasing findings that were never exploitable.

Auditors want current evidence

POPIA, PCI DSS, and ISO reviews ask for recent, evidence-backed testing. A report from eleven months ago describes a system that has already changed.

Untested change is a compliance risk, not just a security one. Regulators worldwide, from GDPR (fines up to €20 million or 4% of global turnover) to POPIA and PCI DSS, expect recent, evidence-backed testing and penalise inadequate safeguards. Testing every release is how you show due diligence between audits.

The comparison

Why teams switch to PentestMe.

Same rigour as a booked engagement, without the wait, the cost, or the once-a-year blind spots.

Currency:
Traditional engagement
PentestMe
Turnaround
2 to 6 weeks
Same day
Typical cost
R50 000 to R150 000 per test
From R3 449 / month
Testing frequency
Once or twice a year
Every release
Findings
Often a raw list
Validated, ranked, retestable
To get started
A consultant's diary
Right now, for free
Compliance evidence
Stale within months
Dated and repeatable

Cost figures are typical market ranges for a comparable manual engagement.

How it works

From target to validated report, in one afternoon.

1

Define scope and prove authorisation

Point PentestMe at a target and prove you may test it: for a domain, a quick DNS record or hosted file, or an authorisation letter we review. Scope is enforced from the first request.

2

The engagement runs

Recon, enumeration, and vulnerability discovery run in parallel, the same phases a tester works through by hand.

3

Findings are triaged and ranked

Findings are triaged, deduplicated, and ranked by real risk, so you see what matters instead of raw noise.

4

You get an actionable report

A clear report with remediation guidance and a retest path, so every fix can be confirmed closed.

Coverage

Every attack surface, one platform.

Confirm your stack is covered. Attackers do not stay in one lane, and neither should your testing.

Web Applications

OWASP Top 10, injection, auth, access control, business logic.

APIs

REST and GraphQL. BOLA and BFLA, auth, rate limits, spec-driven fuzzing.

Network

External and internal hosts, services, misconfig, datastore exposure.

Cloud

AWS, Azure, and GCP posture. IAM, storage, and identity misconfig.

Email

SPF, DKIM, DMARC, relay, and spoofing exposure.

VoIP

SIP enumeration, weak auth, and telephony attack surface.

Methodology and trust

A real methodology, with real guardrails.

Automation is only useful if you can trust what it does and where it stops.

WSTG and PTES coverage tracking

Web testing tracks against the OWASP WSTG checklist and engagements follow the PTES phases, so coverage is measured, not assumed.

Triage and dedup before reporting

Findings are triaged, deduplicated, and ranked before they reach you, so the report is signal rather than raw output.

Scope guard and rate controls

A server-side scope guard and measured request rates keep testing inside authorised targets and gentle on production.

Non-destructive exploit validation

Findings are confirmed with safe proof-of-exploit checks, and higher-risk actions are gated behind explicit authorisation, so validation never damages your systems.

Engagement pipeline live
  1. Recon
  2. Enumeration
  3. Web Vulns
  4. API Vulns
  5. Exploitation
  6. Triage
  7. Reporting

The deliverable

See exactly what you get, before you pay.

Every pentest produces an executive summary, a risk score, and a per-finding breakdown with supporting evidence (proof-of-exploit where it applies), severity, affected assets, and clear remediation steps.

Findings map to CVSS and MITRE ATT&CK, and the whole report is dated evidence that testing was performed, exactly what compliance and leadership ask for.

Open the sample report
Redacted sample PentestMe penetration test report showing risk score, severity breakdown, and validated findings

What you get

Built to deliver findings you can act on.

Multi-surface testing

Web, API, network, cloud, email, and VoIP assessed from one platform, under one scope.

Never chase a false positive

Every reported finding is checked for real exploitability, so your team acts on proven issues instead of triaging noise.

Catch regressions between releases

Run on demand or on a recurring schedule, and get alerted when a new issue appears after you ship.

Actionable reports

Executive summary, ranked findings, remediation guidance, and a retest path in every report.

Framework mapping

Findings mapped to OWASP WSTG, PTES, MITRE ATT&CK, and CVSS for consistent, defensible severity.

Team collaboration

Role-based access and activity tracking so your security and engineering teams work from one source of truth.

Compliance

Proof for the frameworks you answer to.

Findings are mapped to the standards your auditors and regulators care about, so a pentest doubles as compliance evidence.

PCI DSS

Supports Requirement 11, regular testing of systems and networks.

ISO 27001

Technical evidence for Annex A control validation and audits.

SOC 2

Findings mapped to the Trust Services Criteria for control validation.

POPIA

A dated, evidence-backed report supporting reasonable technical safeguards.

Pricing

Enterprise-grade testing, startup-friendly pricing.

Simple monthly plans, no per-engagement quotes, no surprises. From R3 449 a month.

Currency:
MonthlyAnnualSave 20%

Starter

R3 449/mo

2 pentests / month

Most popular

Professional

R6 899/mo

5 pentests / month

Business

R10 349/mo

8 pentests / month

Every plan includes

All six attack surfaces
Validated, ranked findings
Same-day reports with remediation
Free retest on every finding
Scheduled pentests and new-issue alerts
Framework and compliance mapping

Need more pentests or a custom scope?

Enterprise plans, multi-target scopes, and network or cloud engagements. Get an instant quote in under a minute.

Built on the standards professionals rely on

OWASP WSTGPTESMITRE ATT&CKCVSSISO 27001

Data encrypted

Pentest data encrypted, credentials never stored in the clear.

Scope-guarded

A server-side guard blocks internal, loopback and cloud-metadata hosts on every request.

POPIA-aligned

Operated from South Africa under POPIA.

Non-destructive

Safe proof-of-exploit checks, gated higher-risk actions.

Questions

Straight answers to the usual questions.

Is it safe to run against production?
Yes. Testing is designed to run safely against live systems. Exploit validation confirms a vulnerability is real without destructive actions, higher-risk checks are gated behind explicit authorisation, and request rates are kept measured.
How is this different from a vulnerability scanner?
A scanner produces a list of potential issues. PentestMe validates each finding for real exploitability, chains related weaknesses, and ranks by actual risk, so you get proof rather than a backlog of maybes. It works through the WSTG and PTES phases a tester would, not just a signature sweep.
What authorisation do you need?
Before pentesting a domain you prove you control it, by adding a DNS record or hosting a small verification file, or you upload an authorisation letter that we review. Separately, a server-side scope guard always blocks requests to internal, loopback and cloud-metadata endpoints, so testing cannot be turned against infrastructure it should never touch.
Is this automated or a manual consulting engagement?
PentestMe is automation-driven. It works through the same phases an experienced tester would, tracked against WSTG and PTES, and validates every finding for real exploitability before it lands in your report. That is what delivers a pentest in hours instead of weeks, with no consultant to wait on.
Is my data safe with PentestMe?
Pentest data is encrypted, access is role-based, and we operate under POPIA. Target credentials are never stored in the clear, and the scope guard keeps testing inside your verified targets and away from internal, loopback and cloud-metadata endpoints.
What does the free pentest include, and what happens next?
The free pentest runs a full assessment against one target and delivers a validated report, no card required, so you can see the depth before you pay. If it is useful, pick a monthly plan to add targets, schedules, and alerts. If not, there is nothing to cancel.
How long does an engagement take?
Most pentests complete and deliver a report the same day. Larger scopes take longer, but you are not waiting weeks for a slot or a write-up.
Will an auditor accept the report?
Reports are dated, evidence-backed, and mapped to PCI DSS, ISO 27001, and SOC 2, and stand as evidence toward POPIA, which is the kind of artefact auditors and regulators ask to see.
Can I retest after fixing an issue?
Yes. Every report includes a retest path. Fix a finding, re-run the pentest, and confirm the issue is closed. Recurring schedules keep it verified as you ship.

Learn more

Understand how we test, and why it holds up.

Stop testing once a year. Start testing when it matters.

Run your first validated pentest today. No credit card, no consultant's diary, no quote to wait for.

1 free pentest included
No credit card required
Cancel anytime