Company Profile & Service Offering

On-demand, autonomous penetration testing that proves the risk.

PentestMe is a security-testing platform that attacks your applications, APIs, cloud and network the way a real adversary would, then backs every finding with reproducible evidence. Not a scanner dump. A prioritised, exploitable picture of where you are exposed, refreshed as your attack surface changes.

Web applicationsAPIsCloud & M365Network & infrastructure DatabasesVPNAttack Surface ManagementThreat intelligence
Who we are

A testing platform built by offensive engineers, run on demand.

Traditional pentests are a snapshot: expensive, point-in-time, and stale the moment your next release ships. PentestMe combines an autonomous multi-agent testing engine with expert-authored methodology so you get deep, adversary-grade coverage on demand, and again whenever something changes.

8
attack surfaces tested from one platform, web through database
OWASP
Top 10 for web and API mapped, plus MITRE ATT&CK technique coverage
24/7
continuous attack-surface monitoring with change diffing and alerts
100%
findings backed by reproducible evidence, mapped to a severity you can act on
What we test

One platform, every layer between your users and your data.

Each engagement runs the discipline-specific methodology below, chains findings across surfaces, and reports business impact, not isolated alerts.

Web application testing

Our flagship. Full OWASP coverage with a headless browser that finds DOM and framework XSS, auth and session flaws, IDOR and business-logic breaks the way a real user would.

  • XSS, CSRF, SSRF, injection
  • Broken access control / IDOR
  • JWT & OAuth abuse
  • Authenticated crawl & SPA support

API security

OWASP API Top 10 against your REST and GraphQL endpoints, spec-driven or discovered, including the object- and function-level authorization gaps scanners miss.

  • BOLA / BFLA authorization
  • Mass assignment & data exposure
  • GraphQL introspection & abuse
  • Rate-limit & business-flow abuse

Cloud & Microsoft 365

Posture assessment across AWS, Azure, GCP and Microsoft 365, with step-by-step remediation for every misconfiguration, mapped to the exact portal path and command.

  • IAM, storage & network exposure
  • M365 mail rules & delegation
  • Identity & conditional access
  • Guided fixes per finding

Network & infrastructure

External and internal network testing: exposed services, weak configurations, datastore exposure and lateral-movement paths across your estate.

  • Service & port discovery
  • Datastore & pooler exposure
  • Default / weak credentials
  • Active Directory paths

Database & backend

Deep testing of modern data backends, including Supabase and PostgREST: row-level security, RPC injection, storage and realtime exposure, all proven without touching real records.

  • RLS & cross-tenant isolation
  • RPC / SQL injection proof
  • Storage object exposure
  • Realtime & edge-function authz

VPN & remote access

Assessment of SSL-VPN portals and tunnels for authentication posture, credential spray resilience and key or configuration exposure.

  • Portal auth posture
  • Credential-spray resilience
  • WireGuard / OpenVPN exposure
  • Appliance CVE checks

Attack Surface Management

Continuous discovery of your internet-facing assets with change diffing, so a new subdomain, port or exposed service becomes an alert, not a breach.

  • Subdomain & asset discovery
  • Change diff & new-asset alerts
  • Exposure & certificate tracking
  • Ongoing coverage

Threat intelligence

Dark-web and breach monitoring for your domains and people, with branded alerting when leaked credentials or exposed data surface.

  • Leaked-credential monitoring
  • Infostealer & breach data
  • Domain & brand exposure
  • Real-time alert webhooks
How we work

Adversary methodology, executed and proven, never guessed.

Every engagement follows the same disciplined pipeline. We identify, we validate safely, and we only report what we can reproduce.

Recon

Map

Enumerate the full attack surface: assets, endpoints, technologies and trust boundaries.

Enumerate

Probe

Drive each surface with its discipline-specific methodology to surface candidate weaknesses.

Exploit

Validate

Safely confirm exploitability with benign markers, never destructive payloads on live data.

Chain

Correlate

Link findings across layers into real attack paths with genuine business impact.

Report

Deliver

Prioritised findings, reproducible proof and clear remediation, ready for your team.

Authorized and scopedTesting runs only inside an explicit, attested authorization boundary. Intrusive proofs require sign-off.
Prove, do not destroyWe demonstrate access with a benign marker. We never exfiltrate real data or mutate production to make a point.
Evidence over noiseEvery finding carries reproducible proof and a severity you can trust, not a raw scanner alert.
Why PentestMe

The depth of a specialist team, at the cadence of software.

01

Autonomous, not just automated

A multi-agent engine reasons about each target, adapts its plan to what it finds, and fans out heavy tooling only where it matters.

02

Real proof, not scanner noise

Findings are validated and evidenced. Severity reflects demonstrated impact, so your team fixes what is genuinely exploitable first.

03

On-demand, every release

Run a full assessment whenever you ship, and keep your attack surface monitored between engagements. Security keeps pace with your deployments.

04

Safe and accountable

Authorization attestation, target guarding and read-first testing are built in. You always control the boundary.

05

Framework-aligned

Findings map to OWASP and MITRE ATT&CK, so reporting slots straight into your risk and compliance workflows.

06

Full-stack in one place

Web, API, cloud, network, database and more from a single platform, with findings correlated across every layer.

Reporting & delivery

Reports your engineers act on and your board understands.

Executive summary & risk score. A clear, quantified read of your posture for leadership.
Reproducible proof per finding. Evidence, payload and steps so fixes can be verified.
Branded PDF export. Share-ready documents for clients, auditors and stakeholders.
Integrations. Push findings to your workflow through webhooks and ServiceNow.
Packages

Straightforward plans. Scale up whenever you need to.

Every plan includes the full testing platform and reporting. Choose the scan volume that fits your release cadence, or talk to us about a custom package.

Starter
R3 449 / mo
For small teams putting a first, repeatable testing rhythm in place.
  • 2 full scans / month
  • All attack surfaces
  • Evidence-backed reports
  • Branded PDF export
Professional
R6 899 / mo
For growing teams shipping often and needing broader coverage.
  • 5 full scans / month
  • Attack Surface Management
  • Threat-intel monitoring
  • Webhook & ServiceNow integration
Business
R10 349 / mo
For organisations that need ongoing, higher-volume assurance.
  • 8 full scans / month
  • Priority scan scheduling
  • Continuous ASM & alerting
  • Full integration & export suite
Request a quote

All prices in ZAR, VAT included, billed monthly. Need higher volume, dedicated scope or a bespoke arrangement? Custom and enterprise packages are available on request.

See your real attack surface.

Start a free pentest and get an evidence-backed picture of where you are exposed, from your web front end all the way down to your database.