PTaaS

Penetration testing as a service, built for South Africa

PTaaS replaces the annual engagement with continuous testing you start on demand. Same methodology, same evidence, priced in Rand and available the day you need it rather than the quarter you booked it.

Your security posture changes every release. A report from eleven months ago describes a system that no longer exists.

PTaaS vs a traditional penetration test

The testing itself is not the difference. The delivery model is.

Traditional engagementPTaaS
FrequencyOnce a year, or once before an auditEvery release, or on demand
Time to startWeeks — scoping, proposal, bookingMinutes
PriceR50 000 to R150 000 per engagementFrom R3 449/month for two pentests
How you learn the priceScoping call and a proposalPublished on the site
ScopePriced per surface, separate statements of workWeb, API, network, cloud, email and VoIP together
Between testsNothing until the next engagementFindings tracked, retested, and compared run to run

A traditional engagement is still the right call for some work — complex business logic, chained exploitation, and red-team exercises need a human tester. Those run as manual engagements alongside the platform rather than instead of it.

What the platform model changes

Six differences that matter in practice.

Continuous, not annual

A traditional engagement is a snapshot: accurate the week it was run, steadily less true every release after it. PTaaS tests on your schedule, so the answer keeps pace with the code.

Published price, not a quote cycle

Plans are on the site. No scoping call, no proposal, no procurement round before you learn what it costs. A custom quote exists for scopes that genuinely need one.

Start in minutes, not weeks

No slot to book. Verify the target is yours, choose the surfaces, start the engagement. Most complete the same day.

One scope across six surfaces

Web, API, network, cloud, email and VoIP under a single engagement and a single report, instead of separate statements of work per surface.

Findings graded by evidence

Every finding carries its evidence tier: proven by safe exploitation, confirmed by observed behaviour, or flagged as potential and needing confirmation. You know what to fix now and what to verify.

Trackable between tests

Findings persist across engagements, so you can see what was fixed, what recurred, and what is new since the last run, rather than comparing PDFs by hand.

PTaaS and POPIA

POPIA requires appropriate, reasonable technical measures to secure personal information, and expects them to be kept current. An annual test demonstrates diligence on one date. Continuous testing demonstrates it as an ongoing practice, which is the harder thing to evidence and the thing an Information Officer is actually asked about.

What the platform tests

One subscription, one scope, six attack surfaces.

Frequently asked questions

What is PTaaS?

Penetration testing as a service. Instead of buying a single engagement once a year, you subscribe to a platform that runs real penetration tests on demand, reports findings continuously, and tracks them between runs. The testing methodology is the same; the delivery model is not.

How is PTaaS different from a vulnerability scanner?

A scanner performs a signature sweep and hands you a flat list of possible issues. A penetration test works through a methodology, chains related weaknesses, safely proves what it can, and tells you how strong the evidence is for everything else. PTaaS delivers the second thing at closer to the price of the first.

Is PTaaS a replacement for a manual penetration test?

For most scopes it covers the ground a scheduled engagement would, continuously rather than annually. Some work still needs a human: complex business logic, chained exploitation across systems, and red-team exercises. Those are available as manual engagements alongside the platform.

Does PTaaS satisfy compliance requirements?

Reports are dated, evidence-backed, and mapped to PCI DSS, ISO 27001 and SOC 2, and stand as evidence toward POPIA. Because testing runs continuously, you have a current report when an auditor or a customer questionnaire asks for one, rather than a document from eleven months ago.

What does PTaaS cost in South Africa?

Plans start at R3 449 a month for two pentests, billed in Rand. A single traditional engagement typically runs R50 000 to R150 000 and covers one point in time. Your first pentest is free, with no card required.

Try PTaaS free

Run a real, validated penetration test on your own target before you pay anything. No credit card.

Start your free pentest