PTaaS replaces the annual engagement with continuous testing you start on demand. Same methodology, same evidence, priced in Rand and available the day you need it rather than the quarter you booked it.
Your security posture changes every release. A report from eleven months ago describes a system that no longer exists.
The testing itself is not the difference. The delivery model is.
| Traditional engagement | PTaaS | |
|---|---|---|
| Frequency | Once a year, or once before an audit | Every release, or on demand |
| Time to start | Weeks — scoping, proposal, booking | Minutes |
| Price | R50 000 to R150 000 per engagement | From R3 449/month for two pentests |
| How you learn the price | Scoping call and a proposal | Published on the site |
| Scope | Priced per surface, separate statements of work | Web, API, network, cloud, email and VoIP together |
| Between tests | Nothing until the next engagement | Findings tracked, retested, and compared run to run |
A traditional engagement is still the right call for some work — complex business logic, chained exploitation, and red-team exercises need a human tester. Those run as manual engagements alongside the platform rather than instead of it.
Six differences that matter in practice.
A traditional engagement is a snapshot: accurate the week it was run, steadily less true every release after it. PTaaS tests on your schedule, so the answer keeps pace with the code.
Plans are on the site. No scoping call, no proposal, no procurement round before you learn what it costs. A custom quote exists for scopes that genuinely need one.
No slot to book. Verify the target is yours, choose the surfaces, start the engagement. Most complete the same day.
Web, API, network, cloud, email and VoIP under a single engagement and a single report, instead of separate statements of work per surface.
Every finding carries its evidence tier: proven by safe exploitation, confirmed by observed behaviour, or flagged as potential and needing confirmation. You know what to fix now and what to verify.
Findings persist across engagements, so you can see what was fixed, what recurred, and what is new since the last run, rather than comparing PDFs by hand.
POPIA requires appropriate, reasonable technical measures to secure personal information, and expects them to be kept current. An annual test demonstrates diligence on one date. Continuous testing demonstrates it as an ongoing practice, which is the harder thing to evidence and the thing an Information Officer is actually asked about.
One subscription, one scope, six attack surfaces.
Penetration testing as a service. Instead of buying a single engagement once a year, you subscribe to a platform that runs real penetration tests on demand, reports findings continuously, and tracks them between runs. The testing methodology is the same; the delivery model is not.
A scanner performs a signature sweep and hands you a flat list of possible issues. A penetration test works through a methodology, chains related weaknesses, safely proves what it can, and tells you how strong the evidence is for everything else. PTaaS delivers the second thing at closer to the price of the first.
For most scopes it covers the ground a scheduled engagement would, continuously rather than annually. Some work still needs a human: complex business logic, chained exploitation across systems, and red-team exercises. Those are available as manual engagements alongside the platform.
Reports are dated, evidence-backed, and mapped to PCI DSS, ISO 27001 and SOC 2, and stand as evidence toward POPIA. Because testing runs continuously, you have a current report when an auditor or a customer questionnaire asks for one, rather than a document from eleven months ago.
Plans start at R3 449 a month for two pentests, billed in Rand. A single traditional engagement typically runs R50 000 to R150 000 and covers one point in time. Your first pentest is free, with no card required.
Run a real, validated penetration test on your own target before you pay anything. No credit card.
Start your free pentest