Checklist
Checklist before a pentest
The meeting pays off when the scenario is already on the table. Without that, the first call becomes an inventory. With it, you leave with a slice and a next step.
Surface
Which applications are in. Which APIs. Whether there is a mobile app. Whether cloud is in — and which accounts. Production, staging or both.
What is at stake: customer data, payments, tenants, an internal panel.
Limits
What is off-limits. The time window. Whether there is a release blackout. A channel for a critical issue mid-test.
A recent incident changes the slice. A previous pentest: bring what stayed open — not the whole PDF.
Access
Test credentials are discussed after the slice. We do not ask for admin, a VPN or a source dump in the first email.
An NDA when needed. Who signs on your side. Who receives the report.
Format
One-off or ongoing. Whether you need a retest. Whether leadership only wants a PDF or the team will sit in the delivery.
With that on the table, you can compare proposals. Without it, you compare numbers that do not describe the same job.
Guides
Next step
Want to book a meeting?
Tell us the company size and what needs to be protected — the system, the environment, what is at stake. From the call, we assess the scenario and build the work within your scope.