SOC 2 Ready
Penetration Testing Built for North American Compliance
We produce audit-ready evidence for HIPAA risk analyses, SOC 2 Type II security criteria, and NIST CSF assessments. Scoped, documented, and delivered in 2–4 weeks.
- HIPAA
- CCPA / CPRA
- SOC 2 Type II
- NIST CSF
- OSCP
- CEH
- CISSP
- CREST
Deliverables
pentest.business
Your obligation
Annual penetration testing
SOC 2 Type II · Trust Services · USA
Trusted by enterprises in regulated industries
Named clients in medical robotics, managed IT, compliance software and financial-sector web — every logo shown with their consent.
Services and deliverables
One document per scope, and what it says.
Deliverables
pentest.business
Your obligation
Annual penetration testing
SOC 2 Type II · Trust Services · USA
Illustrative finding classes — not client data.
Manual testing, not just a scan
Three of these six phases are the same work. The other three are the whole difference.
We agree the exact perimeter, rules of engagement, LOA, NDA, and testing window.
Technical report + executive summary with CVSS scores, PoC evidence, and remediation steps.
Free re-test of critical and high findings after remediation — closure letter included.
Three of these six are identical. An attacker just doesn't ask permission first — and never writes it down.
Compliance & standards
Your regulator's own control list, and the row our report answers.
Still asking
Case files
What an engagement looks like
A specimen of the report we deliver, and three representative engagements by sector.

European retail bank
Infrastructure & network · Web applications & APIs
Payments / fintech platform
Web applications & APIs · Cloud infrastructure
Healthcare technology
Web applications & APIs · Mobile applications
Outcome
Critical and high findings remediated, then re-tested free of charge — the engagement closes with a signed closure letter.
Illustrative engagement profile — representative of our work, not a specific client.
Our team and your data
The people, the paperwork, and the clients who let us do this.

The testers
Tester certifications
OSCP · CEH · CISSP · CREST
How to get started
Starting costs you a scope, not a number.
- Scope
- LOA
- NDA
- Window
Free scoping call — we reply within one business day. No obligation.
- 1
Describe your perimeter
a form
- 2
Scoped estimate and timeline
one call
- 3
LOA, NDA, kickoff
a signature
We don't publish price lists. Every perimeter is a different size.
How we price a projectStill asking
Still asking
Every engagement ends with evidence
Then you hold the evidence that you tested.
The obligation is to test, not to be broken. The clause below is satisfied by the engagement, not by the findings — and the report is the same document either way.
Annual penetration testing
11 remediated
Illustrative finding classes — not client data.
SOC 2 audit or HIPAA assessment coming up?
Start your penetration test 4–6 weeks before your audit window. We deliver audit-ready reports on time.


