Automated scan
- broad detection
- automation
- identification of potential weaknesses
- little contextualisation
Our experts carry out penetration tests on your applications, infrastructure and networks to identify genuinely exploitable vulnerabilities before an attacker discovers them. Each pentest is performed within a previously authorised scope and results in a technical report, a risk rating and a remediation plan.
What you get
At the end of the pentest
A detailed test report with proof of exploitation, severity levels and remediation recommendations — plus a technical and executive debrief session.
93% of businesses have at least one critical vulnerability detectable in an external pentest
Understand
A pentest is an authorised offensive security test. The aim is to work in a way close to that of an attacker, to check whether vulnerabilities on an application, a network or an infrastructure can actually be exploited.
Where a vulnerability scan mainly detects potential weaknesses, a penetration test seeks to assess their exploitability and real impact.
Entry points.
Exploitable vulnerabilities.
Potential impact.
Priority flaws.
Vulnerability scan vs pentest
The scan shows where to look. The pentest seeks to determine what is genuinely exploitable.
Pentest vs bug bounty
The two approaches can be complementary, but they do not meet exactly the same need.
Cybersecurity audit vs pentest
| Cybersecurity audit | Pentest |
|---|---|
| Global view of the IT system | Targeted offensive test |
| Architecture & configuration | Vulnerability exploitability |
| Processes & governance | Attack simulation |
| Broad scope | Precisely defined scope |
| Global roadmap | Offensive technical report |
Our cybersecurity services
Complete IT assessment: systems, networks, access, applications and sensitive data.
Real attack simulation to identify exploitable vulnerabilities before hackers do.
Define and formalise your security rules, access, incident management and IT compliance.
Deploy technical and organisational measures to block and detect attacks.
Test types
External pentest, internal pentest, web pentest and social engineering testing — every attack vector is covered, from the network to applications.
An external pentest assesses your internet-facing surface: what an attacker can reach without prior access to your internal network.
This internal intrusion simulation assesses what an attacker could achieve after initial access to an internal network.
A web pentest and web application pentest cover your applications and interfaces: authentication, session management, authorisations, user inputs, application logic and APIs.
Tests are built around the main families of application risks recognised by OWASP.
This phishing pentest (social engineering test) measures the organisation's resistance to a controlled manipulation or phishing campaign.
Test approach
The tester has very little initial information and is closer to an external attacker scenario.
Some information or access is provided in order to go deeper into the test.
The tester has more complete technical information to analyse the scope in depth.
The test mode is chosen according to the objective, the budget, the depth required and the constraints of the environment.
Legal framework
The scope is contracted before testing begins.
Domains, IPs, applications, environments and exclusions.
Hours and constraints are defined.
Permitted actions, prohibited actions and emergency procedures are agreed.
No test is started without explicit validation of the scope and intervention rules.
Method
Every pentest follows a structured method — from scoping to retest — so the engagement stays authorised, readable and actionable.
Hover or select a step to see the details.
Scope, objectives, rules, exclusions.
Identification of the elements in scope.
Search for and rating of vulnerabilities.
Validation of their exploitability within the agreed limits.
Technical and business rating.
Return of the environment to the agreed state.
Findings, evidence, severity and recommendations.
Presentation to the teams.
Verification of fixes if planned. See the retest.
01 Scoping
Scope, objectives, rules, exclusions.
Vulnerability classification
Critical
Exploitation likely to generate a major impact.
High
Significant risk requiring priority remediation.
Medium
A real weakness whose context reduces the impact or ease of exploitation.
Low
Recommended improvement or hardening.
The final level is not based on a technical score alone: we also take exposure and business impact into account.
Pentest report
A deliverable readable by leadership and actionable by IT: summary, vulnerability sheets and remediation roadmap.
Pentest report — anonymised example
Vulnerability sheet
Fictitious, anonymised example intended to illustrate the structure of the deliverable. It does not describe any exploitation technique.
Configurator
Your pentest
Application pentest
Indicative estimate. The final quote depends on the technical scope and rules of engagement.
Who is it for?
Pentesting is no longer reserved for large enterprises. Any connected system is a potential target — better to test it before an attacker does.
Your web applications and APIs are exposed 24/7 — an OWASP application pentest identifies flaws before your users or malicious bots do.
A new application, API or portal: an application pentest secures the product itself, not only the infrastructure around it.
Medical, financial or personal data — a pentest shows clients and partners that this data is actively protected.
A pentest can support risk management, technical controls and preparation for an ISO 27001 programme. It is not an ISO certification.
Very common in B2B: a client, buyer or partner asks for a pentest report to validate your security level.
New application, API, portal or infrastructure: the pentest is the last check before opening the service.
Migration, rebuild, cloud, architecture change: a pentest checks that the new attack surface has not introduced flaws.
Retest
The retest targets previously identified vulnerabilities to verify that the implemented fixes are effective.
Optional
The retest is not included in the indicative price. You can add it at scoping — it is then billed separately.
Optional
Same approach as application testing : the retest is optional and billed separately, based on the findings to recheck.
Included
The retest is included in the engagement, together with 3-month remediation follow-up.
Our pricing
The price of a penetration test depends primarily on the scope to be tested, not solely on the size of the company.
Application pentest
€2,900 – 5,500 excl. VAT
1 to 3 web applications / APIs
Retest Optional — billed separately
Request a quoteInfrastructure pentest
€3,900 – 7,500 excl. VAT
Network, servers, cloud, VPN
Retest Optional — billed separately
Request a quoteFull pentest (app + infra)
€6,500 – 12,000 excl. VAT
Full IT, sensitive sector
Retest Included
Request a quoteIndicative pricing — a tailored quote is provided within 24 hours based on your exact scope. The retest is included in the full pentest; on the application and infrastructure offers, it is optional and billed separately.
What determines the price
The price of a penetration test is calculated from the actual scope — not a single flat fee. Cost depends in particular on these elements, confirmed during the first discussion.
Timeline
A few days.
About one to two weeks, depending on preparation and depth.
Specific scheduling.
Scoping and access to environments strongly determine the timeline.
A pentest is an offensive security test performed within an authorised framework. It follows an attacker-like logic to check whether vulnerabilities on an application, network or infrastructure can actually be exploited. See the definition.
Pentest is short for penetration testing. It is the same service. See the definition.
There is no fundamental difference: pentest is the English abbreviation of penetration testing. Both names refer to the same engagement. See the definition.
A cybersecurity audit gives a global view of the IT landscape: architecture, configuration, processes and governance. A pentest is a targeted offensive test, on a defined scope, to assess whether vulnerabilities are exploitable. An audit may come before a pentest; they are not the same service. See the comparison.
A scan mainly detects potential weaknesses, often automatically. A pentest seeks to determine what is actually exploitable and what the impact would be. A scan is not a substitute for a pentest. See the comparison.
An external pentest assesses your Internet-facing surface: what an attacker can reach without prior access to your internal network, including exposed services, remote access, VPN and public interfaces. See external pentest.
An internal pentest simulates an attacker already present on the network. It assesses segmentation, privileges, accounts and possible movement between environments. See internal pentest.
A web pentest, or web application pentest, covers your applications and interfaces: authentication, sessions, authorisation, user input, application logic and APIs. Testing is built around the main application risk families recognised by OWASP. See web pentest.
In a black box pentest, the tester has very little initial information. The approach is close to an external attacker scenario. See test approaches.
Black box: little initial information. Grey box: some information or access is provided to go deeper. White box: the tester has more complete technical information. The mode is chosen according to the objective, budget and desired depth. See test approaches.
This is decided according to the scope and rules of engagement. Neither a systematic yes nor a systematic no: scoping sets the environment, the testing window and authorised actions. No test starts without explicit validation. See the authorised framework.
The price of a pentest depends primarily on the scope to be tested, not solely on the size of the company. As a guide: application pentest €2,900–5,500 excl. VAT, infrastructure pentest €3,900–7,500 excl. VAT, full pentest €6,500–12,000 excl. VAT. See pricing.
The price of a penetration test is the price of a pentest: it is the same service. It is calculated from the scope (applications, APIs, IPs, test type, retest), with indicative ranges from €2,900 to €12,000 excl. VAT depending on the pack. See the price factors.
There is no universal rule. A small scope takes a few days. A standard application or infrastructure takes about one to two weeks, depending on preparation and depth. A complex scope requires specific scheduling. Scoping and access to environments strongly determine the timeline. See indicative timelines.
A deliverable that leadership can read and IT can act on: an executive summary, vulnerability sheets and a remediation roadmap. See the report example.
A retest targets previously identified vulnerabilities to verify that the implemented fixes are effective. It is included in the full pentest; on the application and infrastructure offers, it is optional and billed separately. See the retest.
A pentest is a structured engagement with a defined scope, carried out by a commissioned team within a limited timeframe. A bug bounty is an ongoing programme open to a community of security researchers. Both can be complementary, but they do not meet exactly the same need. See the comparison.
Only within a framework that is explicitly authorised and defined with the organisation: authorised campaign, defined population and rules of engagement. See the phishing test.
Our certified pentesters test your defences and deliver a complete report with proof of exploitation. First conversation free, confidential, no commitment.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.