Continuous testing
Scheduled cycles and on-demand tests for every release, migration or relevant change.
Findings in real time
Every vulnerability appears in DARKFORGE as soon as it is confirmed, with evidence and a recommendation.
Unlimited retesting
We verify every fix when your team has it ready, as many times as necessary.
Predictable cost
A fixed monthly fee and a scope reviewed every quarter, with no project-by-project quotes.
One-off pentesting versus PTaaS
What changes when testing never stops.
How it works
A quick start, a clear baseline and, from there, a cycle that never stops.
Onboarding
We define the scope, assets, time windows and rules of engagement. We set up your space in DARKFORGE and, if there is internal scope, connect the probe.
Baseline pentest
A full pentest of the whole scope to set the baseline: asset inventory, initial findings and the first Cyber Security Risk Meter value.
Continuous cycles
Tests scheduled according to the plan, continuous attack surface discovery in TORO and on-demand tests for every relevant change.
Retest and follow-up
Every fix is verified when your team has it ready, with no limit on the number of times. The status of each finding is updated in the portal.
Quarterly review
Executive report, meeting with management and scope adjustment: new assets come in and those that no longer exist go out.
Annual closure
Annual report with the full evolution, comparison against the baseline and a plan for the next year.
What can be included in the scope, defined at onboarding and reviewed every quarter:
Three plans, one common base
All include the initial pentest, the DARKFORGE portal, unlimited retesting and notification of critical findings in under 24 hours. The difference lies in the cadence and the services included.
- External pentest cyclesEvery six months
- Attack surface in TOROMonthly
- On-demand tests2 per year
- Internal pentest with probe—
- Phishing simulation—
- Cloud and Microsoft 365 audit—
- Source code review—
- Executive reportEvery six months
- Follow-up meetingQuarterly
- External pentest cyclesQuarterly
- Attack surface in TOROWeekly
- On-demand tests6 per year
- Internal pentest with probeAnnual
- Phishing simulationEvery six months
- Cloud and Microsoft 365 auditAnnual
- Source code review—
- Executive reportQuarterly
- Follow-up meetingMonthly
- External pentest cyclesMonthly
- Attack surface in TOROWeekly
- On-demand testsUnlimited*
- Internal pentest with probeEvery six months
- Phishing simulationQuarterly
- Cloud and Microsoft 365 auditEvery six months
- Source code reviewPer major release
- Executive reportMonthly
- Follow-up meetingFortnightly
* Within the contracted scope and with prior planning. All plans are annual subscriptions billed monthly or quarterly; the scope is reviewed every quarter and changes are reflected in the fee for the following period.
Service commitments
What you can hold us to by contract, in every plan.
Critical findings
Notification from confirmation: portal, email and a call to the designated contact.
High findings
Notification with evidence and a provisional recommendation.
Retest
Started within five business days of the request in the portal.
On-demand tests
Scheduled within ten business days of the request.
Queries
A reply from the technical contact assigned to your account.
Reports
Executive report within the first ten days of the following period; annual report in month 12.
Pausing the tests
You can stop any test in progress with a simple notice, with no penalty.
Exportable evidence
Every finding and every report can be exported as control evidence or into your ticketing system.
What you will see every month
The periodic report and the DARKFORGE and TORO dashboards answer the same question from two angles: are we better than last month, and where are we not?
Frequently asked questions
Yes. The baseline pentest is equivalent to a full pentest and the subsequent cycles keep that coverage alive. The annual report documents the whole year.
You request an on-demand test from the portal or through the direct channel. It is scheduled within the committed timeframe and the results are added to the history.
Yes. Every finding keeps its evidence, dates, owner and status, and both reports and individual findings can be exported in PDF and Word as control evidence or into your ticketing system.
Yes, at every quarterly review. Changes are reflected in the fee for the following period.
The same as in any pentest: agreed time windows, no denial of service, an emergency contact and the option to pause testing at any time.
We use it as the baseline: we import its findings into DARKFORGE and the service starts directly with the continuous cycles and retesting.
A stable team assigned to your account, with a fixed technical contact. The same analysts cycle after cycle, so knowledge of the environment is never lost.
They are created specifically for the service, stored encrypted and revoked at the end of each cycle. Real user credentials are never reused.
Getting started with PTaaS
Scoping session
A 60-minute meeting to inventory assets, understand your pace of change and choose the plan.
Proposal with plan and fee
Detailed scope, first-year calendar and a fixed monthly fee, with no surprises.
Onboarding in two weeks
Set-up in DARKFORGE, signed rules of engagement and start of the baseline pentest.
What can be included in the scope.
The scope is defined at onboarding and reviewed every quarter. It can combine any of these assets and, therefore, any of our services.