What is penetration testing as a service?
Penetration testing as a service (PTaaS) combines an always-on testing platform with on-demand human testers. Instead of a single point-in-time test once a year, you get continuous coverage plus deep manual engagements when you need them - for a release, an audit, or a customer request.
How is AI penetration testing different from traditional pentesting?
AI penetration testing automates discovery and continuous coverage across web apps and APIs at machine speed, surfacing common and regression issues fast. Traditional manual testing is where a human finds business-logic flaws and chained exploits that automation can't reason about. Intrudify runs both, so you don't have to choose.
Do you provide a pentest report for SOC 2, ISO 27001 or NIS2?
Yes. Every engagement produces an audit-ready pentest report with control mapping and remediation guidance that SOC 2, ISO 27001, NIS2 and DORA auditors accept. The same report works across frameworks, so you test once and satisfy multiple obligations.
How much does a penetration test cost?
Every penetration test is scoped to the number of apps and APIs and the depth required, then quoted as a single fixed price - no open-ended day rates. We scope in 45 minutes and send the quote, so you know the full cost before any testing starts.
How long does a penetration test take?
We scope within a week and stream the first findings inside 48 hours. A Standard engagement delivers an audit-ready report in under 24 hours of testing; deeper engagements run longer, and a re-test window to validate your fixes is included.
Automated vs manual penetration testing - which do I need?
Automated testing is best for broad, continuous coverage between audits. Manual testing is essential for business-logic vulnerabilities and named compliance reports. Most teams under audit need both, which is exactly what a single Intrudify engagement provides.
What can Intrudify test?
Intrudify is focused on web application and API penetration testing - it maps every endpoint, parameter and authentication flow, including SPA, MFA, OAuth and SAML. It is not a network, infrastructure or VM scanner; the scope is deliberately web and API.