Skip to content

Expert-led service

Penetration testing by people who explain what they found.

A BugSnaps penetration test is a scoped, manual attempt to break your application, API or network the way an attacker would — then a clear account of what worked, how bad it is, and how to fix it.

What we test

Scope, agreed in writing.

  • Web applications

    Authentication, authorization, input handling, sessions and business logic.

  • APIs

    Object- and function-level authorization, data exposure, rate limiting, GraphQL.

  • Networks

    External exposure, internal segmentation, services and configuration.

  • Cloud and code

    Configuration and identity review, and security-focused code review, on request.

How we work

Methodical, and never destructive without agreement.

  1. 01Scope it together — a free call, then a fixed quote and rules of engagement in writing.
  2. 02Reconnaissance and mapping, including the attack surface nobody remembered existed.
  3. 03Manual testing mapped to OWASP WSTG and PTES, with automation for coverage, not conclusions.
  4. 04Critical issues reported the same day we confirm them.
  5. 05Report and walkthrough: plain language for decisions, reproduction steps and fixes for engineers.
  6. 06Fix and retest until every issue is confirmed closed.

What you receive

  • Technical report with reproduction steps and CVSS severity
  • Executive summary you can share with customers and auditors
  • Walkthrough call with the testers
  • Retest and written confirmation of fixes

Manual testing or MyPentest?

MyPentest is a good fit for continuous coverage between engagements: every release, every new subdomain.

Bring in a manual test for business logic, chained attack paths, compliance evidence, or anything with real money or data at stake.

Automated vs manual penetration testing

FAQ

Questions, answered straight.

How long does an engagement take?

Most engagements run 5–12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.

Will testing affect production?

Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.

Is retesting included?

Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.

How is this different from an automated scan?

Scanners find known patterns. A tester chains issues, abuses business logic and judges what actually matters to your company. Tools assist with coverage, but every finding in a BugSnaps report is verified and rated by a person.

Can the report be shared with customers and auditors?

Yes. Alongside the technical report you receive an executive summary suitable for customer security reviews, SOC 2 and ISO 27001 audits, and vendor questionnaires.

Talk to a tester, not a sales team.

A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.