Penetration Test Packages

At Oneleet, we offer 3 different types of penetration test packages.

FeatureComplianceComprehensiveCustom
DescriptionA high-level assessment of your application, evaluating the effectiveness of your security measures.A penetration test that examines all aspects of your application’s attack surface to identify vulnerabilities across all categories.A penetration test that examines all aspects of your application’s attack surface to identify vulnerabilities across all categories.
TargetWeb Applications
Mobile Applications
APIs
Web Applications
Mobile Applications
APIs
Networks
Cloud Assessmentss
Secure Code Reviews
Social Engineering
Web Applications
Mobile Applications
APIs
Networks
Cloud Assessmentss
Secure Code Reviews
Social Engineering
Red Teaming
IoT Devices
Use casesVulnerability testing of existing & new features. Often sufficient for early-stage companies going through SOC 2Vulnerability testing of existing & new features. Microservices testing. Testing based on several OWASP frameworksCompanies with multiple applications, red teaming, etc.
TestersManual test with a penetration tester that is at minimum OSCP & OSCE/OSWE certifiedManual test with a penetration tester that is at minimum OSCP & OSCE/OSWE certifiedManual test with a penetration tester that is at minimum OSCE/OSWE certified
Customizable ReportNot IncludedIncludedIncluded
SupportAnswer within 48HDedicated point of contact that answers within 24HDedicated point of contact that answers within 24H
Free Retesting12 months12 months12 months
Rush deliveryOptionalOptionalIncluded
Letter of EngagementIncludedIncludedIncluded
Letter of AttestationIncludedIncludedIncluded
Customized LettersNot includedIncludedIncluded
Onboarding SupportSlackSlack & LiveSlack & Live
Dedicated Customer Success ManagerNot includedIncludedIncluded
Used StandardsPentest conducted in accordance with industry-standard methodologies such as OWASP Top-10Pentest conducted in accordance with industry-standard methodologies such as OWASP WSTG, OWASP ASVS, etc.Pentest conducted in accordance with industry-standard methodologies such as OWASP WSTG, OWASP ASVS, etc.