Penetration testing services: find the gaps before attackers do
We specialise in professional penetration testing and IT security audits. We identify vulnerabilities in your infrastructure, applications and networks before cybercriminals exploit them. Every pentest is performed manually by OSCP- and OSWE-certified testers, and you receive a report with proof of exploitation and CVSS scores.
- 1000+Pentests completed
- 24hFirst vulnerabilities in the platform
- 30 daysRetest included after the report
- OSCPOSWE · OSEP · OSCE³ – our testers’ certifications
- 443/tcp https · 8443/tcp https-alt · 22/tcp ssh
- /admin 302 · /api/v2 200 · /backup.zip 200
- CriticalIDOR: other customers’ invoices via /api/invoices/{id}
- HighNo login rate limiting on /login
- MediumIncomplete CSP and HSTS headers
- LowServer version disclosed in headers
- 14findings
- 3critical and high
- 24hto first alert
Our certifications
Tests are performed by penetration testers holding Offensive Security and eLearnSecurity certifications: OSCP, OSWE, OSEP, OSED, OSCE³, OSWP, eWPTX, eCPPT, KLCP, alongside ISO 27001 auditors.
What is penetration testing?
Penetration testing (pentest) is a controlled simulation of hacker attacks aimed at identifying weaknesses in IT system security. We act as ethical hackers: using the same techniques as cybercriminals, but in a legal and controlled manner, delivering a detailed report with remediation recommendations.
Below you will find the types of tests we run, the black, grey and white box methods, the step-by-step process, indicative pricing and what the report contains. If you are planning your first pentest, start with the scope and pricing sections and then book a free scoping call.
- 83%of companies experienced a cyberattack in 2024
- USD 4.45Maverage cost of a data breach
- Vulnerability detection before an attack
- Compliance with GDPR, PCI DSS, ISO 27001
- Detailed report with recommendations
- Protection of reputation and client data
Types of penetration testing: web, API, mobile, desktop, infrastructure, cloud, Wi-Fi, AI/LLM
We offer comprehensive penetration testing services tailored to your IT infrastructure. Each type of test has its own methodology, scope and price range.
WEB / API
Web application penetration testing
We offer professional web application testing using Black Box and Grey Box methods. Our approach enables a comprehensive security assessment of applications, both from the perspective of an external attacker and a partially informed internal user. Tests are conducted in accordance with the Penetration Testing Execution Standard (PTES) methodology.
The result of the tests is a detailed electronic report that includes:
- Description of discovered security vulnerabilities
- Evidence confirming their existence
- Guidance on remediating identified issues
- Analysis of potential consequences of exploiting discovered vulnerabilities
During testing, we use a methodology based on best practices described in the OWASP Testing Guide, as well as the OWASP Top 10, OWASP Web Security Testing Guide and ASVS methodologies.
API penetration testing
We perform API penetration testing using Black Box and Grey Box models, focusing on the security of communication between system components, data integrity, and the proper implementation of authentication and authorisation mechanisms.
We apply the PTES methodology and best practices from the OWASP API Security Top 10, OWASP ASVS and Web Security Testing Guide. Upon completion of testing, you will receive a comprehensive technical and business report containing:
- Description of all discovered vulnerabilities
- Evidence confirming their occurrence (requests, responses, screenshots)
- Analysis of impact on data confidentiality, integrity and availability
- Technical and organisational recommendations to enhance API security
- Remediation action priorities based on business impact
Mobile applications
Mobile application penetration testing involves controlled, ethical attack simulations on applications installed on Android and iOS devices, aimed at discovering real security vulnerabilities before cybercriminals do.
iOS penetration testing
We perform iOS application penetration testing using Black Box, Grey Box and White Box models. We analyse data storage methods on the device, API server communication security, certificate integrity, and protection mechanisms against application modification or reverse engineering (tampering). We also test application resistance to jailbreak detection bypass, unauthorised access to Keychain keys, and incorrect implementations of cryptographic mechanisms.
Android penetration testing
We conduct Android mobile application testing using Black Box, Grey Box and White Box models, focusing on code security analysis, environment configuration, and application resistance to attacks in real-world scenarios. We examine, among others: data storage security in device memory, API server communication, protection against decompilation and APK file modification, correct cert pinning implementation, and resistance to hooking techniques (e.g. Frida, Xposed).
We conduct tests in accordance with recognised standards:
- OWASP Top 10 Mobile Risks
- OWASP Mobile Application Security Testing Guide (MASTG)
- OWASP Mobile Application Security Verification Standard (MASVS)
Thick client (desktop)
Our tests include both manual and automated verification of various vulnerability classes in desktop applications. Applications undergo both static and dynamic analysis.
Testing methods
- Fuzzing and dynamic testing
- Network component and API analysis
- Injections
- Cryptography security verification
- Testing components stored on the operating system
- Analysis of logs and data stored by the application
- Process and memory monitoring
- Registry key review
- Reverse engineering and static analysis
Analysed areas
- Application architecture
- Data storage and cryptography usage
- Authentication and session management mechanisms
- Application network communication
- Application interaction with the operating system
- Protections against reverse engineering
IT infrastructure
During infrastructure tests, we conduct comprehensive analyses of all devices in the subnet to identify vulnerabilities and configuration errors that could enable taking control of tested hosts. One of the goals of these tests is to determine the visibility of hosts and services that could be targeted by attackers both physically present on the network and attacking remotely.
Infrastructure tests aim to verify the security of services and systems accessible to both Internet (external) and LAN (internal) network users. We apply an approach based on industry best practices such as OSSTMM and PTES.
Steps performed during testing
- Identification of exposed TCP and UDP services
- Identification of weaknesses in discovered services
- Attempts to exploit identified vulnerabilities
- Verification of identified vulnerabilities
Cloud (AWS/Azure/GCP)
Cloud penetration testing involves detailed analysis of configurations, security policies and access rules, using specialised tools and techniques to identify weaknesses in cloud infrastructure.
VIPentest applies individually tailored testing methodologies to effectively analyse and secure cloud environments, taking into account their unique architecture and threat models. Our cloud environment penetration tests cover Azure, AWS and GCP platforms, providing a comprehensive security assessment of your cloud infrastructure.
WiFi networks
During our wireless network penetration tests, we determine the security types (Open, WEP, WPA, WPA2, WPA3 Personal or Enterprise) and authentication mechanisms used by your organisation.
Attack techniques used
- Encryption attacks: including dictionary and brute-force attacks, exploiting WEP weaknesses, improper WPA2 configuration and weak passwords
- Machine-in-the-Middle attacks: including Rogue Access Points and Evil Twins
- Denial of Service (DoS) attacks: disrupting wireless communication, such as flooding
AI / LLM Security
Specialised security testing of applications utilising artificial intelligence and large language models (LLM). We verify the resilience of AI systems against real attack vectors, including input manipulation, data leaks and security mechanism bypasses.
Tested areas
- Prompt Injection (direct & indirect): injecting malicious instructions into the model
- Jailbreaking: bypassing LLM restrictions and security policies
- Training data leaks (PII leakage): extracting confidential information from the model
- Output manipulation: forcing incorrect or harmful responses
- RAG Poisoning: attacks on Retrieval-Augmented Generation systems
- Insecure Plugin/Tool Use: abusing tools connected to the LLM
- Model Denial of Service: exhausting resources and blocking availability
We conduct tests in accordance with the OWASP Top 10 for LLM Applications and our own methodologies developed on the basis of the latest research in adversarial AI.
People and processes: social engineering, red team
A pentest checks the technology. To assess the resilience of the whole organisation, we complement it with social engineering testing (phishing campaigns, vishing, smishing) and a red team assessment that tests detection and response, in which we simulate a multi-week attack and check whether your team and SOC detect and stop it.
A phishing campaign for up to 500 people takes 2–4 weeks, and a full TLPT cycle with Threat Intelligence takes 8–16 weeks. We combine the results of social engineering tests with those of technical tests so that management sees the full risk picture: technology, people and processes.
- Phishing simulations and other attacks on employees
- Red team operations mapped to MITRE ATT&CK
- TLPT for the financial sector (DORA / TIBER-EU)
Testing methods: black box, grey box and white box
Choose an approach tailored to your needs and level of access to system information. Black box, grey box and white box penetration tests differ in how much the tester knows at the start.
Black Box
Simulation of an external hacker attack. The tester has no knowledge of the tested system: they start from scratch, just like a real attacker.
Grey Box
Optimal balance of time and effectiveness. The tester has partial knowledge of the system, e.g. API documentation or a test account.
White Box
The most thorough analysis. The tester has full access to source code, architecture documentation and system configuration.
Methodology: OWASP, PTES, OSSTMM, NIST and MASVS
We conduct our penetration tests in accordance with international IT security standards and methodologies.
OWASP
Open Web Application Security Project: the web application and API security standard (Web Security Testing Guide, Top 10, ASVS).
PTES
Penetration Testing Execution Standard: a comprehensive pentest methodology, from scoping to reporting.
OSSTMM
Open Source Security Testing Methodology Manual: a security testing methodology for infrastructure and networks.
NIST CSF
National Institute of Standards and Technology: the Cybersecurity Framework for managing cyber risk.
MASTG / MASVS
OWASP Mobile Application Security: the testing standard for iOS and Android mobile applications.
OWASP LLM Top 10
Security standard for AI applications and large language models: prompt injection, data leaks, RAG poisoning.
Penetration testing for NIS2, DORA, ISO 27001, PCI DSS, HIPAA and GDPR
We help meet the requirements of key IT industry regulations and standards. The test report includes a description of scope and methodology written for your auditor or regulator.
HIPAA
Protection of medical data and patient health information.
DORA
Digital Operational Resilience Act: digital resilience of the EU financial sector, including TLPT.
NIS2
EU Directive on network and information systems: cybersecurity of essential and important entities.
PCI-DSS
Payment Card Industry Data Security Standard: payment data security.
ISO 27001
International standard for information security management (ISMS).
NIST
National Institute of Standards cybersecurity and risk management framework.
GDPR
General Data Protection Regulation: compliance with EU data protection laws.
KNF / UKNF
Polish Financial Supervision Authority recommendations on IT security.
Penetration testing process step by step
Every test follows the same process, whether it covers a single application or your entire infrastructure. You know what is happening at each stage and how long it will take.
- 01
Scoping call
We agree what is to be tested, in which model (black, grey or white box), in which environment and when. After the call you receive a quote with a specific number of days and a fixed price, not a “from”.
- 02
Formalities
Contract and NDA signed electronically, plus the rules of engagement: time window, your point of contact, and the escalation path if we find a critical vulnerability.
- 03
Reconnaissance and threat modelling
We map the application or network, identify technologies, user roles and entry points. We establish what the worst-case scenario would be for your business and start there.
- 04
Manual testing
An OSCP- or OSWE-certified pentester manually verifies every vulnerability class from OWASP, PTES and OSSTMM. Scanners are only a supporting tool. You see each vulnerability in the vulnerability management platform on the day it is found; critical ones we also report by phone.
- 05
Report
An executive summary for management, a list of vulnerabilities with CVSS scores, step-by-step proof of exploitation and recommendations in order of implementation. We walk your team through it in a debriefing meeting.
- 06
Retest
Once you have deployed the fixes, you mark them in the platform with one click, we verify that the vulnerabilities are really gone and issue a final report with a certificate for your client, auditor or regulator.
Penetration testing cost: what drives the price
The price depends on three factors: the size of the scope (number of features, endpoints or hosts), the number of user roles that must be tested separately, and the testing model. White box with access to source code is more thorough but takes more time. Below are indicative net price ranges; you receive an exact price after a 30-minute scoping call.
| Scope | Variant | Net price | Duration |
|---|---|---|---|
| Web application or API | unauthenticated (black box) | from PLN 6,000 | 3–4 days |
| Web application or API | 1 user role (grey box) | PLN 9,999–15,000 | 5–7 days |
| Web application or API | 2–3 roles, admin panel | PLN 14,000–22,000 | 7–10 days |
| Web application or API | 4+ roles, many modules, integrations (white box) | from PLN 22,000 | from 10 days |
| Mobile application | one platform, 1 role, backend in scope | PLN 9,999–14,000 | 5–7 days |
| Mobile application (iOS + Android) | both platforms, 1 role | PLN 14,000–20,000 | 7–10 days |
| Mobile application (iOS + Android) | multiple roles, payments or medical data | from PLN 18,000 | from 10 days |
| External infrastructure | up to 25 IP addresses | from PLN 6,000 | 3–5 days |
| Internal infrastructure + Active Directory | up to 250 hosts, 1 domain | PLN 15,000–30,000 | 7–12 days |
| Internal infrastructure + Active Directory | over 250 hosts, multiple domains or sites | from PLN 30,000 | from 12 days |
| Social engineering | phishing campaign, up to 500 people | PLN 9,999–16,000 | 2–4 weeks |
| TLPT (DORA / TIBER-EU) | full cycle with Threat Intelligence | from PLN 172,000 | 8–16 weeks |
The ranges apply to typical scopes. The price grows with size: the number of screens and endpoints, roles, hosts, domains and environments. Large applications, multiple environments or distributed networks are quoted individually after a scoping call. All prices are net amounts in PLN.
Included in the price: the report in two versions (executive and technical), a debriefing meeting, a retest within 30 days and a certificate after the retest, and access to the vulnerability management platform. Quoted separately: testing in production outside business hours, more than one environment, and on-site work at your premises.
What you get in the report
A VIPentest penetration test report has two parts, because two different audiences read it: management and the technical team.
Executive summary
2–3 pages: overall security level, number of vulnerabilities by severity, the three most important business risks and the recommended order of action. No jargon, ready to show to the board or a client.
Technical section
Every vulnerability with a CVSS 3.1 score, impact description, proof of exploitation (screenshots, requests, code), exact location and a remediation recommendation referencing OWASP and CWE.
Scope and methodology description
What was tested, in which model, with which tools, what was excluded and why. This is the part your ISO 27001, NIS2 or DORA auditor needs.
Retest report and certificate
A table: vulnerability, status after the fix, verification date. Plus a certificate of testing you can share with business partners. Access to the vulnerability management platform remains after the project ends.
Visibility from day one: the vulnerability management platform
Most companies learn the results of a test from a PDF after it is over. With us, every client gets access to the VIPentest vulnerability management platform for the duration of the test and beyond.
Live test progress
You see what stage the team is at, what has been tested, what remains and whether we are on schedule.
Vulnerabilities during the test, not after
Every finding appears in the platform on the day it is discovered, with a CVSS score, evidence and a recommendation. Your development team can start fixing before the test is over.
Fix reporting and retest
Once a fix is deployed, you mark the vulnerability as remediated, we verify it and close it. The history of every vulnerability is preserved.
Report and certificate in one place
You download them from the platform as soon as they are ready. Access does not expire when the project ends.
How to prepare your company for a penetration test
Good preparation shortens the test by a day or two and increases its value. Before we start, we need six things from you.
Purpose of the test
A regulatory requirement, a client’s demand, a new release or a general security assessment. The purpose determines the model and scope.
List of what we are testing
Addresses, application names, repositories (for white box), IP ranges.
Environment
Test, pre-production or production. Production requires a time window and the owner’s consent.
Test accounts
One for each user role, with data that can be safely modified.
Provider consents
If the application is hosted in the cloud or with a hosting provider, some of them require advance notice of the test.
Point of contact and escalation path
Who picks up the phone when we find a critical vulnerability at 11 pm.
Who penetration testing services are for
Penetration tests are ordered by organisations that process customer data, are subject to regulation, or need to show a business partner proof of security. Most often we work with:
Software houses and SaaS
The end client requires a test report before go-live or in the contract. We test the web application, API and mobile apps before release, and the retest confirms the fixes. See penetration testing for software houses.
E-commerce and fintech
Payments, card data and user accounts: a scope aligned with PCI DSS and KNF recommendations. We check the basket, payments, customer panel and integrations with payment providers. See penetration testing for banking and fintech.
Banks and insurers
Financial entities covered by DORA and KNF supervision: regular tests of critical systems, and for the largest institutions TLPT in line with TIBER-EU.
Healthcare
Systems holding patient medical data: HIPAA and GDPR requirements, tests of applications, patient portals and the facility’s infrastructure.
Essential and important entities under NIS2
Energy, transport, manufacturing, public administration and their suppliers: infrastructure and application tests as part of the risk management required by NIS2.
Companies facing an audit or a client questionnaire
ISO 27001 certification, an internal audit or a security questionnaire from a business partner: the test report and certificate close the “penetration testing” item without further questions. If the questionnaire also asks about hardening, we complement the pentest with a security configuration audit against CIS benchmarks or a compliance audit for NIS2, DORA and ISO 27001.
Frequently asked questions about penetration testing
Find answers to the most common questions about penetration testing.
How long does a penetration test take?
The duration of penetration testing depends on the scope and complexity of the tested system. A typical web application pentest takes 3 to 10 business days, depending on the number of roles and modules. An external infrastructure test takes 3–5 days, an internal network with Active Directory 7–12 days, and a comprehensive IT infrastructure security audit may require 2 to 4 weeks. Add 2–3 days for the report. After an initial analysis, we prepare a detailed schedule tailored to your needs.
Can penetration testing disrupt system operations?
Professional penetration tests are conducted in a controlled and safe manner. Before starting pentests, we sign an agreement defining the scope of activities, time windows and security procedures. We do not run denial-of-service attacks without explicit consent, and we agree risky operations with your point of contact as we go. We can perform tests on a staging environment or during low-traffic hours, minimising the risk of impact on production, and in production we work on test accounts and data that can be modified.
What will I receive after the tests are completed?
You will receive a detailed report containing: an executive summary for management, a full list of discovered vulnerabilities with risk assessment according to CVSS 3.1, a technical description of each vulnerability with exploitation evidence (Proof of Concept), prioritised remediation recommendations, and support throughout the remediation process. After the retest we add a final report and a certificate of testing, and you download both from the vulnerability management platform.
How often should penetration tests be conducted?
We recommend conducting penetration tests at least once a year and after every significant change in IT infrastructure or application update. Regulated industries (finance, healthcare, e-commerce) often require more frequent audits: PCI DSS requires pentests quarterly or after every significant change, and DORA and KNF recommendations assume regular testing of critical systems. A retest within 30 days of the report confirms that the fixes actually worked.
How much does penetration testing cost?
The cost of penetration testing depends on many factors: test scope, system complexity, chosen methodology (Black/Grey/White Box) and delivery timeline. A black box test of a web application or API starts from PLN 6,000 net, a grey box test with one user role costs PLN 9,999–15,000, external infrastructure of up to 25 addresses from PLN 6,000, and an internal network with Active Directory PLN 15,000–30,000. We prepare individual quotes after a free consultation and project scope analysis. Contact us to receive an offer tailored to your needs.
What is the difference between a penetration test and a vulnerability scan?
A scanner compares software versions against a database of known bugs and produces a list of “possible” issues, some of which do not exist. A penetration test is the work of a person who actually tries to exploit vulnerabilities, chains them into attack scenarios and shows the real impact on the business. A scan is one element of a test, not a substitute for it. In a pentest report every vulnerability has proof of exploitation, a CVSS score and a remediation recommendation, not just a CVE number.
Do you test the production environment or a staging copy?
Both, depending on the situation. We prefer a pre-production environment identical to production, because it allows testing without restrictions. We test production when there is no test environment or when the client wants to verify the real configuration. In that case we agree a time window, exclude load testing and work on test accounts. If the application is hosted in the cloud or with a hosting provider, some providers require advance notice of the test, which we help you arrange.
Is a retest after remediation included in the price?
Yes. One retest performed within 30 days of delivering the report is part of the service. Once you have deployed the fixes, you mark them in the vulnerability management platform with one click, and we check whether the vulnerabilities are really gone. After the retest we issue a final report with a table (vulnerability, status after the fix, verification date) and a certificate of testing for your client, auditor or regulator.
Can I follow the test while it is in progress?
Yes. You get access to the VIPentest vulnerability management platform, where you see the progress of the test and the vulnerabilities found on the day of discovery, with a CVSS score, evidence and a recommendation, and after remediation you submit them for a retest with one click. We additionally report critical vulnerabilities by phone. You download the report and certificate from the same platform, and access remains after the project ends.
Which type of penetration test should we start with?
If your company has not been tested before, we usually start with what is exposed to the internet: the web application or API in a grey box model with one user role, plus the external infrastructure. These are the scopes an attacker checks first, and their test fits within 3–7 days. The internal network with Active Directory, mobile applications and social engineering tests are added in subsequent cycles, and organisations with a working SOC consider red team operations.
Do penetration tests also cover cloud, Wi-Fi and AI systems?
Yes. Beyond web applications, mobile apps, APIs and infrastructure, we test AWS, Azure and GCP cloud environments (configuration, security policies, IAM access rules), wireless networks (WPA2/WPA3, 802.1X, Rogue AP and Evil Twin attacks) and applications built on large language models according to the OWASP Top 10 for LLM Applications: prompt injection, jailbreaking, data leaks, RAG poisoning. Each of these scopes is quoted separately after a conversation about the architecture.
Will I receive a certificate for a client or auditor after the test?
Yes. After the retest we issue a final report and a certificate of penetration testing that you can share with business partners, your ISO 27001 auditor or a regulator under NIS2, DORA or KNF recommendations. The certificate confirms that the test was performed and states its result after the retest. The scope and methodology description in the report is written so that an auditor can use it without further questions. You download the report and certificate from the vulnerability management platform.
Ready to secure your infrastructure?
Contact us and receive a free consultation. Our certified experts will help you choose the optimal scope of penetration testing for your organisation.
- Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
- Scoping call under NDAWe agree on goals, environment, dates and access.
- Quote and test planUsually the same day after the call. No commitment.
- Retest within 30 days included
- Vulnerability management platform
Write to us: free quote and scoping consultation
Briefly describe what you want to test. We reply within one business day.

