Penetration testing for customer security reviews
When a customer’s security review asks for a recent third-party pen test, we test what they’re asking about and give you a letter to share.
Last reviewed October 2026
What your customer will want to see
When a customer’s security review asks about testing, it may want:
- A test within the window they name
- An independent testing firm
- The scope, matched to the product they buy
- Fix status for critical and high findings
After your retest, the attestation letter covers all four without exposing your full report. It states the test dates, scope, method, and results, and shows the retest status.
Tests to consider
- Web applications The product your customer buys, tested with two accounts for every user role.
- APIs The API your customer integrates with, or the one behind your app.
- Networks and Active Directory Your internet-facing systems, if the review asks about your perimeter.
- Cloud (AWS, Azure, Google Cloud) The cloud accounts that hold your customer’s data.
- Mobile apps Your iOS and Android apps, if your customer’s users rely on them.
- AI and LLM applications AI features that touch customer data, such as chat assistants and agents.
- Code review and threat modeling Design and code review, if the review asks how you build securely.
Working back from your deal
- Send us their request. Share the questionnaire section or email that asks about testing, and we’ll scope the test to match it.
- A free scoping call, then a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
- Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends. Send your customer the attestation letter, and we walk your team through the findings on a call.
- Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and a letter that shows the retest status.
Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
What it costs
- Web application, including its own APIFrom $5,000 per application
- Separate public or partner APIFrom $8,000 per API
- Cloud environmentFrom $10,000 per environment
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
What you can send your customer
- An attestation letter with the test dates, scope, method, and results, made to share
- An updated letter after the retest, showing the retest status
- The full report, which stays with your team or goes to your customer under NDA if they need detail
- A walkthrough call with your team after the report
Why customers ask
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”[1]
Questions about customer security reviews
What is an attestation letter?
A letter from HackNow that states the test dates, the scope, the method, and a summary of the results, and after your retest it shows the retest status. It confirms a test took place. It isn’t a SOC 2 report, a certification, or an audit opinion.
Can we share the full report?
You decide. Share the letter with the customers who ask, and the full report under NDA if a customer needs detail.
Can you match the scope our customer asked for?
Yes. Send us their request or questionnaire section, and we’ll scope the test to match it.
How fast can you start?
Testing can usually start within 5 business days of signing. Most web application and API tests take one to three weeks of testing, and the final report is delivered within 5 business days after testing ends. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
Tell us what you need tested.
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.