Penetration testing for customer security reviews

When a customer’s security review asks for a recent third-party pen test, we test what they’re asking about and give you a letter to share.

Last reviewed October 2026

What your customer will want to see

When a customer’s security review asks about testing, it may want:

  • A test within the window they name
  • An independent testing firm
  • The scope, matched to the product they buy
  • Fix status for critical and high findings

After your retest, the attestation letter covers all four without exposing your full report. It states the test dates, scope, method, and results, and shows the retest status.

Working back from your deal

  1. Send us their request. Share the questionnaire section or email that asks about testing, and we’ll scope the test to match it.
  2. A free scoping call, then a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
  3. Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
  4. Final report delivered within 5 business days after testing ends. Send your customer the attestation letter, and we walk your team through the findings on a call.
  5. Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and a letter that shows the retest status.

Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.

What it costs

  • Web application, including its own APIFrom $5,000 per application
  • Separate public or partner APIFrom $8,000 per API
  • Cloud environmentFrom $10,000 per environment

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.

See starting prices for every service

What you can send your customer

  • An attestation letter with the test dates, scope, method, and results, made to share
  • An updated letter after the retest, showing the retest status
  • The full report, which stays with your team or goes to your customer under NDA if they need detail
  • A walkthrough call with your team after the report

See an example report and attestation letter

Why customers ask

Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”[1]

Questions about customer security reviews

What is an attestation letter?

A letter from HackNow that states the test dates, the scope, the method, and a summary of the results, and after your retest it shows the retest status. It confirms a test took place. It isn’t a SOC 2 report, a certification, or an audit opinion.

Can we share the full report?

You decide. Share the letter with the customers who ask, and the full report under NDA if a customer needs detail.

Can you match the scope our customer asked for?

Yes. Send us their request or questionnaire section, and we’ll scope the test to match it.

How fast can you start?

Testing can usually start within 5 business days of signing. Most web application and API tests take one to three weeks of testing, and the final report is delivered within 5 business days after testing ends. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.

Tell us what you need tested.

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.