How to choose a penetration testing company
Ten questions to ask every firm on your shortlist, including us. Our answers are under each question.
Last reviewed October 2026
-
How much of the testing is manual?
Why it matters: OWASP’s Web Security Testing Guide says business-logic flaws “cannot be detected by a vulnerability scanner.”[1]
Our answer: Automated tooling covers breadth. Our testers focus on manual work: authorization, business logic, and chaining issues together.
-
Who will test, and what qualifications do they hold?
Why it matters: Certifications show a baseline. Ask which ones the people on your test hold.
Our answer: Our own US-based testers. Certifications held across our testing team include OSCP, CRTO, CISSP, CCSK, CompTIA PenTest+, CompTIA CySA+, and AWS Certified Solutions Architect – Associate.
-
Is any of the work passed to another firm?
Why it matters: You should know who will have access to your systems and data.
Our answer: No. All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
-
Can we see a sample report?
Why it matters: The report is what you’re paying for, and what your auditor or customer will read.
Our answer: Yes. Read our example report, built on a fictional company. A sample report is available on request under NDA. Ask for it
-
What’s in the report?
Why it matters: Your engineers need evidence and reproduction steps; your leadership needs a summary they can act on.
Our answer: An executive summary, technical findings with evidence and reproduction steps, attack narratives, remediation guidance, and an attestation letter.
-
Is a retest included?
Why it matters: A retest shows your fixes actually worked.
Our answer: Yes. One retest of reported findings within 90 days of the final report, with an updated report.
-
How is the price set?
Why it matters: A fixed fee keeps the budget predictable.
Our answer: Every engagement is a fixed fee after a free scoping call, and your price won’t change once testing starts unless the scope does. Starting prices are on our pricing page.
-
How do you keep production safe?
Why it matters: A test shouldn’t become an incident of its own.
Our answer: Signed rules of engagement, agreed testing windows and source IP addresses, emergency contacts on both sides, and nothing destructive without written approval. You can pause testing at any time with one message.
-
How do you handle our data?
Why it matters: Your testers will see sensitive data.
Our answer: A mutual NDA first if you want one, and evidence handled under the confidentiality and retention terms in your contract. How we handle your data
-
How quickly will you tell us about critical findings?
Why it matters: A critical flaw shouldn’t wait for the final report.
Our answer: Critical findings are reported within 24 hours of confirmation, not held for the report. Final report delivered within 5 business days after testing ends.
Tell us what you need tested.
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.