Startup Launch Program

A Real Pentest for $4,500.

Manual pentesting. Fixed price. No back-and-forth quotes.

A one-week, audit-ready engagement.

Your enterprise customer wants a third-party pentest before they sign. Your SOC 2 auditor expects one. We deliver the full report in one week, while most vendors take three just for a proposal.

New Startup Offer

$1,000 Credit

CREST Certified

500+ Companies

4.7 / 5 Rating

What's Included

Everything you needfor a compliant launch.

$4,500 USD. That's the number.

No hourly rates. No retainer. No invoice that comes in 40% higher than the quote. One asset, one week, one fixed price.

Included

Your report is ready in 7 days.

Not 3 weeks. Not "pending scoping confirmation." Day seven, you have a report — verified findings, risk ratings, and remediation notes.

Included

It's structured for auditors.

SOC 2. ISO 27001. HIPAA. Enterprise security reviews. The report format is designed to satisfy exactly what these frameworks expect.

Included
Is This You?

Built for high-velocity startupsat Every Stage.

Enterprise Ready

A buyer asked for a pentest before they'll sign.

Audit Pending

You're 60-90 days out from SOC 2 or ISO 27001.

Launch Phase

You're launching and want to know where you stand.

First Test

You've never had a proper third-party security test.

The Ideal Match

High-growth teams handling
critical customer data.

Whether you're early-stage or scaling, building SaaS, fintech, healthtech, or AI. We specialize in high-velocity teams across NZ, Australia, and the US.

Priority Access:YCTechstarsAntlerBlackbirdIcehouseStartmate

Who we're not for

Teams that prefer
procurement over production.

If you need a 60-page vendor proposal, three intro calls, and a process that takes longer than the test itself - we're probably not the right fit. We skip the red tape.

Our Expertise

Web, Mobile, and APIPenetration Testing

Web Application

Penetration Testing

SaaS platforms, customer dashboards, admin panels, and internal portals.

Tested from an external attacker's perspective - no internal access needed. We focus on the surface your customers and attackers actually see.

Mobile Application

Penetration Testing

iOS and Android apps. Authentication, session handling, and API calls.

We check the areas most auditors scrutinise - and most teams leave untested until it's too late: local storage, biometrics, and session security.

API Penetration

Testing (REST & GraphQL)

Broken auth, excessive data exposure, and business logic flaws.

The attack surface most startups expose before they realise it needs testing. We dive deep into injection flaws and cross-tenant data leaks.

One asset per engagement.

You pick the one that matters most for your next audit or deal. Multiple assets? Use the scoping form - we'll come back with clear pricing and no surprises.

Scoping Form
The Roadmap

Four Steps. Seven Days.

Step 1 - Apply

(2 minutes)

Short form below. We review every application within 24 hours to confirm your startup's eligibility.

Step 2 - Scope Call

(30 minutes)

One call. We confirm the asset, access requirements, and your compliance target. No long discovery sessions.

Step 3 - Test Runs

(5 business days)

Manual testing by security researchers - not automated scans. You keep shipping. We keep testing.

Step 4 - Report Delivered

Day Seven

Verified vulnerabilities, risk ratings, and remediation guidance your team can act on. Structured for auditors.

No long discovery sessions. No back-and-forth for two weeks. Just results.

The Comparison

Why Not Just Use Cobalt,Bugcrowd, or Astra?

Fair question. Those platforms were built for enterprise security teams with annual testing budgets of more than $15,000. If you're a startup in Auckland or Sydney, they will often quote you out of the conversation.

FeatureCapture The BugCobaltAstraHackerOneBugcrowd
Startup credit / free
Manual pentestPartial
Timeline1 week1-2 weeksVariesVariesVaries
Fixed pricing
NZ / AU focus
CREST certified
Audit-ready reportPartial
Startup program

This comparison covers manual penetration testing only, not automated vulnerability scanning tools. All data based on publicly available information.

View all pricing details →

We're the right choice if you need one credible, audit-ready pentest, fast, at a price that doesn't require a board approval.

Questions We Get Asked

FAQs

Final Step

Apply for Your
Pentest Credit

We review every application within 24 hours. If eligible, we confirm your credit and book the scope call immediately.

Redirecting to secure Microsoft Form

What Happens Next

1

Review

We respond within 24 hours.

2

Scope

30-minute confirmation call.

3

Launch

Report delivered by day seven.

Priority for YC, Techstars, Antler, Blackbird, Icehouse & Startmate teams.

All applications are reviewed individually by our security team.

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.