Skip to content
SECQON

An automated external penetration test for startups

A customer, investor or auditor has asked for a penetration test, and a manual engagement is weeks away and priced for a larger company. SecQon runs an automated external penetration test against assets you have proved you own: real attack payloads from a narrow allowlist of rules, bounded and non-destructive, and a report that says both what was tested and what was not.

The problem

Someone needs a pentest report by a date, and you have not budgeted for a manual engagement.

You have tried a free scanner and got a long list of unverified warnings you could not act on or explain.

You want to know what an attacker on the internet can actually reach, not just whether a header is missing.

How SecQon helps

What SecQon does not do here

  • This is an automated test, not a human-led one, and the report says so. It does not test business logic, race conditions or stored XSS, and it does not chain findings into attack paths.
  • IDOR/BOLA is reported as a precondition, not a proven breach: confirming it needs a second account. Mass-assignment findings are also reported unconfirmed.
  • We test from outside only, and only assets you have verified. Nothing inside your network, and no subdomain you have not verified separately.
  • A thorough test of a real site takes hours. Our own full Deep sweep of docqon.com took about 4.2 hours.
  • Six OWASP Top 10 categories have purpose-built tests, A07 is covered only in part, and A10 (SSRF) is assessed only where the out-of-band check ran. A04 and A09 cannot be assessed from outside.

The plan we suggest

Business $399 per month

When you want what a manual pentest does, continuously.

up to 30 verified assets

Choose BusinessCompare all plans

The checks that matter for this

  • Web application pentest

    A browser-rendered crawl plus bounded proofs for XSS, SQL injection and SSRF, and an active scanner on the pentest tier.

  • API security

    Your API’s own schema, read as an outsider: open operations, GraphQL introspection, CORS and leaked stack traces.

  • Exposed ports & services

    36 high-risk TCP ports — databases, container control planes, remote admin — checked with one connect each.

  • TLS & certificates

    Certificate trust and expiry, and whether your server still accepts TLS 1.0 or 1.1.

Questions people ask

Which plan runs the penetration test?

Business ($399 a month) runs it on demand, and can run it on the monthly re-audit if you give a separate standing authorisation. If you need one report by a date, the one-off pentest report is $99 for a single Deep and penetration-test scan on one verified asset.

What happens to the $99 if the scan fails?

A one-off scan that fails, is cancelled, never starts, or is refused because the asset is not verified refunds its credit, once.

Can this replace a manual pentest?

It covers the ground an automated external test can, and some requirements accept that; ask whoever set yours. It cannot replace a human tester for business logic or chained attacks. If a contract specifies a human-led test, you need one.

Will it break my production site?

It is built not to. Destructive and data-extraction actions are blocked at every depth, payloads are bounded, and traffic is limited to 10 requests per second per asset. We still recommend telling your team before a Deep or penetration-test scan.

Does it test pages behind our login?

Yes, on Growth and above. You store a session header or browser-storage values, and our own checks and the crawl use it. The template sweep and the SQL-injection probe do not run signed in.

How long does it take?

Hours, not minutes, depending on how much of the site the crawl finds. The scan runs in the background, and the results and report appear in the app when it finishes.

Last reviewed on 24 Sep 2026.

See what a scan finds on your own asset

Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.

Start freeCompare plans