An automated external penetration test for startups
A customer, investor or auditor has asked for a penetration test, and a manual engagement is weeks away and priced for a larger company. SecQon runs an automated external penetration test against assets you have proved you own: real attack payloads from a narrow allowlist of rules, bounded and non-destructive, and a report that says both what was tested and what was not.
The problem
Someone needs a pentest report by a date, and you have not budgeted for a manual engagement.
You have tried a free scanner and got a long list of unverified warnings you could not act on or explain.
You want to know what an attacker on the internet can actually reach, not just whether a header is missing.
How SecQon helps
Real attack payloads, on a narrow allowlist
The full penetration test runs an active scan limited to 13 rules: path traversal, local and remote file inclusion, server-side code injection, OS-command injection, server-side template injection, XPath injection, XXE, open redirect, CRLF injection, server-side includes, SQL injection and reflected XSS. It is seeded with the URLs our headless-browser crawl found.
Bounded proof, where the class allows it
Deep checks try to demonstrate, not just detect: reflected markup injection rendered in Chromium with a screenshot, SQL injection shown by a boolean differential that reads no data, and SSRF shown by your server calling a collector we run. Only these can earn the label "demonstrated".
Your API and your WAF
The test looks for API operations that answer without the authentication their own schema declares, enumerable object references (the precondition for IDOR/BOLA), and — with a stored test account — mass-assignment probes against that account's own record. It also measures how many of a fixed set of attack signatures your WAF actually blocked.
Safe by construction
Nothing is scanned until you prove ownership. Every packet is checked against your verified assets and pinned to the authorised IP. Destructive actions are blocked at every depth, and each level of intrusiveness needs its own acknowledgement from you.
A report you can send
Plain-language impact, step-by-step fixes with configuration for common servers and frameworks, the evidence behind each finding, and a record of which stages ran. Exploitation claims are made only from stages that ran on that scan.
What SecQon does not do here
- This is an automated test, not a human-led one, and the report says so. It does not test business logic, race conditions or stored XSS, and it does not chain findings into attack paths.
- IDOR/BOLA is reported as a precondition, not a proven breach: confirming it needs a second account. Mass-assignment findings are also reported unconfirmed.
- We test from outside only, and only assets you have verified. Nothing inside your network, and no subdomain you have not verified separately.
- A thorough test of a real site takes hours. Our own full Deep sweep of docqon.com took about 4.2 hours.
- Six OWASP Top 10 categories have purpose-built tests, A07 is covered only in part, and A10 (SSRF) is assessed only where the out-of-band check ran. A04 and A09 cannot be assessed from outside.
The plan we suggest
Business $399 per month
When you want what a manual pentest does, continuously.
up to 30 verified assets
The checks that matter for this
- Web application pentest
A browser-rendered crawl plus bounded proofs for XSS, SQL injection and SSRF, and an active scanner on the pentest tier.
- API security
Your API’s own schema, read as an outsider: open operations, GraphQL introspection, CORS and leaked stack traces.
- Exposed ports & services
36 high-risk TCP ports — databases, container control planes, remote admin — checked with one connect each.
- TLS & certificates
Certificate trust and expiry, and whether your server still accepts TLS 1.0 or 1.1.
Questions people ask
Which plan runs the penetration test?
Business ($399 a month) runs it on demand, and can run it on the monthly re-audit if you give a separate standing authorisation. If you need one report by a date, the one-off pentest report is $99 for a single Deep and penetration-test scan on one verified asset.
What happens to the $99 if the scan fails?
A one-off scan that fails, is cancelled, never starts, or is refused because the asset is not verified refunds its credit, once.
Can this replace a manual pentest?
It covers the ground an automated external test can, and some requirements accept that; ask whoever set yours. It cannot replace a human tester for business logic or chained attacks. If a contract specifies a human-led test, you need one.
Will it break my production site?
It is built not to. Destructive and data-extraction actions are blocked at every depth, payloads are bounded, and traffic is limited to 10 requests per second per asset. We still recommend telling your team before a Deep or penetration-test scan.
Does it test pages behind our login?
Yes, on Growth and above. You store a session header or browser-storage values, and our own checks and the crawl use it. The template sweep and the SQL-injection probe do not run signed in.
How long does it take?
Hours, not minutes, depending on how much of the site the crawl finds. The scan runs in the background, and the results and report appear in the app when it finishes.
Last reviewed on 24 Sep 2026.
See what a scan finds on your own asset
Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.