Geography
- Penetration testing in Brazil Penetration testing for Brazilian companies: what the market asks, what Bacen requires of licensed institutions, and what the LGPD does not name. Proposed scope, not a brochure.
- LGPD vs Bacen: mandate and diligence What the LGPD actually requires and what Bacen requires of licensed institutions. Pentest is not named in the statute; the annual intrusion test is, in CMN Resolution 5.274/2025.
- Pentesting for businesses in Argentina Web/API assessments for Argentine teams: remote engagement, integration authorization and actionable deliverables.
- Web and API pentesting in Uruguay Human-led Web/API pentesting from Montevideo. Scope, evidence and readiness for Uruguayan businesses.
AI + offensive
- AI-assisted pentesting What AI can do in a real pentest and what it cannot: acceleration with a human gate. The difference between automating reconnaissance and automating judgment.
- PTAI vs automated pentesting The difference between an offensive AI platform with a human gate and a scanner with AI branding. What to ask any vendor promising 'automated pentesting'.
Comparison
- Pentest cost: how to scope a quote Effort drivers, illustrative scopes and terms to compare Web/API pentest proposals without invented price ranges.
- How to choose a pentesting provider Questions and criteria for comparing scope, evidence, communication, retesting and terms before commissioning a pentest.
- PTaaS vs traditional pentest An honest comparison: what PTaaS solves, what a point-in-time pentest solves, and when neither works. No selling the default modality.
- Rekon vs traditional pentest An honest comparison between Rekon's hybrid model (agents + human gate) and the traditional consultancy: cadence, evidence, accountability and coordination costs.
- REKON and Strike: comparing proposals Public-offering comparison reviewed September 18, 2026. Delivery model, evidence and procurement questions without fabricated rankings.
Surface
- Internal infrastructure pentesting How the internal network gets tested: lateral movement, domain escalation, and what it means that one compromised endpoint does not become the whole network.
- Cloud infrastructure pentesting How a cloud environment and identity get tested: IAM, roles, excessive permissions, metadata SSRF and escalation paths. What a real cloud scope includes.
- Web and API penetration testing for businesses Human-led testing of authentication, authorization and business logic. Agree on scope and get evidence your team can act on.
- Pentest preparation: checklist and multi-tenant matrix Prepare accounts, roles, environments and rules of engagement. A synthetic matrix for discussing authorization without sharing secrets.
Industry
Deliverables
- Sample pentest report: multi-tenant API A fully synthetic report with scope, findings, evidence, remediation and retesting. No customer data or customer results.
- What a pentest report is The anatomy of a serious pentest report: validated findings, reproducible PoCs, ATT&CK mapping and negative controls. What to demand before signing.
- What a penetration test is What a real pentest is: authorised exploitation, reproducible PoC and a human gate. When not to hire Rekon.