Skip to content
← Learn

Buying guide

How to choose a pentesting provider

Questions and criteria for comparing scope, evidence, communication, retesting and terms before commissioning a pentest.

Ask for evidence before choosing Ask for a synthetic or authorized sample report. Check prerequisites, reproduction steps, impact, fixes and limitations. Individual credentials can provide context, but do not replace methodology or prove the quality of your future deliverable. This guide applies to any provider, including REKON.

Proposal comparison worksheet For each provider record answer / evidence / open question across eight rows: 1. assets and exclusions; 2. roles and tenants; 3. human testing and automation; 4. accountable contact and communication channel; 5. urgent findings; 6. reporting and evidence handling; 7. retest window and cost; 8. schedule and commercial terms. A missing answer means unconfirmed, not that the provider lacks the capability.

Questions that reveal depth How would they test that one organization’s administrator cannot access another? What happens when an integration is out of scope? How would they distinguish a complete fix from one that only blocks the original example? Ask for reasoning and limitations without requesting another customer’s private evidence.

Requirements before authorization Identify who can authorize the assets. Agree on testing windows, prohibited actions, emergency contact, stop conditions, evidence handling and deletion. Confirm whether retesting is included in writing. A pentest does not certify compliance or guarantee the absence of vulnerabilities.

Inspect the deliverable Apply these criteria to the sample report. Compare delivery models in REKON and Strike. Request proposed scope once you have identified objectives and assets.

Straight answers

How do I request a proposal?

Share the application type, roles and objective through the contact form. Do not send credentials or customer data.

Does a pentest guarantee security?

No. It evaluates an agreed scope and version within a testing window. Limitations and residual risk remain.

What is agreed before testing?

Assets, permissions, environments, exclusions, communication, deliverables and retest terms.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn