Skip to content
← Learn

Method

What a penetration test is

What a real pentest is: authorised exploitation, reproducible PoC and a human gate. When not to hire Rekon.

A penetration test is not a CVE inventory. It is an authorised attack: someone tries to get in, chains what they find and shows how far it goes. What remains is a report your team can reproduce. A pentest may find no exploitable path. Its quality depends on scope, testing and evidence, not on forcing an exploit.

What a real test includes

Scope written before anything is touched. Rules of engagement: windows, forbidden targets, emergency contacts. Authorised exploitation, not a verbal “best effort”. A PoC per finding: steps, evidence, conditions. Negative controls designed to verify expected denials; failed attempts and limitations documented separately. A person’s signature, not a platform’s.

The human gate

Agents sweep surface, enumerate and propose paths. That accelerates. They do not set scope, they do not fire an intrusive action and they do not carry the result. A person authorizes every step that breaks something and signs the report. Without that gate, automation is theatre with an attack budget.

When not to hire us

If compliance demands a logo that is not ours. If the asset to test is not inventoried and scope would be fiction. If nobody on the other side owns remediation. If you want a promise not to touch production and, at the same time, a real test: those two things do not coexist. Rekon does not publish turnarounds on the web.

Cadence: event or continuity

A point-in-time pentest freezes the moment of the test. It serves a year-end close, a contract requirement, a board. If you deploy every week, the report is stale before you finish reading it: that is a cadence question, not a brand question. The comparison is in PTaaS vs traditional pentest. Companies in Brazil: penetration testing in Brazil and LGPD vs Bacen. If the method fits, we propose scope.

Straight answers

How is a pentest different from a scanner?

The scanner lists known weaknesses. The pentest answers what an attacker can achieve with what was found: it exploits under authorisation, chains findings and documents the path. Validation may be limited for safety; the report should explain what was demonstrated and what remained untested.

Who authorizes each intrusive action?

A person. Agents propose paths and accelerate reconnaissance; they do not sign and they do not fire exploitation alone. Every intrusive action passes a logged human gate. The report is signed by whoever supervised.

When should you NOT hire Rekon?

If you need Big Four letterhead, we are not the provider. If you want a scanner PDF, neither. If nobody on your side will remediate, the report becomes an anxiety document. If continuity is critical, we agree on the environment, windows, limits and stop conditions; we do not guarantee zero risk. And if you need a turnaround published on the web, we will not put one: the window is fixed in the contract.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn