Skip to content
· 6 min read

Pentest retest: the free 14-day pass, then a new quote

A pentest retest is one free check of the same URL within 14 days of a $2,400 one-time review. A new feature or a second app is a new quote.

Open shade over a weathered garden bench, with a closed brass padlock on the main gate, an open side-shed latch, and blank red and green inspection tags, for a pentest retest of the same gate.
Article language

Showing original language

A pentest retest is the second look at findings you already paid me to write down.

You fixed them. You want to know if they still open. That is the whole job.

Short answer: A pentest retest is one free pass on the same URL, inside 14 days of the first report, included in the $2,400 one-time web application security review. $1,200 starts the original review. I recheck the findings you say are fixed. A new feature, a new URL, or a second app is a new quote. There is no subscription.

HackerOne’s pentest retest docs (updated June 13, 2025) give Essential customers 30 calendar days and Premium customers 90, with unlimited retests during that window. I do not sell that program. I sell one retest, one URL, 14 days. The review price sits on pricing.

What does a pentest retest actually include?

A pentest retest checks the findings from the original report on the same application and the same target URL. I mark each one fixed, still open, or not retested. I do not hunt a feature you shipped after the report.

The table is the quote. Read it before you treat “retest” as a second full review.

Free pentest retestNew review
PriceIncluded in the $2,400 one-time fee$2,400 again, $1,200 to start
WindowOnce, within 14 days of the first reportWhenever you book
TargetSame application, same URLNew URL, new app, or a material new surface
What I openFindings already in the reportFrontend, auth, and the APIs the UI calls
What you getA short note on those findingsA new severity-ranked report
Not includedNew routes, a second app, source review, a compliance stampLeftover work on the previous app

The first PDF — severity, evidence without payloads, a remediation an engineer can ticket — matches the sample report. The retest note is shorter. It points at the original findings. It does not reprint a cookbook.

How long is the pentest retest window?

The free pentest retest ends 14 days after I send the first report, not 14 days after your last pull request merges. If the report lands on a Monday, day 14 is two Mondays later. Ask inside that window. After it closes, the same check is a new $2,400 quote.

The original 48-hour clock starts when login works. That rule is in how the 48-hour review clock starts. The retest clock starts when you have the report.

Inside those 14 days:

  1. You name which findings you believe are fixed.
  2. The URL is the one in the written scope.
  3. A test user can still sign in, or you send a fresh invite if you rotated access.
  4. You say so if a finding was accepted and will not be fixed.

A dead login on day 13 does not extend the window. Send a working user before it closes.

A 2026 pentest RFP template from Stingrai lists one retest within 60 days as a common fixed-price clause. That is a larger-firm window. It is not this offer.

Which changes make the pentest retest a new job?

Same URL, same findings, one pass: free. A new hostname, a second application, a feature the first report never saw, or a second retest after the free one: a new quote at $2,400.

The path is short:

Trigger. You write that specific findings are fixed, and the date is still inside 14 days.

Action. I sign in with the same roles and reopen only those findings.

System of record. A short retest note on the original report: fixed, still open, or skipped because you accepted the risk.

Human escalation. If the route is new, the host changed, or you want the whole app walked again, I stop and send a new quote. I do not widen the free pass in silence.

Lines I actually use:

  • You patched the findings and deployed them to the same production URL. That is the retest.
  • You patched them on staging, and the scoped URL was production. That is a different host. I retest the URL in the scope, not both.
  • You shipped a billing page the first report never opened. That page is a new engagement, even on the same domain.
  • You have a second product, or you want the repository read. Two apps, and source review, are separate quotes. The retest stays on the running app.

Invoice chase and Friday numbers are a different job: One Lane is $3,500 once for one named ops lane. Booking from ChatGPT is Business MCP, not a security review. A retest does not do either.

What should you send before the pentest retest?

Send the finding list, a working login, and the same URL that was in the written scope. I do not need a meeting, a slide deck, or a scanner export. If the password changed, send the new one before day 14 or I cannot run the pass.

Use this list:

  • Written confirmation you still authorize the same target.
  • Finding titles from the report, marked fixed or accepted.
  • The URL, unchanged.
  • A test user that can reach those screens. A second role only if the original finding needed it.
  • Anything you rotated: password, guest invite, IP allowlist.
  • The deploy time, so I am not checking Friday’s build against Thursday’s note.

I put test state back the way I found it. Credentials and payloads stay out of the note.

When this isn’t the right move yet

Skip the pentest retest if nothing is fixed yet, if day 14 has already passed, or if you want a new page or a second app tested. Those are a new review at $2,400, not a free extra on the first PDF.

Do not start the original review yet if you cannot name the URL, cannot create a test user, or cannot authorize the work in writing. The $1,200 start does not replace access. It is on the review page. The first report’s clock still waits until login works.

Do not buy this if you need a SOC 2 letter, a CREST badge, or a PCI QSA stamp. I do not sell those. I do not hold offensive-security certifications, and a 14-day retest is not an audit letter.

Do not treat the pass as a retainer. One retest is included. A later look is a new $2,400. A monthly scanner is a subscription from someone else.

If the app is still a prototype with no real accounts, wait. A retest of an empty login is a note that says the login is empty.

What does the retest note tell your engineer?

The note tells your engineer which original findings are closed and which still reproduce on the same URL. It is not a new discovery report, and it is not a certificate you can hand an auditor.

Hand engineering the original PDF plus those lines. If something is still open, the first remediation still stands.

If you want the format before you pay, ask for the redacted sample on the sample request form. Start when the URL and a user exist.

Pay $1,200 to start on the security review page, or ask for the sample first. I reply with scope and what access I need. The free pentest retest exists only after that report is already in your hands.

FAQ

What is included in a pentest retest? +

One pass on the same application and target URL, within 14 days of the first report. I mark findings you say you fixed as fixed, still open, or skipped. It is included in the $2,400 one-time review. A second app, a new URL, or a feature the first report never saw is a new $2,400 quote.

How much does it cost if I only want the retest? +

The retest is not sold alone. The review is $2,400 per application, $1,200 to start and $1,200 when the report is delivered. The one free retest is part of that price. If the 14 days have passed, or you want another pass, that is a new $2,400, not a discount add-on.

Does the retest cover a new page we shipped? +

No. The free pass reopens findings already in the report, on the same URL. A page, role, or hostname that was not in the original scope is a new engagement. Tell me before I log in so I do not treat a new surface as a free extra.

Will the retest note include exploit steps? +

No. The note names the original finding, whether it still reproduces, and the same remediation language as the first PDF. No payloads, no credentials, and no client names. Ask for the redacted sample before you send access if you want that format first.

Related operator notes

Keep reading

No-pressure first step

Not sure which one fits?
Get a free 20-min audit.

Bring one workflow you'd want automated. I'll tell you which deployment fits — and which doesn't — in twenty minutes. No pitch deck, no follow-up sequence. Useful even if you don't buy.

  • A real plan, not a sales call

    Which surface (Telegram, Discord, Slack, phone) fits your team, and which one doesn't.

  • Honest "don't buy this" if it applies

    If a $99/month SaaS solves it, I'll tell you which one and how.

  • A timeline + price range

    When I could deploy, what it'd cost, and what you'd own at the end.