Sample pentest report: what to demand before you send credentials
A sample pentest report should show severity bars, remediations, and restored state — with no client names and no exploit payloads.
Ask for a sample pentest report before you hand over SSO.
You are not being difficult. You are buying a PDF that legal, engineering, and sometimes a customer will read. If the sample is a Nessus dump with a logo on top, keep shopping.
Short answer: I send a redacted sample that shows snapshot, severity bars, evidence without payloads, remediations, and a retest line. Ask from the contact form. The paid job is on the security review page.
What a grown-up sample contains
Cover and version. A snapshot table. Findings with an ID, a severity, a path, and a fix an engineer can ship. A closer that says test state was restored. No live customer names.
What it should not contain: shell commands to copy-paste, tokens, or a second company’s hostname.
How this ties to the offer
$2,400 per application. $1,200 to start. Report 48 hours after access. One free retest of the same URL in 14 days. Numbers also live on pricing.
FAQ
Should I ask for a sample pentest report? +
Yes. You are buying a document. See the format, the ranking, and whether it includes exploit recipes you do not want in email.
What should be redacted? +
Client names, live hosts, credentials, and anything that would help a stranger reproduce an attack.
Do you have a sample? +
Yes. Ask from the contact form. The live offer is $2,400 per application, $1,200 to start.