What is a penetration test for a product team?
A penetration test is authorized hostile use of a system you own. For a SaaS app that usually means the live UI, auth, and API — not a Hollywood red team.
A penetration test is authorized hostile use of a system the owner asked you to test. That sentence is the whole job.
Everything else is marketing. People append “CREST,” “red team,” “unlimited apps,” and “AI-powered” to the same two words.
Short answer: For a product team with one web app, a penetration test is an authorized security review of the live frontend, auth, and API. I sell that for $2,400 per application, $1,200 to start, report in 48 hours after access.
What the words legally imply
You need written authorization. You need a target the sender owns. You do not scan a neighbor tenant or a payroll vendor “just to be thorough.”
If someone offers a pentest without asking who owns the URL, hang up.
What product teams actually need
Not a six-week physical-plus-phishing circus. They need:
- A test user that works
- A second role if they have one
- Notes ranked by severity
- Remediations an engineer can ship
- One retest of the same URL
That is the web application security review. The same number is on pricing. A sample report is available before you pay. No exploit recipes in the PDF.
FAQ
What is a penetration test? +
Authorized testing that tries to break the rules of a system you own. On a web product it is usually login, roles, pages, and APIs. It is not surprise scanning of a vendor you do not control.
Is a penetration test the same as a vulnerability scan? +
No. A scan lists tool output. A human review asks whether a signed-in user can reach another tenant's records.
Do I need a certified pentest? +
Only if a customer or auditor named a stamp (CREST, PCI QSA). Most first-time product teams need a usable report, not letterhead.