CyberSecureMVP
AUTHORIZED PENETRATION TESTING

Active testing — only against assets you prove you control.

CyberSecure's passive scans show what the Internet can see. A penetration test goes further: it actively probes your web and network surface for exploitable weaknesses and validates them, so you find out before an attacker does. It is available to subscribed customers and runs only under an explicit authorisation.

Create account Log in

Not ready to sign up? Run a free Simple Scan of public information first — no account needed.

What a test covers

Scope: testing is limited to verifying exploitable weaknesses on your own assets. It does not perform post-exploitation, lateral movement, data exfiltration, credential spraying, phishing or social engineering — those belong in a human-led engagement with its own contract.

How authorisation works

Active testing can cause real effects on real systems, so two things are required before a test runs — every time:

  1. Proof you control the domain. You publish a DNS TXT record we give you; we confirm it resolves when the test is requested and again when it starts. A domain you no longer control can't be tested on an old approval.
  2. A signed rules-of-engagement record. You name the authorising person and an emergency contact, set the testing window, and agree to the rules of engagement. We keep this as an audit record tied to the test.

Penetration testing uses CyberSecure's active scanning engines and is available when active scanning is enabled for your account. Contact us if you'd like it turned on.