Skip to content

Is a VAPT enough?

Sometimes. A VAPT is a vulnerability assessment and penetration test, often just called a pentest. It tests what’s named in its scope, usually from outside. We also look at the parts behind it and follow the paths to your data and your customers’.

Free 30-minute call. Fixed fee for the agreed scope, quoted before work starts.

What faces the internet, and everything behind it

A typical SaaS product. Watch what a pentest looks at and what we look at, or step through it yourself.

An architecture diagram of a typical SaaS product. The steps under it say which part the diagram lights.
  1. Step 1 of 7

    A VAPT usually tests the web app and API, from outside.

  2. Step 2 of 7

    We look at every part you choose, design and code included. We test hands-on where you’ve agreed it.

  3. Step 3 of 7

    Say someone leaves your team. You remove their login, and a pentest of your app might confirm it’s gone.

  4. Step 4 of 7

    Can they still open a customer’s account through a support or admin tool?

  5. Step 5 of 7

    Can they still read or download your data and your customers’?

  6. Step 6 of 7

    Can they still change what your customers run?

  7. Step 7 of 7

    Do the keys they held for connected apps and AI tools still work?

Penetration test vs security assessment

They answer different questions, and you may need both. A pentest report covers what was in its scope.

VAPTOur assessment
The question it answersCan someone break into the systems we’re testing?Is our SaaS built and set up to keep our data and our customers’ safe?
What it coversThe apps, APIs or networks named in the test.Your product, plus the cloud and build behind it and the accounts that can reach them.
Choose it whenA customer or auditor asks for a pentest report.You’re launching, changing or growing, and want to know where you’re exposed.

Which do you need right now?

Pick the closest match. If none fits, tell us what’s going on.

The way in is usually already there

In each case the way in was there before the attack. An assessment looks for the same kind of gap in your platform.

WhenWhat happenedWhat an assessment would have asked
May 2026

A software flaw

Verizon found that 31% of the breaches in its 2026 data set started with an attacker exploiting a software vulnerability.

Verizon 2026 Data Breach Investigations Report
Which internet-facing systems run software nobody patches quickly?
June 2024

A login without MFA

Mandiant traced the Snowflake customer breaches it investigated to stolen passwords. The accounts had no multi-factor authentication.

Mandiant on the Snowflake customer breaches, 2024
Which accounts can reach your data and your customers’ with a password alone?
September 2025

An integration with too much access

Attackers used stolen credentials from Cloudflare’s Salesloft Drift integration to copy support-case data out of Salesforce.

Cloudflare on the Salesloft Drift incident, 2025
What can each connected tool reach, and who would notice?

Verizon’s figure covers breaches in all industries. The questions in the last column are ours, not the sources’.

You don’t need to pick a service first

Tell us what worries you. On a free 30-minute call, we’ll help you decide what needs a look. We reply within one working day.

Request a free call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.
Or try the customer data mini assessment