Overview
Hackrate Continuous Penetration Testing provides organizations with a coordinated 12-month security testing program designed for environments where applications, infrastructure, and security priorities continuously change.
Instead of purchasing disconnected penetration tests throughout the year, customers establish an annual testing framework covering governance, testing capacity, reporting, and recurring planning. Each target is evaluated individually, and the customer selects the appropriate testing model based on sensitivity, exposure, architecture, recent changes, and business risk.
The service supports customer-controlled applications, APIs, infrastructure, and digital assets running on or using Amazon Web Services (AWS), including workloads built on services such as Amazon EC2, Amazon API Gateway, Amazon CloudFront, Elastic Load Balancing, Amazon S3, and other AWS services.
How It Works
-
Annual Security Testing Roadmap: Hackrate and the customer review relevant applications, environments, known risks, planned releases, previous testing, and available testing capacity to establish the annual framework.
-
Monthly Risk-Based Planning: Recurring planning sessions review completed testing, unresolved vulnerabilities, remediation progress, significant environmental changes, and current business risks to determine upcoming testing priorities.
-
Target-Specific Testing Model: For every approved target, the customer chooses the most appropriate delivery model:
- Hackrate Internal Team: Restricted assessments performed by assigned Hackrate pentesters for sensitive applications, internal environments, and systems requiring controlled access.
- Selected Elite Ethical Hackers: Invitation-only testing using selected ethical hackers to provide diverse attacker perspectives and creative exploration.
- Hybrid Testing: Combines internal specialist expertise with selected Elite Ethical Hackers for targets requiring both contextual depth and broader attacker perspectives.
No target or technical information is shared with Elite Ethical Hackers unless explicitly approved by the customer.
-
Security Testing: Each activity receives its own scope, objectives, participants, access model, timeline, rules of engagement, and reporting requirements before testing begins.
-
Centralized Findings: Validated vulnerabilities from approved testing activities are managed through the Hackrate Ethical Hacking Platform, providing a centralized view across targets and testing models.
-
Remediation and Review: Customers can assign findings to responsible teams, monitor remediation status, maintain supporting evidence, and use results to determine future testing priorities.
Key Benefits
- Continuous Risk-Based Testing: Redirect testing capacity toward applications and environments where security assessment provides the greatest value.
- Flexible Testing Models: Select internal, invitation-only crowdsourced, or hybrid testing independently for each target.
- Annual Testing Capacity: Establish contracted testing capacity within a predictable 12-month framework.
- Monthly Prioritization: Adapt upcoming assessments to releases, architecture changes, incidents, emerging risks, and remediation activity.
- AWS Workload Assessment: Assess customer-controlled applications, APIs, infrastructure, and workloads hosted on or using AWS.
- Centralized Vulnerability Management: Review findings, ownership, evidence, communication, and remediation status through the Hackrate platform.
- Program-Level Visibility: Maintain a consolidated view of assessments, vulnerabilities, remediation progress, recurring weaknesses, and future priorities.
A Coordinated Annual Testing Program
Continuous Pentest is not continuous automated scanning or testing performed every day. It is a recurring, risk-based penetration testing program where individual security assessments are planned and executed according to the annual framework and current monthly priorities.
The exact annual capacity, testing models, scope, reporting requirements, deliverables, and commercial terms are defined individually for each customer.
Highlights
- 12-Month Security Testing Program - Coordinate multiple penetration testing activities through one annual framework with contracted capacity, recurring planning, and centralized reporting.
- Risk-Based Monthly Prioritization - Continuously adjust testing priorities around new releases, architecture changes, remediation progress, incidents, and evolving business risks.
- Internal, Crowdsourced or Hybrid - Choose Hackrate internal pentesters, selected Elite Ethical Hackers, or a controlled hybrid approach independently for each approved target.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
Hackrate provides ongoing customer support throughout the 12-month Continuous Penetration Testing program, including annual planning, monthly prioritization, assessment scoping, testing coordination, rules of engagement, vulnerability triage, severity assessment, reporting, platform-related questions, and remediation support.
Customers receive support for the duration of their contracted program. Hackrate works with designated customer stakeholders to coordinate upcoming assessments, review findings and remediation progress, and adjust testing priorities according to current risks and available capacity.
Urgent security findings can be escalated through the communication channels agreed with the customer. Specific response times, testing capacity, retesting services, and additional support requirements may be defined in the applicable private offer or statement of work.
Support contact: Email: support@hckrt.com Website: