Services · Kassandra Security · San Diego, CA

Every engagement is scoped, hand-tested, and retested until it holds.

Five defined services, each with a fixed-fee starting point and a written scope before day one. Pick the surface you need proven — external, application, cloud, the human layer, or your SOC 2 controls — and we test it by hand, not by scanner output.

Methodology
PTES-aligned recon, exploitation, and post-exploitation
Turnaround
5–8 testing days plus 3 days reporting on a focused scope
Every fee includes
One verification retest on every reported finding

01 — The service ledger

Five services, each with a defined scope and a price

Starting fees for typical small and mid-sized scopes. The final number is fixed in the scoping document once we’ve counted your hosts, apps, and cloud accounts.

01

Penetration Test

Manual external, internal, and network testing across your agreed target list. We chain misconfigurations, abuse trust relationships, and validate exploitability — then hand you a CVSS-scored report with reproduction requests, not a scanner dump padded with informational CVEs.

External & internal Manual exploitation Attestation letter
02

Web Application Assessment

Authenticated, per-role testing against the OWASP Testing Guide — authorization logic, injection, business-logic abuse, session handling, and access control between tenants. Sized by application count and user-role complexity, not by an arbitrary hour block.

OWASP-aligned Auth & IDOR Multi-role
03

Cloud Configuration Review

A control-plane audit of your AWS, Azure, or GCP tenancy — IAM policies, public exposure, logging and key management, network segmentation, and drift from CIS Benchmarks. You get a prioritized fix list mapped to the exact resource and the policy that opened it.

AWS · Azure · GCP CIS Benchmarks IAM & exposure
04

Phishing Simulation Program

A campaign wave with a tailored pretext, lookalike domain, and a just-in-time training landing page. We report click, submit, and report rates broken out by team — so you learn which department needs the next round, not just an aggregate percentage.

Custom pretext Per-team metrics JIT training page
05

SOC 2 Readiness Assessment

A fixed-scope gap analysis before you sit an audit. We review policies, controls, and evidence against the Trust Services Criteria and hand you a gap register your auditor accepts plus a remediation roadmap ordered by effort and criticality.

Trust Services Criteria Gap register Remediation roadmap

02 — What a pentest actually covers

Four surfaces, one test methodology

Internet-facing perimeter

Everything an unauthenticated attacker can reach: exposed services, VPN endpoints, forgotten subdomains, and credential reuse from public breaches.

Post-compromise lateral movement

Assumed-breach testing from inside the LAN — privilege escalation, Active Directory abuse, and how far a single foothold can travel.

Control-plane misconfiguration

IAM over-permission, public buckets and snapshots, unencrypted key stores, and lateral paths through misused roles across your cloud accounts.

Application & authorization logic

Injection, broken access control, tenant isolation, and business-logic flaws a scanner never understands because they need a human to reason about intent.

03 — What lands in your inbox

A report an engineer can act on and a board can read

Every engagement, regardless of service, ships the same documented set of deliverables — no thin summary, no PDF that sits in a drawer. Here is exactly what you own at close-out.

A printed penetration test report with severity charts on a dark desk

Findings, evidence, retest

The raw data is yours to share with auditors, insurers, and customers. We hold an encrypted copy for 12 months, then destroy it.

  1. Executive summary

    One page in plain language — the risk posture, the themes behind the findings, and what a non-technical stakeholder needs to sign off on.

  2. CVSS-scored findings

    Each issue rated with vector string, impact, and likelihood, ordered by priority so remediation effort goes where it matters first.

  3. Reproduction steps

    The exact requests, payloads, and screenshots your engineers need to reproduce and confirm the fix — no guesswork handed off.

  4. Remediation guidance

    Specific, technology-aware fixes — not “apply patches.” We name the setting, the code path, or the policy that closes it.

  5. Attestation letter

    Where SOC 2 is in play, an auditor-ready letter mapping findings to the relevant Trust Services Criteria for CC4.1 and CC7.1.

  6. Verification retest

    One pass on every reported finding after you remediate — fixed items marked resolved with evidence, residual risk documented.

04 — Request a scope

Tell us the surface, get a fixed-fee proposal

Send a few details about what you run and what you’re trying to prove. We reply within one business day with a scoped, fixed-fee proposal — no sales sequence, no discovery funnel.

  • Weekday replies within one business day
  • NDA signed before any technical detail
  • San Diego on-site & remote across the U.S.

Or email hello@kassandrasecurity.com directly.

05 — Scoping questions

What informed buyers ask before signing

How do you price when I don’t know my host count yet?

The scoping call exists for exactly this. We map your assets together in 45 minutes — external IPs, applications and their roles, cloud accounts — and turn that into a fixed number before anyone touches a system. The starting fees on this page assume a typical small-to-mid scope; the scoping document sets the final figure.

Can I combine services in one engagement?

Yes, and it’s usually cheaper than booking them separately. An external pentest plus a web-app assessment, or a cloud review bundled into SOC 2 readiness, share reconnaissance and reporting effort — we reflect that overlap in a combined scope rather than stacking two full fees.

Do you test production or staging?

Either, defined in the rules of engagement. Non-destructive testing runs safely against production within agreed windows and rate limits. Anything destructive — or a denial-of-service check — only runs against staging with explicit written authorization.

Is the verification retest really included?

Yes — one verification pass on every finding we reported is part of the engagement fee, not an upsell. You remediate, we re-test, and each item moves to “resolved with evidence” or stays flagged with the residual risk noted in plain language.

06 — Reach the desk

Book a scoping call

Office

10517 Caminito Pollo
San Diego, CA 92126

Hours

Weekdays 10am–5pm

Coverage

San Diego on-site · remote across the U.S.