Skip to content

Enterprise security review · Fixed fee · Named operator

The deal-blocker penetration test.

A focused application and API test, scoped to produce the one artifact an enterprise security review asks for and a trust centre cannot generate: a current third-party penetration test report with a practitioner’s name on it.

$12,000

Fixed · 5 days end to end

10 days

Business days from signed authorisation

1 day

To a scoping call

Fee credit

If the report is late

Zero Harbor Security is taking 3 founding clients at $9,500 — not a discount, a trade for a named case study and one reference call, agreed in writing before the engagement starts.

For partners

What you need before you put anyone in front of your client.

If you run compliance, audit or a fractional security practice, you already hold the relationship and the trust. What you usually do not hold is delivery capacity for manual testing — and the firm you refer becomes a statement about your judgement. So this is the boundary, in writing, before anything persuasive.

Never competes with you

Manual penetration testing only. Zero Harbor Security does not issue SOC 2 opinions, CMMC certifications, ASV scans or any attestation a partner firm would issue itself. The boundary is structural, not a promise.

White-label or named

Deliver under your brand, co-branded, or as a named subcontractor on your engagement letter — your call, agreed before scoping.

Published price

You can quote a client without phoning anyone first. Partner rates are on a stated schedule rather than negotiated per deal.

Your client stays yours

No direct solicitation of a client introduced by a partner, for the term of the relationship and twelve months after. In writing, in the partner agreement.

Scope

What is in, and what is deliberately not.

A fixed fee is only honest if the boundary is published with it. Everything below is included at the stated price; everything in the second column is quoted separately rather than absorbed quietly or discovered late.

Included

  • One web application or API, authenticated and unauthenticated
  • Business-logic and access-control testing — the classes no scanner models
  • Authentication, session and authorisation flows
  • Injection, deserialisation and server-side request classes
  • Supporting external attack surface for the application in scope
  • Rules of engagement and written authorisation before anything is touched

Not included

  • Internal network and Active Directory — scoped separately
  • Cloud configuration review — scoped separately
  • Physical security and social engineering — not offered
  • Anything requiring accreditation Zero Harbor Security does not hold: the SOC 2 opinion itself, PCI ASV scanning, FedRAMP assessment, CMMC certification, Common Criteria evaluation

Deliverables

Six documents, and what each one is for.

A penetration test report is worth exactly what the person reading it will accept. These are built for three different readers — the prospect’s security engineer, your own executive, and whoever files it.

Executive summary
One to two pages, written to be forwarded to the prospect’s security team without editing. This is the document that actually moves the deal.
Technical report
Every finding with evidence, CVSS rating, business impact and a specific remediation step. Not a scanner export.
Remediation status per finding
What was fixed, what was accepted with a stated rationale, what is outstanding. A reviewing security engineer reads this column first.
Attestation letter
The operator who ran the test, by name, with credentials and serial numbers, scope, method and dates. One page, designed to be attached to a questionnaire response.
Coverage record
What was tested and how — test by test, pass or fail. So a clean report still shows the work rather than asking anyone to take it on trust.
Retest
One retest, included — within 30 days of report delivery, against the original scope, re-verifying the findings in the original report.

Timeline

Ten business days, from authorisation.

Quoted from signed authorisation rather than from first contact, because scoping and your own legal review are not under Zero Harbor Security’s control and a date that depends on your paperwork is not a commitment.

  1. Day 0 Scoping call Within one business day of the introduction. Scope, boundary and exclusions agreed in writing.
  2. Day 0 Authorisation Written authorisation signed by someone entitled to give it. The clock starts here, not at enquiry.
  3. Days 1–4 Testing Automated tooling runs coverage. The billed hours go into exploitation and chaining.
  4. Day 5 Reporting Findings written up, rated and evidenced. Executive summary drafted for forwarding.
  5. By day 10 Delivery Report, executive summary and attestation letter delivered. Retest scheduled on request.

Who signs

The name on the report is the person who ran the test.

The common failure in this market is not technical. It is being quoted a senior and delivered a junior, with a report signed by someone who never touched the system.

Who signs

The attestation carries the name and credentials of the operator who ran the test — junior or principal. Nobody signs for work they did not personally perform. Where a junior leads, a named senior reviewer signs alongside them, and both names appear.

Disclosed before you sign

The seniority mix and the hours at each level are disclosed before you sign, and they are reflected in the price. You are never quoted a senior and delivered a junior.

Continuity

The same operator runs your next test unless you ask for fresh eyes. If they become unavailable you are told before the engagement starts, not when the report arrives with a different name on it.

On this engagement

You are told which operator is assigned before anything is signed, and that name is on the attestation letter when the report arrives. Their credentials travel with it, serial numbers included, so a reviewer can check them without asking anyone to take it on trust.

The operators →

When not to

Five reasons not to hire Zero Harbor Security.

If you are deciding whether to put this firm in front of someone, the useful thing is knowing where it is the wrong answer. Some of these are free alternatives, and naming them costs less than a referral that goes badly.

  1. 01

    The questionnaire is the whole blocker

    If the review is asking for policies, a SOC 2 report you already hold, or answers to a standard questionnaire, a trust centre closes it faster and cheaper than a pentest. Vanta, Drata and a good security engineer with a spreadsheet all beat this engagement on that job.

  2. 02

    Your compliance platform already includes testing

    Several platforms bundle or broker a test on higher plans, sometimes at no marginal cost. Ask what you already own before buying it twice. If the artifact it produces satisfies the reviewer, that is the correct answer.

  3. 03

    The deal closes in under two weeks

    Ten business days from signed authorisation is the commitment, and authorisation usually takes a few days of its own. If the contract is signing sooner, this cannot help and saying otherwise would be a lie with a date on it.

  4. 04

    You need continuous coverage

    A point-in-time test answers a point-in-time question. If the requirement is continuous scanning or an always-on programme, a platform serves you better and Zero Harbor Security will say which ones.

  5. 05

    You are under about twenty-five people

    At that size the honest answer is usually that the fee is disproportionate to the deal. Ask the reviewer whether a self-assessment plus a remediation commitment clears the gate — very often it does.

Contact

Send the application, or the date the deal needs to close.

A scoping call within one business day, then a fixed price and a delivery date in writing. If this is not the right work, Zero Harbor Security will say so and point you somewhere better — see §06 for where it usually points.

Scope a test