Enterprise security review · Fixed fee · Named operator
The deal-blocker penetration test.
A focused application and API test, scoped to produce the one artifact an enterprise security review asks for and a trust centre cannot generate: a current third-party penetration test report with a practitioner’s name on it.
$12,000
Fixed · 5 days end to end
10 days
Business days from signed authorisation
1 day
To a scoping call
Fee credit
If the report is late
Zero Harbor Security is taking 3 founding clients at $9,500 — not a discount, a trade for a named case study and one reference call, agreed in writing before the engagement starts.
For partners
What you need before you put anyone in front of your client.
If you run compliance, audit or a fractional security practice, you already hold the relationship and the trust. What you usually do not hold is delivery capacity for manual testing — and the firm you refer becomes a statement about your judgement. So this is the boundary, in writing, before anything persuasive.
Never competes with you
Manual penetration testing only. Zero Harbor Security does not issue SOC 2 opinions, CMMC certifications, ASV scans or any attestation a partner firm would issue itself. The boundary is structural, not a promise.
White-label or named
Deliver under your brand, co-branded, or as a named subcontractor on your engagement letter — your call, agreed before scoping.
Published price
You can quote a client without phoning anyone first. Partner rates are on a stated schedule rather than negotiated per deal.
Your client stays yours
No direct solicitation of a client introduced by a partner, for the term of the relationship and twelve months after. In writing, in the partner agreement.
Scope
What is in, and what is deliberately not.
A fixed fee is only honest if the boundary is published with it. Everything below is included at the stated price; everything in the second column is quoted separately rather than absorbed quietly or discovered late.
Included
- One web application or API, authenticated and unauthenticated
- Business-logic and access-control testing — the classes no scanner models
- Authentication, session and authorisation flows
- Injection, deserialisation and server-side request classes
- Supporting external attack surface for the application in scope
- Rules of engagement and written authorisation before anything is touched
Not included
- Internal network and Active Directory — scoped separately
- Cloud configuration review — scoped separately
- Physical security and social engineering — not offered
- Anything requiring accreditation Zero Harbor Security does not hold: the SOC 2 opinion itself, PCI ASV scanning, FedRAMP assessment, CMMC certification, Common Criteria evaluation
Deliverables
Six documents, and what each one is for.
A penetration test report is worth exactly what the person reading it will accept. These are built for three different readers — the prospect’s security engineer, your own executive, and whoever files it.
- Executive summary
- One to two pages, written to be forwarded to the prospect’s security team without editing. This is the document that actually moves the deal.
- Technical report
- Every finding with evidence, CVSS rating, business impact and a specific remediation step. Not a scanner export.
- Remediation status per finding
- What was fixed, what was accepted with a stated rationale, what is outstanding. A reviewing security engineer reads this column first.
- Attestation letter
- The operator who ran the test, by name, with credentials and serial numbers, scope, method and dates. One page, designed to be attached to a questionnaire response.
- Coverage record
- What was tested and how — test by test, pass or fail. So a clean report still shows the work rather than asking anyone to take it on trust.
- Retest
- One retest, included — within 30 days of report delivery, against the original scope, re-verifying the findings in the original report.
Timeline
Ten business days, from authorisation.
Quoted from signed authorisation rather than from first contact, because scoping and your own legal review are not under Zero Harbor Security’s control and a date that depends on your paperwork is not a commitment.
- Day 0 Scoping call Within one business day of the introduction. Scope, boundary and exclusions agreed in writing.
- Day 0 Authorisation Written authorisation signed by someone entitled to give it. The clock starts here, not at enquiry.
- Days 1–4 Testing Automated tooling runs coverage. The billed hours go into exploitation and chaining.
- Day 5 Reporting Findings written up, rated and evidenced. Executive summary drafted for forwarding.
- By day 10 Delivery Report, executive summary and attestation letter delivered. Retest scheduled on request.
Who signs
The name on the report is the person who ran the test.
The common failure in this market is not technical. It is being quoted a senior and delivered a junior, with a report signed by someone who never touched the system.
Who signs
The attestation carries the name and credentials of the operator who ran the test — junior or principal. Nobody signs for work they did not personally perform. Where a junior leads, a named senior reviewer signs alongside them, and both names appear.
Disclosed before you sign
The seniority mix and the hours at each level are disclosed before you sign, and they are reflected in the price. You are never quoted a senior and delivered a junior.
Continuity
The same operator runs your next test unless you ask for fresh eyes. If they become unavailable you are told before the engagement starts, not when the report arrives with a different name on it.
On this engagement
You are told which operator is assigned before anything is signed, and that name is on the attestation letter when the report arrives. Their credentials travel with it, serial numbers included, so a reviewer can check them without asking anyone to take it on trust.
When not to
Five reasons not to hire Zero Harbor Security.
If you are deciding whether to put this firm in front of someone, the useful thing is knowing where it is the wrong answer. Some of these are free alternatives, and naming them costs less than a referral that goes badly.
- 01
The questionnaire is the whole blocker
If the review is asking for policies, a SOC 2 report you already hold, or answers to a standard questionnaire, a trust centre closes it faster and cheaper than a pentest. Vanta, Drata and a good security engineer with a spreadsheet all beat this engagement on that job.
- 02
Your compliance platform already includes testing
Several platforms bundle or broker a test on higher plans, sometimes at no marginal cost. Ask what you already own before buying it twice. If the artifact it produces satisfies the reviewer, that is the correct answer.
- 03
The deal closes in under two weeks
Ten business days from signed authorisation is the commitment, and authorisation usually takes a few days of its own. If the contract is signing sooner, this cannot help and saying otherwise would be a lie with a date on it.
- 04
You need continuous coverage
A point-in-time test answers a point-in-time question. If the requirement is continuous scanning or an always-on programme, a platform serves you better and Zero Harbor Security will say which ones.
- 05
You are under about twenty-five people
At that size the honest answer is usually that the fee is disproportionate to the deal. Ask the reviewer whether a self-assessment plus a remediation commitment clears the gate — very often it does.
Contact
Send the application, or the date the deal needs to close.
A scoping call within one business day, then a fixed price and a delivery date in writing. If this is not the right work, Zero Harbor Security will say so and point you somewhere better — see §06 for where it usually points.