Penetration Testing
Scope and approach
External and internal define the testing perspective. Infrastructure, applications, APIs and mobile define the assets in scope.

Testing perspective
External
Testing from outside the environment against the internet-facing attack surface.
Internal
Testing from an agreed starting point inside the environment.
Assets and systems in scope
Network and infrastructure
Internal and external networks, exposed services and segmentation.
Web applications and APIs
Authentication, sessions, application logic and API boundaries.
Mobile applications
Android and iOS using static and dynamic testing methods.
Scope size
From penetration testing to continuous validation
Initial engagement
Expert-led penetration testing
Establishes a validated security baseline across the agreed systems and attack surfaces.
- Scope driven by the client's systems and risks
- Expert-led testing and validation
- Prioritised findings and recommendations
Continuing model
Continuous penetration testing with AigentX
AigentX, KomodoSec's AI pentesting platform, enables recurring or continuous attack testing within the agreed scope — under human supervision.
- Internal network, external infrastructure, web and API testing
- Cadence aligned to releases, system changes and risk
- Evidence-based findings, reviewed and validated by KomodoSec
Scope, cadence and the use of AigentX follow the client's environment and technical requirements.
Your next step
The fastest route to a solid proposal is a short technical conversation about your specific environment.
