ClearPenTest

Testing

Vulnerability scan

Also called: vulnerability scanning, automated scan

A vulnerability scan is an automated check that compares software versions and configurations against a database of known vulnerabilities, producing a list of potential issues without confirming whether any of them can actually be exploited.

Scanning is cheap and repeatable, which is its value: it gives continuous coverage between penetration tests. Its limit is that it has no model of your application's logic, so it cannot evaluate whether one customer can reach another customer's data.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.