Penetration testing

A penetration test is a scoped, time-boxed, manual engagement against a system you nominate. It is not a scan with a nicer report on the front. The value is in the part a scanner cannot do: reasoning about a business process, chaining two unremarkable findings into one that matters, and deciding whether a control actually holds.

What a test covers

How it fits with the platforms

Testing is a point-in-time exercise; the estate is not. Maphra answers the question that has to be answered before a test can even be scoped properly — what is actually exposed, including the assets nobody remembered. Maphra discovers everything your organisation exposes to the internet, decides what actually matters, and proves exploitability — continuously, without an agent and without a credential.

AppSecD covers the other side. AppSecD runs SAST, DAST, SCA, secret detection, IaC, container, Kubernetes and API security from one platform — wired into Git, gated at the pull request, and managed through a real vulnerability lifecycle. A finding a tester reports once should not reappear six months later, and the lifecycle is what stops it: findings deduplicate across scans, carry ageing and an SLA, get assigned to an owner, and closing one can require maker-checker approval.

Scope and authorisation

Manual testing runs only against systems you own or are authorised to test, inside a scope agreed in writing before anything starts. The same principle is built into Maphra: active validation runs only inside an explicit scope boundary you define, and the scope gate prevents active checks from reaching third-party hosts that merely appear in your surface.

Talk to DedSec Technologies about scoping an engagement.