Unlimited manual penetration testing

Test everything.
As often as you like.

One subscription. Every test type - web, infrastructure, cloud, red team, physical. A senior tester starts within days, not procurement cycles.

From £4,999/year

Three service levels based on how quickly testing starts.

Unlimited

Test requests - one active test at a time.

Next day

Fastest testing start with reserved Rapid capacity.

Evidence for ISO 27001 · SOC 2 · PCI DSS

How it works

From request to retest, without the procurement cycle.

01

Request

Book any test in the portal. No statements of work, no SoW ping-pong - the subscription covers it.

02

Test

Scoping call, rules of engagement agreed, then senior testers get to work. Manual-first, always.

03

Fix & retest

Remediate, then verify. Retesting is included in the subscription - not an upsell.

The portal

Every test, every finding, one place.

Request tests, track progress, and export audit-ready evidence for ISO 27001, SOC 2 and PCI.

portal.darkside-sec.com
Active requests+ New test request
PT-2026-0007External infrastructure test
In progress
PT-2026-0006Web application test - customer portal
Report ready
PT-2026-0005Internal network & Active Directory
Retest scheduled
Findings by severity46 open · 118 resolved
3 critical7 high14 medium22 low

Pricing

Three speeds. Same testing depth.

Choose how quickly each approved, ready-to-test engagement enters active testing.

Standard

£4,999/year

GBP · or $6,699 USD/year

Planned security testing for teams working to a predictable roadmap.

Testing startsWithin 10 business days
Discuss Standard

Rapid

£13,999/year

GBP · or $18,699 USD/year

Reserved priority capacity when testing cannot wait.

Testing startsNext business day
Discuss Rapid
Included in every plan
  • Unlimited test requests, with one active test at a time
  • Every test type, delivered by senior penetration testers
  • Reporting, remediation guidance and retesting included
Need multiple tests running at once?

Add concurrent testing capacity with 15% off each additional subscription.

Talk to us

Testing-start commitments begin once scope, access, credentials and rules of engagement are confirmed, and apply to the next eligible request. Prices shown are annual totals in GBP or USD, excluding VAT and applicable taxes. 12-month term. Quarterly and annual billing available. On-site expenses are billed at cost.

Pentester credentials

Certified expertise.

Our penetration testing team holds recognised certifications across red teaming, web exploitation, cloud and infrastructure.

CRTOZero-Point Security

Red Team Operator

End-to-end adversary simulation with Cobalt Strike, from initial access and command and control through to objectives and professional reporting.

Certification details
CRTLZero-Point Security

Red Team Lead

Advanced adversary simulation and emulation against mature defensive controls, demonstrating the skills needed for complex red team operations.

Certification details
CPTSHack The Box Academy

HTB Certified Penetration Testing Specialist

A hands-on assessment of real-world enterprise penetration testing, from enumeration and exploitation through to a professional client report.

Certification details
CWESHack The Box Academy

HTB Certified Web Exploitation Specialist

Hands-on web application pentesting and bug bounty expertise: finding non-obvious flaws, chaining vulnerabilities and producing actionable reports.

Certification details
eJPTINE Security

Junior Penetration Tester

Practical penetration testing across assessment methodology, host and network auditing, exploitation and web application testing.

Certification details
CARTPAltered Security

Certified Azure Red Team Professional

Practical Azure and Entra ID red teaming across discovery, initial access, privilege escalation, lateral movement, persistence and data access.

Certification details
ICCAINE Security

INE Certified Cloud Associate

Foundational multi-cloud expertise spanning core services, identity, architecture, management, security and compliance.

Certification details
+Continuous development

And many more

Our team continues to build specialist capability across offensive security, cloud, infrastructure, application testing and adversary simulation.

Explore our credentials

FAQ

Common buying questions.

What does unlimited penetration testing mean?

You can submit unlimited test requests during the subscription. We run one active test at a time, then move to the next scope once reporting and agreed retesting are complete.

Which test types are included?

Web application, API, network infrastructure, cloud configuration, mobile app, red team, physical security and social engineering testing are included in every plan.

How quickly can testing start?

Standard testing starts within 10 business days, Priority within 5 business days, and Rapid the next business day. The commitment begins once scope, access, credentials and rules of engagement are confirmed, and applies to the next eligible request.

Do reports support ISO 27001, SOC 2 and PCI DSS evidence?

Yes. Reports include scope, methodology, risk-rated findings, evidence, remediation guidance and retest status so they can support audit and customer assurance reviews.

Is retesting included?

Yes. Once you fix a finding, retesting is included so the report can show whether the issue is fixed, still open or partially remediated.

How is client data handled?

Engagement data is handled under written rules of engagement and data-processing terms. Evidence is access-controlled, encrypted in transit and at rest, and retained only for the agreed period.

Choose when your next test starts.

Standard within 10 business days. Rapid as soon as the next business day.

Book a call