Continuous security testing

Recurring and scheduled security testing for applications and infrastructure that change often, available as a retainer.

On this page

What continuous security testing is

We test new features, releases, and infrastructure changes on a recurring schedule. Scope and rules of engagement are agreed once and reviewed when they change, so each round starts without new setup.

This service suits teams that release often, run several products, or need evidence of regular testing for customers and auditors. It is available as a retainer.

What can be covered

We agree the products and environments in scope during scoping. Coverage can include any of the following.

New features and releases

Testing of changes before or after release, based on what your team has shipped since the last round.

Applications and APIs

Web applications, mobile apps, and APIs, tested with the same methods as our application security testing.

Cloud and infrastructure changes

New accounts, services, network changes, and cluster configuration as your environment grows.

AI features and agents

New AI features, agents, and tool integrations as they are added to your products.

Retests

Retests of fixed findings in the next scheduled round or when your team asks.

Periodic full assessments

A broader assessment of the full scope at an agreed interval, alongside change-based testing.

How an engagement runs

We agree the products, environments, and asset types in scope, the testing schedule, and how your team tells us what has changed. The rules of engagement are agreed at the start and reviewed when scope changes. An NDA is signed before you share details.

What you receive

Each round produces the same set of deliverables, sized to what changed and the scope you agree with us.

Agreed scope

  • Written scope covering targets, environments, and accounts
  • Rules of engagement with test windows, excluded actions, and contacts
  • NDA signed before you share details

Findings

  • Each finding rated by severity
  • Status of open findings carried forward between rounds

Reports

  • Executive report for leadership and stakeholders
  • Technical report with reproduction steps for each finding
  • Remediation guidance your engineers can act on

Retest

  • Retest of findings after your team applies fixes
  • Updated status for each retested finding

Engagement models

Duration and frequency depend on scope.

ModelHow it worksWhen it fits
Scheduled roundsTesting at an agreed interval, covering changes since the last roundYou release on a regular cadence and want testing planned ahead.
Release-based testingTesting of specific releases or features your team flagsMajor changes ship at irregular times.
RetainerReserved testing capacity used across products, releases, and retests as neededYou have several products or teams and want flexibility in what gets tested.
Full assessment with change testingA full assessment at an agreed interval, with smaller rounds for changes in betweenYou need a periodic report for audits and also ship changes often.

How it fits with your delivery process

Continuous testing runs alongside the automated scanning in your build pipeline. Scanners find known issue patterns quickly. Manual testing covers authorization, business logic, and issues that only appear when several weaknesses are combined.

We agree with your team how upcoming changes are flagged to us and how findings reach the engineers who own the affected code.

Standards and methods

Each round uses the same standards as our individual services: the OWASP Web Security Testing Guide, ASVS, MASVS, and API Security Top 10 for applications, CIS Benchmarks for cloud and infrastructure configuration, and NIST SP 800-115 for the overall process.

Recurring testing supports the verification practices described in the NIST Secure Software Development Framework (SP 800-218).

Common questions

How is this different from a one-off penetration test?

A one-off test assesses a fixed scope at one point in time. Continuous testing repeats on a schedule, focuses each round on what changed, and keeps a standing scope and rules of engagement.

How does a retainer work?

You reserve testing capacity for a period and use it across the products, releases, and retests you choose. Terms are agreed during scoping.

Will testing affect production?

Testing is planned to avoid disruption. The rules of engagement set test windows, list excluded actions such as denial-of-service or load testing, and name who to contact if something looks wrong. The same rules apply to every round unless your team agrees a change.

What access do you need?

Standing test accounts for each role, access to the agreed environments, and a way to see what has changed, such as release notes or a changelog.

How are findings shared securely?

We sign an NDA before you share details of your environment. How reports and other sensitive material are exchanged is agreed with your team during scoping.

Can you provide a letter for our customers?

We can discuss it during scoping.

How to prepare

List the products and environments to include and how often each changes. Decide how your team will tell us about upcoming releases.

Set up test accounts and access that stay valid between rounds, name a contact for each product, and share previous test reports so recurring issues can be tracked.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.