What continuous security testing is
We test new features, releases, and infrastructure changes on a recurring schedule. Scope and rules of engagement are agreed once and reviewed when they change, so each round starts without new setup.
This service suits teams that release often, run several products, or need evidence of regular testing for customers and auditors. It is available as a retainer.
What can be covered
We agree the products and environments in scope during scoping. Coverage can include any of the following.
New features and releases
Testing of changes before or after release, based on what your team has shipped since the last round.
Applications and APIs
Web applications, mobile apps, and APIs, tested with the same methods as our application security testing.
Cloud and infrastructure changes
New accounts, services, network changes, and cluster configuration as your environment grows.
AI features and agents
New AI features, agents, and tool integrations as they are added to your products.
Retests
Retests of fixed findings in the next scheduled round or when your team asks.
Periodic full assessments
A broader assessment of the full scope at an agreed interval, alongside change-based testing.
How an engagement runs
We agree the products, environments, and asset types in scope, the testing schedule, and how your team tells us what has changed. The rules of engagement are agreed at the start and reviewed when scope changes. An NDA is signed before you share details.
Each round focuses on what changed since the last one, plus any areas you ask us to revisit. Testing is manual, supported by tooling, and uses standing access agreed at the start.
Each round produces findings rated by severity, with reproduction steps and remediation guidance. An executive report summarizes the period for leadership.
Fixed findings are retested, and their status carries forward between rounds so you can see what remains open.
What you receive
Each round produces the same set of deliverables, sized to what changed and the scope you agree with us.
Agreed scope
- Written scope covering targets, environments, and accounts
- Rules of engagement with test windows, excluded actions, and contacts
- NDA signed before you share details
Findings
- Each finding rated by severity
- Status of open findings carried forward between rounds
Reports
- Executive report for leadership and stakeholders
- Technical report with reproduction steps for each finding
- Remediation guidance your engineers can act on
Retest
- Retest of findings after your team applies fixes
- Updated status for each retested finding
Engagement models
Duration and frequency depend on scope.
| Model | How it works | When it fits |
|---|---|---|
| Scheduled rounds | Testing at an agreed interval, covering changes since the last round | You release on a regular cadence and want testing planned ahead. |
| Release-based testing | Testing of specific releases or features your team flags | Major changes ship at irregular times. |
| Retainer | Reserved testing capacity used across products, releases, and retests as needed | You have several products or teams and want flexibility in what gets tested. |
| Full assessment with change testing | A full assessment at an agreed interval, with smaller rounds for changes in between | You need a periodic report for audits and also ship changes often. |
How it fits with your delivery process
Continuous testing runs alongside the automated scanning in your build pipeline. Scanners find known issue patterns quickly. Manual testing covers authorization, business logic, and issues that only appear when several weaknesses are combined.
We agree with your team how upcoming changes are flagged to us and how findings reach the engineers who own the affected code.
Standards and methods
Each round uses the same standards as our individual services: the OWASP Web Security Testing Guide, ASVS, MASVS, and API Security Top 10 for applications, CIS Benchmarks for cloud and infrastructure configuration, and NIST SP 800-115 for the overall process.
Recurring testing supports the verification practices described in the NIST Secure Software Development Framework (SP 800-218).
Common questions
How is this different from a one-off penetration test?
A one-off test assesses a fixed scope at one point in time. Continuous testing repeats on a schedule, focuses each round on what changed, and keeps a standing scope and rules of engagement.
How does a retainer work?
You reserve testing capacity for a period and use it across the products, releases, and retests you choose. Terms are agreed during scoping.
Will testing affect production?
Testing is planned to avoid disruption. The rules of engagement set test windows, list excluded actions such as denial-of-service or load testing, and name who to contact if something looks wrong. The same rules apply to every round unless your team agrees a change.
What access do you need?
Standing test accounts for each role, access to the agreed environments, and a way to see what has changed, such as release notes or a changelog.
How are findings shared securely?
We sign an NDA before you share details of your environment. How reports and other sensitive material are exchanged is agreed with your team during scoping.
Can you provide a letter for our customers?
We can discuss it during scoping.
How to prepare
List the products and environments to include and how often each changes. Decide how your team will tell us about upcoming releases.
Set up test accounts and access that stay valid between rounds, name a contact for each product, and share previous test reports so recurring issues can be tracked.

