Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Pen Test Scoping Calculator

Estimate the effort and price range for a penetration test before you ever get on a call. Choose your target type, scale, authentication, and environments to see a tester-day estimate and a budget band.

Estimated effort
0 days
Estimated price range
$0
What a test at this scope typically includes:
    How we estimate. We size tester-days from target type, scale, authenticated roles and environments, then apply a typical day rate of about $1,400 to $2,200. Complexity, retesting and timeline move the final number, which we confirm on a short scoping call.

    Questions

    How is pen test pricing estimated?

    Most penetration tests are scoped by effort, measured in tester-days. We estimate days from the type of target, its scale, the number of authenticated roles, and how many environments are in scope, then apply a typical daily rate range to produce a price band.

    Why does authentication increase the cost?

    Every distinct user role is its own attack surface. A tester has to exercise the app as each role and test for privilege escalation between them, so more roles mean more days of testing.

    Is this a quote?

    No. It is a planning estimate to help you budget and prepare for a scoping call. Final pricing depends on the real complexity of the target, the testing methodology, retesting needs, and reporting requirements. We confirm scope before any engagement.

    What is the difference between a vulnerability scan and a pen test?

    A scan is automated and finds known issues. A penetration test is performed by people who chain weaknesses together, exploit business logic, and validate real impact. Auditors and enterprise buyers usually want a manual pen test, not just a scan.

    Is this calculator free?

    Yes, it is free with no signup. When you are ready, we scope and deliver penetration tests with our offensive-security partner.

    Not ready for a call yet?

    Get the security playbook

    A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Compliance Penetration Testing

    We run the test end to end and hand you an auditor-ready report.

    Explore Compliance Penetration Testing →

    Ready to scope a real test?

    Our penetration testing services are delivered with our offensive-security partner and pair well with ongoing vulnerability management so findings don't just get a one-time fix. We deliver a report your auditors and customers will accept. Bring this estimate to a scoping call.

    About our pen testing Book a call

    Want the full picture on SOC 2?

    This gives you the shape of the problem. The full picture is all 61 criteria of SOC 2, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free SOC 2 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.