Skip to content
Penetration Testing
Pentest as a Service Β· SecTepe SnapScan Β· self-hosted

Pentest as a Service with SecTepe SnapScan

Continuous attack-surface validation delivered as a managed service β€” on SecTepe SnapScan, our own pentesting platform. Self-hosted in Germany, startable on demand, with graded approvals for active exploitation and an unbroken audit trail. Complementary to the classic pentest β€” not a replacement.

SnapScan Run #42

last 24h Β· hybrid scope

Completed
Hosts enumerated3,428
Attack paths discovered17
Critical paths3
High-risk paths6
Proof of exploitability12
Remediation guidancegenerated

What is Pentest as a Service?

PTaaS closes the gap between two annual pentests. Instead of a single snapshot, you get continuous, autonomous attack simulation against your production environment β€” driven and interpreted by SecTepe.

Continuous, not a snapshot

Regular runs surface drift, new exposures and regressions after releases immediately β€” instead of waiting for next year's pentest.

Autonomous attack chains

SnapScan combines vulnerabilities, misconfigurations and weak credentials into real attack paths β€” not just a list of single CVEs.

Production-safe & GDPR-compliant

Safe exploitation without DoS risk, no agents on endpoints, EU data handling and full logging of every action.

Our own platform

SecTepe SnapScan

We do not run PTaaS on a bought-in US platform but on one we built and operate ourselves. That decides where your findings sit, who can see them, and how quickly we can change something when your environment demands it.

Sovereign and self-hosted

The platform runs in German data centres β€” or entirely on your own infrastructure if you prefer. There is no telemetry to a third party and no licence margin for you to carry.

  • Operated by us, or self-hosted by you
  • Containers or a hardened appliance, shipped signed
  • Multi-tenant with roles, permissions and an audit trail

We develop it ourselves

Whatever our analysts find missing in the field, we build in. You are not talking to a reseller but to the team that writes and runs the platform.

  • Findings carry through as evidence towards your ISMS
  • A new critical CVE triggers a retest across the fleet
  • Open findings export for SOAR and your own automation

What SnapScan delivers

Eight core capabilities that clearly set PTaaS apart from classic vulnerability scanning.

Agentic AI pentest

An AI agent does not work through a checklist but follows paths: it combines findings, digs further and documents the chain traceably.

Exploitability, not a raw list

Active verification in three graded modes proves what is actually exploitable β€” with an evidence artefact instead of “potentially vulnerable”.

Attack chains & blast radius

Surfacing the few combinations that genuinely lead to impact β€” with an exposure score from A to F per target.

Internal pentest via runner

An engagement-bound runner inside your network with a signed scope: AD enumeration, credential testing and escalation paths, behind explicit opt-in.

Cloud and Kubernetes posture

Configuration in AWS, Azure and GCP against CIS guidance, plus a read-only audit for Kubernetes clusters.

Attack surface in view

Continuously recording subdomains, services and certificates β€” including a diff of what changed since the last run.

Scheduled and on-demand runs

Startable on a schedule or with one click β€” before a release, after a migration, or when a new critical CVE lands.

Finding-level retest

One click re-checks that single finding and records the outcome: remediated, still present, or inconclusive.

Our managed PTaaS process

Five clearly bounded steps β€” so PTaaS acts as a continuous security service, not just a tool.

1

Onboarding & scoping

Define crown jewels, environments, run frequency and rules of engagement together.

2

SnapScan setup

Tenant setup, runner deployment, integrations with AD, cloud accounts and ticketing.

3

Continuous pentesting

Automated runs on schedule or event β€” external, internal, cloud, hybrid.

4

Triage by SecTepe

Our analysts assess every finding in context, remove noise and prioritise.

5

Remediation & retest

Remediation guidance, retest after fix, trend reporting towards audit.

Classic pentest vs. PTaaS

Both approaches complement each other β€” neither replaces the other. The table below lists the strengths per approach.

CriterionClassic pentestPTaaS with SnapScan
Methodologymanual, analyst-drivenautonomous, platform-driven
Frequencypoint in time (annual / release)continuous / on-demand
Business-logic flaws✓ stronglimited
Environment coveragescope-limited✓ very broad
Time to react to changesproject cadenceminutes to hours
Regulatory fitISO 27001, NIS2, TISAX, DORA (formal evidence)complementary evidence of continuous effectiveness
Typical valuedeep audit, logic risksdrift detection, release gating

Best practice: an annual manual pentest for depth and creativity plus ongoing PTaaS for breadth and timeliness.

Where PTaaS is particularly strong

Four scenarios where continuous, autonomous pentesting delivers the biggest leverage.

Mid-market under NIS2

Regular evidence of effectiveness between audits β€” without building your own red team.

Critical-infrastructure operators

Continuous attack-surface monitoring for regulated sectors (energy, healthcare, finance).

MSSP and SOC customers

Complements detection & response with proactive validation: does your SOC react to real attack paths?

DevOps & release-driven teams

Release gating inside CI/CD: no release without a green PTaaS run on the changed attack surface.

What you get out of every run

Every PTaaS run produces directly actionable results β€” for the C-level, for technical teams and for audit.

  • Executive summary

    C-level-ready summary with attack paths, risk score and progress over time.

  • Exploit evidence with attack chain

    Reproducible steps and hashed evidence artefacts per finding β€” proven chains marked as such.

  • Prioritised remediation guidance

    Sorted by impact and enriched with CISA KEV and EPSS β€” Dev and Ops know what to tackle first.

  • Trend reporting over time

    Continuous view: are attack surfaces shrinking, are risks staying open for long?

  • Compliance mapping

    Indicative mapping to ISO 27001 Annex A and BSI IT-Grundschutz as a basis for evidence β€” not a certification statement.

  • SecTepe triage & remediation guidance

    Our analysts interpret findings, remove noise and accompany remediation including retest.

PTaaS Trend β€” Q1/2026

12 runs Β· hybrid scope

Attack paths at start42
Attack paths now9
Critical open1
High open3
Median fix time9 days
NIS2 mappingArt. 21 covered

Frequently asked questions about PTaaS

Answers to the most common questions about Pentest as a Service with SnapScan.

Does Pentest as a Service replace a classic penetration test?
No. PTaaS is a strong complement, not a replacement. The manual pentest remains essential for business-logic flaws, zero-days and creative attack paths. SnapScan fills the gap in between with continuous coverage: repeated runs that make changes in your attack surface immediately visible. For NIS2, ISO 27001 and DORA we recommend an annual manual pentest plus ongoing PTaaS runs.
Where does SnapScan run and how is data processed (GDPR)?
SnapScan is our own platform and self-hosted. We run it in German data centres β€” findings go to no US provider. Internal testing uses an engagement-bound runner inside your network; if you prefer, you can run the platform entirely yourself, as containers or as a hardened appliance. We secure the GDPR-compliant framework with a DPA, scoping documentation and data minimisation.
Is this safe for production?
By default, scans run without active exploitation. Going further requires your explicit approval, and it is graded: from an out-of-band callback that proves a weakness without executing anything, through a strictly read-only proof command, up to interactive sessions that require a second, separate opt-in. The runner rejects targets outside the signed scope locally, a kill switch stops work in progress immediately, and every attempt lands in the audit trail. We agree time windows, scope and emergency communication with you before every run.
How often should PTaaS run?
Typically monthly to weekly runs for external attack surfaces, and event-based runs for internal environments (e.g. after major releases, cloud migrations, M&A integration). The biggest value emerges when PTaaS becomes part of your release and change process.
How is pricing structured?
We offer PTaaS as an annual subscription with a defined asset and run volume. The price includes onboarding, platform usage, triage by SecTepe analysts, remediation guidance and retest after fixes. Because the platform is ours, you are not paying a third party licence margin on top. Terms on request.
Which environments does SnapScan cover?
External attack surfaces (internet-exposed assets and subdomains), web applications and APIs including authenticated testing, cloud configuration in AWS, Azure and GCP, Kubernetes clusters, and internal networks with Active Directory via a runner inside your network. On request, .onion targets are covered over Tor as well.

Ready for continuous pentesting?

Start with a no-obligation SnapScan demo or a scoping call. We walk you through a live run against a demo environment β€” and show how PTaaS fits into your security operations.

How we work with you

We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.

1. Free initial conversation

We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.

2. Structured assessment

We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.

3. Delivery with a dedicated lead

A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.

4. Continuous operations & review

After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.