Penetration testing · Human in the loop
AI-assisted penetration testing, verified by human testers.
We test web applications, APIs, cloud environments, mobile apps and LLM-based systems. AI tooling maps the attack surface and handles the volume. A certified tester exploits, verifies and writes up every issue before it reaches your report.
Fixed prices from $999 · Proposal within one business day · Free retest
- Certifications
- OSCP · CRTP · eWPTXv2 · C-AI/MLPen
- Hall of fame acknowledgements
- Google · Mastercard · U.S. Federal Trade Commission · Telstra · OLX Group · Naspers · Regions Bank
Where AI helps, and where a person decides
We use AI tooling for the parts of a test that reward speed and scale. Exploitation, judgment calls and sign-off stay with a certified tester, and nothing goes into a report until a person has reproduced it.
AI-assisted
Breadth and speed
- Mapping the attack surface: subdomains, endpoints, parameters and exposed services
- Reading large JavaScript bundles, API schemas and source code for routes, secrets and risky patterns
- Generating and ranking test cases across large APIs
- Sorting scanner output so testing time goes to likely issues
- First drafts of finding write-ups, which the tester then edits
Human in the loop
Judgment and proof
- Scoping, rules of engagement and safe limits for production systems
- Manual exploitation, chaining issues together and business logic testing
- Reproducing every finding by hand. Unverified scanner or AI output never reaches your report
- Rating severity in the context of your business and your data
- Final report review, debrief and retest
Which AI tools are used, and how your data is handled, is agreed in the rules of engagement before testing starts. If your policy rules out third-party AI services, tell us during scoping.
Services
Most engagements combine two or more of these. Every test includes manual work by a certified tester.
01
Web application testing
Authentication, sessions, access control, injection, SSRF and business logic. Manual testing mapped to the OWASP Top 10 and the OWASP Web Security Testing Guide.
02
API security testing
REST, GraphQL and gRPC. Object and function level authorization, mass assignment, rate limiting and excessive data exposure, mapped to the OWASP API Security Top 10.
03
AI and LLM application security
Direct and indirect prompt injection, agent and tool permission abuse, system prompt and data leakage, and the security of RAG pipelines and vector stores.
04
Network and Active Directory
External and internal testing. Kerberoasting, AS-REP roasting, pass-the-hash, lateral movement and privilege escalation paths through your domain.
05
Mobile application testing
Android and iOS apps tested against OWASP MASVS: reverse engineering, local data storage, certificate pinning and the APIs behind the app.
06
Cloud and CI/CD review
AWS, Azure and GCP. IAM misconfiguration, exposed storage, serverless and container security, pipeline injection and leaked secrets.
Also available: secure code review, red team engagements, social engineering and phishing simulation, vulnerability assessment, IoT and firmware testing, and smart contract review.
How an engagement works
Step 1
Scope
Send us the targets and any constraints. Within one business day you get a proposal with a fixed price, a timeline and draft rules of engagement.
Step 2
Test
AI-assisted reconnaissance and coverage, then manual testing by a certified tester. We agree testing windows for production systems and keep you updated throughout.
Step 3
Report
An executive summary for leadership, and technical findings with CVSS scores, reproduction steps, evidence and remediation guidance mapped to your compliance framework.
Step 4
Retest
Once your fixes are deployed, we retest the reported findings at no extra cost and issue an updated report.
Pricing
Fixed prices for a defined scope, agreed in writing before testing starts.
Quick Audit
For early-stage startups
$999
- One web application or API
- OWASP Top 10 coverage
- AI-assisted and manual testing
- Executive summary report
- 5 business days
Standard
For SOC 2, PCI DSS or HIPAA preparation
$2,500
- Full web application and API test
- Infrastructure scan
- Report mapped to SOC 2 and HIPAA controls
- Free retest
- 10 business days
Comprehensive
For larger or multi-surface scopes
From $5,000
- Web, API, cloud and mobile
- Red team simulation
- Full compliance mapping
- Executive and technical reports
- Priority support
- Timeline agreed per scope
Every engagement includes a retest of the findings you fix. Larger scopes, multiple applications and full red team engagements are quoted individually.
See a report before you buy
The sample report is a redacted web application and API test. It shows exactly what you receive: an executive summary, a findings table, a full write-up of a critical issue, and remediation guidance.
Contents
Confidential
- 01Executive summary
- 02Scope and approach
- 03Findings summary
- 04F-001: SQL injection in user profile API
- 05What every report includes
Common questions
Anything else, email team@rootdarth.com.
What does AI-assisted mean in practice?
We use AI tooling to map the attack surface, read large codebases and API schemas, and generate test cases faster than a person could by hand. A certified tester does the exploitation, decides what is real and what matters, and reproduces every finding before it goes in the report.
Will our data be shared with AI providers?
Only as agreed in the rules of engagement. Before testing starts we confirm which tools will be used and how evidence and data are stored. If your policy rules out third-party AI services, tell us during scoping.
How much does a penetration test cost?
Fixed-price packages start at $999 for a single web application or API. The Standard package is $2,500 and the Comprehensive package starts at $5,000. Larger scopes are quoted individually after a short scoping exchange.
How long does a test take?
A Quick Audit takes 5 business days and a Standard engagement takes 10. Network and red team engagements usually run 3 to 4 weeks. Expedited timelines are available.
Is testing safe for production systems?
We agree scope, testing windows and limits in the rules of engagement, use non-destructive techniques, and stay in contact throughout the test. We can test a staging environment instead if you prefer.
Can we give the report to our auditor?
Yes. Findings are mapped to SOC 2, PCI DSS, HIPAA, ISO 27001 and NIST controls where relevant, and the executive summary is written for non-technical readers. The report is suitable for audits and enterprise vendor security reviews.
Is retesting included?
Yes. After you fix the reported issues we retest them at no extra cost and issue an updated report.
Request a proposal
Email a short description of what you want tested. It helps to include the targets (URLs, apps, IP ranges or repositories), any testing window, and the compliance standard you are working toward.
- Response
- A scoped proposal with a fixed price and timeline within one business day.
- Confidentiality
- Testing runs under a signed NDA, written authorization and agreed rules of engagement.
- Included
- Executive and technical report, plus a free retest of the findings you fix.