What do I get with the free live test?+
An initial assessment of one public website, a summary of what was checked, and a prioritized report of findings with suggested next steps. It is a limited first look, not a full authenticated penetration test. We confirm your ownership and the testing scope before starting.
How do AI models and security experts work together?+
AI models help explore the agreed attack surface, investigate potential weaknesses, and organize evidence. Security experts validate reportable findings, assess the real-world impact, and review the recommended fixes. We evaluate newer models before adding them to the workflow.
Can you test a website built with AI?+
Yes. Whether you built with an AI coding tool, a framework, or a development team, the important question is how the deployed application behaves. For deeper testing, we agree on test accounts and access to the relevant workflows.
Will testing affect my live website?+
Testing is scoped with you first, including rate limits, excluded routes, and a suitable test window. Destructive tests are excluded from the initial assessment. For deeper workflows, we may recommend a staging environment and test accounts.
What is the difference between a pentest and ongoing testing?+
A penetration test is a scoped engagement with deeper investigation and an expert-reviewed report. Ongoing testing repeats agreed automated checks daily or weekly, tracks changes, and routes new findings for review. A daily scan is not a new full manual pentest every day.
Which plan includes GitHub code and deployment testing?+
GitHub-connected coverage is planned as an included part of the paid Ongoing testing subscription, on both weekly and daily schedules. It covers selected-repository code checks and deployment-triggered website tests. The free assessment and one-time Website pentest do not include the recurring GitHub workflow. The integration is not yet available; repository and environment scope, scan capacity, and expert-review allowance will be agreed in your quote.
What happens when I deploy new code?+
The planned workflow checks pull requests for code flaws, vulnerable dependencies, and exposed secrets. Once a successful deployment is confirmed, it matches the actual commit to the enrolled website and runs the full agreed automated suite for that environment. Findings and retests stay linked to the release. An eligible deployment must have an enrolled target and agreed access; expired previews, failed authentication, or unfinished scans are reported as incomplete, not as a pass.
Do I need the daily schedule for deployment-triggered tests?+
No. GitHub-connected release testing is planned for both Ongoing testing schedules. Weekly or daily controls scheduled checks between releases; confirmed deployments trigger their own tests within the agreed capacity. The planned first integrations are Vercel and a post-deploy CI callback. Production and preview environments have separate agreed scopes, and a full automated suite does not mean a new manual pentest on every deployment.
Does a clean report mean my website is completely secure?+
No. Every assessment has a defined scope and a point in time. Reports explain what was tested, what could not be tested, and what remains uncertain. Ongoing testing helps you revisit that picture as your application changes.