Framework Pentesting Contracts
Pentesting as a Service (PtaaS) is not a new concept for us – but has been established practice for many years. Long before the term became a buzzword, we were already continuously performing penetration tests throughout the year under framework agreements. For example, we test new functionalities, modified components, or set a new focus in coordination with the customer – on a monthly, quarterly, or semi-annual basis.
Pentesting as a Service also does not mean the use of an automated tool, but still the execution of a full, manual penetration test by experienced penetration testers. The difference lies in the objective – instead of testing the entire scope once a year, the tests are carried out several times a year, and the focus is dynamically adjusted to the customer’s current requirements. The advantage is also that, as a pentest service provider, one works very closely and repeatedly with the customer and their products, thereby building up a high level of experience and efficiency. In addition, the framework agreement – or, as a buzzword, Pentesting as a Service – ensures revenue, and this commitment is in turn rewarded with a price discount. In the past, it was called a “pentest framework contract” – now many call it Pentesting as a Service or even agile penetration testing.
Your advantages with
binsec GmbH
As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.
Contact usMore than 10 years of practical experience in penetration testing
No subcontractors or external freelancers
Direct communication with the responsible senior penetration tester
Structured, documented, and reproducible testing methodology based on PTDoc®
Fully controlled in-house pentesting infrastructure, no cloud services used
Local LLMs on own hardware in German data centers
Identification of technical and business-relevant security risks
Risk-weighted vulnerability assessment or CVSS based scoring
Report including executive summary and detailed technical section
Retesting of identified vulnerabilities included
Your advantages with
binsec GmbH
As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.
More than 10 years of practical experience in penetration testing
No subcontractors or external freelancers
Direct communication with the responsible senior penetration tester
Structured, documented, and reproducible testing methodology based on PTDoc®
Fully controlled in-house pentesting infrastructure, no cloud services used
Local LLMs on own hardware in German data centers
Identification of technical and business-relevant security risks
Risk-weighted vulnerability assessment or CVSS based scoring
Report including executive summary and detailed technical section
Retesting of identified vulnerabilities included
Approach: Standard-Compliant & Reproducible
A penetration test is a structured attack on IT systems or applications to identify potential vulnerabilities. It uses the same tools and techniques that real attackers would use to break into a system. Thus, a penetration test is not an automated vulnerability scan. On the contrary, a penetration test as a service is always a combination of using security tools and conducting manual tests to uncover vulnerabilities. While a real attacker only needs to find and exploit a single vulnerability, a penetration tester checks all relevant attack vectors.
Having a structured approach is one of the most important factors. For this purpose, we use our own platform PTDoc®, a specialized pentest documentation tool that logs all manual testing steps in full compliance with all relevant security standards and translates them into a clear, reproducible report for you. Since this tool significantly reduces the overhead of report generation, it allows us to focus entirely on our core mission as pentesters: identifying and analyzing critical security flaws. This is particularly relevant when conducting Pentesting as a Service (PtaaS). Our approach is based on all relevant standards and publications.
How We Work During Pentesting as a Service (PtaaS)
From Planning to Re-Testing
Preparations
We coordinate the technical and organisational framework for the penetration test, communication channels, points of contact and testing windows. Depending on the project, this is done through a kick-off meeting or a brief exchange via e-mail. Where required, the client provides relevant technical documentation and access to the systems within scope.
Conducting
The penetration test is performed using a structured and risk-oriented assessment approach that combines automated analysis techniques with extensive manual testing. The specific test cases and assessment procedures depend on the actual conditions, technologies and attack surface encountered within the target environment.
Reporting
After the assessment, we prepare a detailed report including an executive summary, risk ratings, technical details and remediation recommendations. Findings are documented in a clear and reproducible manner and critical issues are communicated immediately during the engagement if required.
Debriefing
We are happy to review the findings and recommendations together with your team. During the debriefing, we explain technical details, potential impacts and remediation priorities, while answering questions and discussing next steps.
Re-Testing
After remediation, we verify whether the identified findings have been successfully resolved and update the report accordingly. Re-testing is generally included for remote assessments and provides assurance that the implemented measures are effective.
Request a Quote for Pentesting as a Service (PtaaS)
Planning a penetration test always requires a careful balance between the time invested in testing and the financial framework to achieve a reasonable price-performance ratio. Successful pentests are characterized by a precise balance between these factors, as this is the only way to guarantee a reliable review of all relevant attack vectors. The time required depends on the size and complexity of the scope. While analyzing a small web application without complex permission structures often takes just a few days, auditing extensive corporate networks can take several weeks.
To provide a tailored pentest offer, we require initial information regarding the systems and applications to be examined, allowing us to accurately assess the target environment. For web applications, providing test credentials is highly beneficial. Any additional technical details, such as the frameworks and technologies utilized, help us design the ideal testing scenario for you. If you require an infrastructure penetration test, we will need the relevant network addresses in advance. In this case, we will first perform a non-invasive network scan to conduct an initial scoping analysis, which forms the basis for your detailed quote.
binsec GmbH is a German pentest company for professional penetration testing. Contact Us for a Quote for Pentesting as a Service (PtaaS), Get your pentest today!
Contact us
Penetration Testing at binsec GmbH
The key questions for anyone commissioning a penetration test – from cost and execution to data protection.
Most companies that regularly perform penetration tests opt for an annual cycle. On one hand, various standards require annual testing; on the other hand, an annual penetration test can be easily integrated into budget planning. Conducting a penetration test every nine months, for example, would be difficult to align with financial planning. A semi-annual schedule — meaning two tests per year — is often too expensive for most.
However, there are companies that conduct penetration tests twice a year, focusing on different aspects each time. From a security and risk management perspective, it would be ideal to perform a penetration test after every significant system change. In practice, however, this often fails due to limited personnel and financial resources.
One possible solution is to establish a framework agreement for penetration testing, often referred to by the buzzword Pentesting as a Service. In this model, recurring tests are performed at defined intervals – for example, quarterly or semi-annually – with the scope adjusted each time to reflect current changes or specific focus areas. This makes it possible to review security-relevant developments on a regular basis without having to initiate a new individual engagement for a full penetration test each time.
The cost of a penetration test depends on scope, complexity, and manual effort – for example the number and type of target systems, the depth of the analysis, and the scope of the report. Because a genuine, manual pentest is individual, we replace blanket hourly rates with a transparent fixed-price quote for your specific target environment.
A detailed, transparent breakdown by scope, method, and effort is available in our article on pentest costs.
A penetration test provides more than just technical details. It establishes a reliable basis for understanding and developing IT security as part of overall corporate governance. Organizations benefit on several levels.
- Transparency: Clear visibility into existing vulnerabilities, the attack surface, and the actual security posture.
- Prioritization: Structured assessment by risk and impact, enabling targeted allocation of resources.
- Effectiveness check: Verification of whether existing security controls such as firewalls, WAFs, or endpoint security function as intended.
- Strategic planning: A solid basis for investment decisions and for further developing the security strategy.
- Compliance and assurance: Support in meeting regulatory requirements (e.g., ISO 27001, TISAX, NIS2, PCI DSS) and providing objective evidence to customers, partners, or auditors.
- Response capability: Insights into how quickly and effectively internal teams react to simulated attacks.
The essential benefit is that organizations can assess their security posture not only in theory, but in practice and in a verifiable manner. This enables realistic risk evaluation and well-founded prioritization of mitigation measures.
A common question from clients is: Why does binsec GmbH consistently uncover vulnerabilities in penetration tests that other providers have missed?
The answer is PTDoc – our internal tool for the structured execution and documentation of penetration tests. Developed by binsec systems GmbH and maintained within the binsec group, it was created to address a central challenge: How can quality remain consistently high as the team grows and individual testers have different personal focus areas? And how can we ensure that results are always identical and reproducible, regardless of which senior penetration tester performs the assessment?
PTDoc provides the solution: standardized methodologies for different targets – from Active Directory to mobile applications to networks. Established standards such as the OWASP Testing Guide, MASVS, and OSSTMM are continuously integrated. At the same time, the experience of our testers is embedded in the test steps: new checks are regularly added and made immediately available to the entire team.
In practice, this means:
- binsec uncovers vulnerabilities that others miss. Over the past years, we have repeatedly identified findings that were overlooked in previous tests.
- PTDoc relieves binsec’s testers: They can fully focus on executing the test, while documentation, evidence management, and report generation are handled efficiently in the background.
- Reports are fast and multilingual: PTDoc supports both German and English reporting – and can deliver results in both languages if required.
This is the secret behind binsec pentesting: a systematic approach that combines standards and experience, ensures quality and repeatability – and delivers the decisive difference for clients. One client summarized it this way: “Since working with binsec, I don’t even consider the previous tests from other providers to have been real penetration tests.”
Before a penetration test is conducted, it may be necessary to establish contractual agreements addressing data protection requirements. This ensures compliance with legal regulations (e.g., GDPR) and clearly defines the responsibilities and obligations between the client and the penetration tester. The scope of personal data processing during a penetration test largely depends on the specific objectives of the engagement. The following types of personal data may be processed during a penetration test:
Personal Data of One or More Client Contacts
This typically includes the first name, last name, business email address, business phone number, and position within the company. These personal details are usually stored and processed in email clients, on mail servers, within phone systems, in calendar entries, and in the final penetration test report. It may sound trivial – and in this case, it is – but this information is necessary for communication between client and tester. Such data is always processed and is often publicly available anyway.
-
Personal Data of Other Employees
When the objective of the penetration test targets the corporate network, contact with employee personal data is often unavoidable. For external penetration tests, this is less common, but for internal tests, especially those involving Active Directory, it is almost inevitable. At a minimum, tester may obtain the names of employees. A common part of internal testing involves attempting to escalate privileges or gain access to additional accounts and systems. If successful – which becomes more likely as the number of employees increases – the tester may obtain valid passwords or at least password hashes. To conduct the test, at least this data must be processed locally on the tester's device. Further escalation, such as account compromise or bypassing access controls, may expose even more information. In the worst-case scenario, such as a full compromise of Active Directory, a large volume of personal data could become accessible. However, it is not necessary to copy this data to the penetration tester's systems – quite the opposite: it should be avoided wherever possible. There is no operational need to do so.
Personal Data of the Client’s Customers
Personal customer data may be encountered when production systems are tested. A straightforward example is an online store. Securing customer data in such systems is a primary goal of penetration testing. Part of the test is to determine whether it is possible to gain unauthorized access to customer records. If successful, individual customer data entries may be temporarily displayed and thus processed locally on the tester’s device.
In the latter two cases, it may be advisable to conclude a data processing agreement (DPA). The focus should always be on the principle of data minimization. A penetration tester is – obviously – not a malicious attacker, and there is no need to process significant volumes of personal data. Only for reporting purposes is it necessary to find a reasonable compromise between anonymization and pseudonymization. For example, if login credentials are successfully obtained during the penetration test, they must be included in the report to provide the client with the relevant information. However, these credentials should not be linked to specific individuals.
Penetration tests generate sensitive information: technical details about systems, configurations, vulnerabilities, user accounts, and internal structures. It is therefore essential to define not only where but also how this data is processed.
All processing takes place within a controlled, self operated infrastructure in Germany. Operations run from a data center in Frankfurt am Main and are complemented by a physically separate hot standby location to ensure redundancy and high availability. Project data is not processed in public cloud environments and is not transferred to unspecified third countries.
Own IPv4 and IPv6 address space is operated. As a Local Internet Registry, an independent network and routing infrastructure is maintained using enterprise hardware including Juniper networking components. Hypervisor and storage systems are fully operated under direct technical control.
Project data is handled exclusively within dedicated, segmented systems. Access is strictly role based and limited to the senior penetration testers involved in the respective engagement. Collected data typically includes:
- technical test notes and analyses
- screenshots and evidences
- draft and final reports
All laptops used are fully encrypted. Project data is deleted locally from tester systems after completion. Central documentation and management of all findings takes place exclusively within PTDoc as the controlled core system. This combination of self operated infrastructure, strict access separation, encrypted endpoints and structured documentation processes ensures that data processing remains controlled and traceable.
Pentesting
for specific standards and requirements
There are a lot of standards or legal requirements worldwide, that require conducting of a penetration test.
binsec GmbH: Professional Penetration Testing
Pentesting as a Service (PtaaS)
As a specialized provider for penetration testing, binsec GmbH focuses specifically on your Pentesting as a Service (PtaaS).
Talk directly to the executing experts instead of sales consultants. Better pentesting. No nonsense. As a dedicated penetration testing firm, we do things differently: We do not sell automated vulnerability scans as a true pentest, focusing instead on manual analysis of complex business logic flaws. Looking for a professionally conducted penetration test? Let's discuss your project.
Contact us
Frequently Asked Questions
It is difficult to give an generalized answer to this question, since the toolset used basically depends on the respective test object. Of course, we use tools such as nmap to check IT infrastructures or the Burp Suite Professional in the case of web applications.
However, we believe that publishing a tool list is mere window dressing, as each target system should be tested individually. However, you are welcome to ask us about the tools we used after the pentest.
Hosting critical business applications on a cloud provider such as Amazon AWS, Microsoft Azure, Google Cloud Hetzner Cloud or STACKIT Cloud is becoming increasingly common.
Of course we perform penetration tests for applications hosted in the cloud. This also applies to penetration testing of cloud-based IT infrastructures, provided that the virtual machines are not managed directly by the cloud provider.
We perform penetration tests for almost any IT environment, system, application or network – right down to protocol fuzzing. Only the analysis of hardware chips under a microscope is something we leave to others.
Typical targets of our penetration tests include:
Web Applications and APIs
Mobile Applications
Servers, Platforms and Infrastructure
- Webserver Pentesting
- Network Pentesting
- Firewalls Pentesting
- WiFi / WLAN Pentesting
- Active Directory (AD) Pentesting
- RDP Server / Remote Desktop Pentesting
- OT Pentesting
Containers and DevOps
Identity and Authentication