Edit Template
Rapid Pentest · AI-assisted

AI does the sweep. Our engineers do the proving.

AI agents sweep your external network and public web applications. A White Knight Labs engineer validates every finding by hand and writes the report.

STARTING AROUND

$3,500

wkl-agent · rapid-pentest · sample run 00:00:00 RUNNING
WKL Every candidate above is reproduced by hand before it becomes a finding. Nothing reaches your report until a White Knight Labs engineer confirms it.

$3,500

Typical starting price

<5 days

Report turnaround

100%

Findings human-validated

3

Documents, every time

Who built this

The people who train penetration testers built the agent.

45+

Senior and principal operators on staff. No junior testers, no offshore contractors.

Veteran-owned

Founded and run by operators out of the US offensive security community.

We train them

Our courses certify working penetration testers. The agent was tuned against the same labs.

1,500+

Test engagements delivered to date.

Why you're here

You are probably here for one of three reasons

01 / EXTERNAL PRESSURE

A customer is asking

Their security questionnaire wants to know whether you run penetration tests. You need a document, and you needed it last week.

02 / AUDIT PRESSURE

An auditor is asking

SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or whichever framework you answer to. It calls for a pentest, and your auditor wants proof a qualified tester did the work.

03 / YOUR OWN

You are asking

You want to know whether you are exposed. You would rather find the hole yourself than read about it later.

All three get the same thing: a real test, and a report your auditor will accept.

Pick your test

We run two kinds of penetration test. Here is how to pick.

This page

A customer is asking

AI-assisted · engineer-validated
Best when

You need credible evidence for an auditor or a customer, your scope is straightforward, and you want it handled quickly.

Our core services

Full penetration testing and red team

100% human-led · start to finish
Best when

The environment is complex, the stakes are high, or you need a real adversary simulated against your defenders.

Rapid Pentest aims at what an outsider can reach. That focus is deliberate. It is why the agents are tuned the way they are, why the price is fixed, and why the report lands in days.

Work that runs past that edge stays with our operators. If your scope calls for it, we will tell you before you pay and move you to the right engagement. We would rather point you at the right test than sell you the wrong one.

Agent scope widens as each new surface proves out in our labs. Today it is the external edge.

SCOPE · what the agents run against, and what they do not

Rapid Pentest covers
Rapid Pentest covers

That second list is not a gap. It is our core business, and people run it.

Before you buy

What this is not

Three things we would rather tell you now than have you find out after the invoice.

A tool alone is not a pentest

Plenty of vendors sell you a scanner on a monthly plan and leave the output for you to sort out. Nothing here reaches your report until a person reproduces it, and you are buying a finished test rather than a license to run one.

A real pentest, scoped to your perimeter

This is a penetration test. A qualified engineer exploits what the agents surface, proves every finding by hand, and writes the report you hand your auditor. What you are not buying is a red team engagement. No attack paths chained across systems, no business logic abuse, no adversary emulation against your defenders. That work takes an operator days on a single target and it is priced for what it is.

The agents stop at your edge

Internal networks, Active Directory, cloud identity, and anything needing a foothold inside are out of reach here. If that is your scope, this product will not serve you and we will say so on the first call.

If any of those three describe what you actually need, say so on the form and we will move you to a human-led engagement instead. That conversation costs you nothing.

Our AI pentester

We did not license an AI pentester. We built one.

Our agents are trained in-house by White Knight Labs operators on how real intruders actually work. Not a scanner with a language model bolted on. Agents that chase objectives, chain what they find, and know the difference between an open port and a way in.

We trained them against purpose-built lab environments where we already knew every flaw, then kept tuning until they surfaced the ones that mattered and stopped surfacing the ones that did not.

What the agents do on your engagement

01

A tool alone is not a pentest

Sweeps every live host and service for vulnerabilities, then ranks what it finds by what an attacker would actually use first.

02

Tests exposed logins

Checks exposed authentication for weak and reused credentials, at thresholds set with you so nobody gets locked out.

03

Works your objectives

Tell us what would hurt most. Reaching a customer database, landing on a specific host, getting past the edge. The agents work toward it.

04

Goes for code execution

Where a real path to remote code execution exists, we prove it rather than flagging a version number and calling it a day.

05

Proves what holds

A clean result is a result. When the perimeter stands up, you get evidence of what was tried and what it withstood.

06

Hands off to a human

Everything the agents find goes to a WKL engineer for manual reproduction before it becomes a finding in your report.

Limits

Guardrails, because these agents attack for a living

The agents are aggressive by design. That only works if the limits are real. Every one of these is set before the first packet leaves.

RULES OF ENGAGEMENT · signed before testing begins

✓ enforced in the harness

approval_gates = true

A tool alone is not a pentest

Plenty of vendors sell you a scanner on a monthly plan and leave the output for you to sort out. Nothing here reaches your report until a person reproduces it, and you are buying a finished test rather than a license to run one.

hard_stops = true

Hard stops we do not cross

No denial of service, no intentionally taking hosts down, no exploits known to cause damage. Written into your rules of engagement.

lockout_safe = true

Lockout-safe credential testing

Spray thresholds and timing agreed with you in advance, so testing your logins never locks out your staff.

scope_lock = true

Scope enforced in the harness

The agents cannot reach anything outside the addresses and applications you listed. Exclusions are enforced, not requested.

kill_switch = true

A kill switch you hold

One call or one reply and testing halts. You do not need a reason.

Confidentiality

Your findings do not leave our hands

The first question a security buyer asks about an AI pentest is where the data goes. Here is the answer before you have to ask it.

DATA HANDLING · agreed in writing before testing begins

✓ part of your engagement terms

The model OURS

A custom model we built

The agent runs on a model White Knight Labs built and operates. Your scope, your traffic, and your findings are never handed to a commercial chatbot or a third-party AI provider.

Training DISABLED

Your engagement trains nothing

Findings, scan output, credentials, and anything else the agents touch on your engagement are never used to train or tune a model. Not ours, and certainly not anybody else's.

Where it runs = US ONLY

United States infrastructure

Spray thresholds and timing agreed with you in advance, so testing your logins never locks out your staff.

Retention = 90 DAYS

Deleted after 90 days

Raw scan output, agent logs, and working data are held for 90 days after testing completes, then deleted. You keep your documents. We do not keep your attack surface.

Access = ENGINEER ONLY

One person, and no one else

The engineer assigned to your engagement is the only person who can reach your data. Not the wider team, not a sales function, and no third party at any stage.

Every line here goes into your engagement terms. If your security review needs it in a different form, send the questionnaire and we will complete it.

The human half

Agents find things. They do not decide what is real.

Plenty of vendors will run an automated tool against your network, drop the output into a template, and call it a penetration test. Your auditor might accept it. Your enterprise customer probably will not, and an attacker certainly does not care.

The agents cover ground faster than a person can. That is where the time and the cost savings come from. What they do not do is decide what ends up in front of you.

Every candidate finding goes to a White Knight Labs engineer who reproduces it by hand. Anything we cannot reproduce, we throw out. What reaches you is proven, with the steps to repeat it and a fix that works.

What that means for you
The honest tradeoff

An agent sweeps broadly, a human digs deeply. Across an external footprint that trade works in your favor. Inside a complex environment it does not, which is why every engagement past the edge stays fully human-led.

"Simply running an automated tool does not satisfy the penetration testing requirement."

PCI SECURITY STANDARDS COUNCIL

We agree. That is why a person signs yours.

What you get

Three documents, every time

Here is exactly what lands in your inbox, section by section, so you know what you are buying before you buy it.

01 / FOR YOUR ENGINEERS

Technical report

Every finding with the evidence behind it and a fix your team can act on this week.

Inside

PDF · included with every test

02 / FOR YOUR CUSTOMER

Attestation letter

The one page you forward when a customer or an auditor asks for proof.

Inside

PDF · included with every test

03 / FOR THE SIGNER

Executive summary

Written for the person who approves the budget and does not read pentest reports.

Inside

PDF · included with every test

NOTE

We do not publish client deliverables. Every report we produce belongs to the client who paid for it, and it stays that way. If you want to see the format before you commit, ask on the call and we will walk you through the structure directly. That courtesy is the same one you get once you are a client.

Turnaround is measured in days, not weeks. We confirm your delivery date before testing starts

How it works

Four steps, and only one of them is yours

STEP 01

Reach out

Tell us what you want tested. Send scope detail if you have it, or just tell us what you are after.

YOU
STEP 02

Price and paperwork

We come back with a fixed number, a short statement of work, and rules of engagement. Both are brief.

WKL
STEP 03

We test

Agents sweep. An operator validates by hand. Anything critical reaches you immediately.

WKL
STEP 04

You get your documents

Report, attestation letter, and executive summary on the delivery date we agreed.

WKL
Pricing

Around $3,500 to start. Yours depends on your scope.

A small external footprint usually lands near $3,500. Treat that as a rough starting point, not a quote. What you actually pay depends on how much you have exposed and whether you want a web application tested too.

Tell us what you have and we will come back with a fixed number. Once you have it, that is the number you pay.

✓ NO SETUP FEE

Nothing to pay before the quote.

✓ NO PLATFORM FEE

You are buying a test, not a subscription.

✓ NO PER-USER CHARGE

Team size does not change the price.

✓ ALL THREE DOCS

Report, letter, and summary included.

Get started

Two ways to reach us

Start with the short one. If you already know your scope, the second tab adds a few technical details that help us quote you faster.

    What is 6 + 9 ? Refresh icon

      What do you want tested? *

      What is 6 + 9 ? Refresh icon

      Questions

      What people ask before they buy

      Is this a real penetration test?

      Yes. A qualified WKL engineer performs the manual exploitation and writes the report. AI handles the repetitive sweeping, the same way Nmap and Burp Suite always have. The difference between this and our core engagements is not whether a human is involved. It is how much of the work a human drives, and how deep the test goes.

      No. Full penetration tests and red team engagements are human-led from start to finish. Rapid Pentest is a separate product with a deliberately narrower scope.

      No denial of service, no intentionally taking hosts down, and no exploits known to cause damage. Credential spraying runs at thresholds agreed with you. Anything disruptive waits for human approval.

      Yes. It satisfies PCI DSS 4.0 requirement 11.4, and the qualified-independent-tester expectation that runs through SOC 2 Type II, ISO 27001, HIPAA, FedRAMP, CMMC, and most other frameworks. Tell us which one you answer to and we will confirm the fit before you buy.

      You still get the full document set. A clean result with evidence of what was tried is exactly what a compliance requirement asks for.

      Your external network, your public web applications, and your APIs. Anything an outsider can reach without a foothold inside. That is the surface the agents are trained and tuned against, and it is the surface this fixed price covers.

      When the work runs past your external edge. Internal networks, Active Directory, cloud identity, attack paths chained across systems, or a test run against a live defensive team. Those are human-led engagements, and they are what we do most. Send us your scope either way and we will tell you which one fits before you pay for anything.

      Stop guessing about your attack surface

      Tell us what you need tested. We will price it, confirm a start date, and put you in touch with the White Knight Labs engineer who will run your test. If your scope runs past the external edge, we will say so and point you at the human-led engagement that fits.

      Edit Template