One platform · external + continuous

Penetration testing,
end to end.

A modern pentesting platform that goes beyond the once-a-year PDF. Run an audit-credible external pentest for your SOC 2 or HIPAA evidence package, then drop a Trustivum Sentry on your LAN for continuous internal coverage the other 364 days.

SOC 2 + HIPAA mapped Branded PDF reports Free retest, every external Sentry: drop-in, no install
EXTERNAL PENTEST XSS in /searchHIGH Weak TLS cipherMED SSH config hardenedOK DNSSEC validOK SENTRY · CONTINUOUS scanning · LAN 3 new findings → portal
$2,495
Flat external pentest — limited scope
7 days
Business-day report turnaround
3 tiers
External · Sentry · Sentry Pro
365
Days of coverage with a Sentry
The gap

An annual test sees one day. Attackers get 365.

Every SOC 2 or HIPAA audit circles the same line: “provide evidence of penetration testing.” Traditional firms quote five figures and weeks of scheduling for a report your auditor skims in minutes — and the rest of the year goes unwatched.

Day 0 annual test 364 days blind — new deploys, new CVEs, drifted configs ▸ WITH A SENTRY: scheduled scans all year Day 365 next test
Three ways to use it

Pick where you want coverage. Or pick all three.

Most teams start with the external pentest — that's what the auditor circled. Then they add a Sentry once they remember the year has 364 more days in it.

Tier 1 · External
External Pentest
$2,495 flat

A one-shot, audit-credible external pentest mapped to SOC 2 and HIPAA — the thing your auditor wants in the evidence package.

  • Up to 3 external assets (web apps, APIs, domains)
  • Automated scanning + manual analyst verification
  • Branded PDF report with confidentiality stamp
  • SOC 2 + HIPAA control mapping on every finding
  • One free retest within 30 days
  • 7-business-day turnaround
Request a Pentest
RECOMMENDED Tier 2 · Continuous
Sentry Standard
Drop-in appliance

Plug it in and it runs scheduled internal-network scans for the rest of the year. No install, no firewall changes.

  • Compact appliance, ships pre-imaged
  • Connects automatically over a private mesh
  • Discovery, CVE checks, share & service scans
  • Weekly or monthly scan windows, configurable
  • Findings stream live to your customer portal
  • Quarterly trend report for board + audit
Talk to us about Sentry
Tier 3 · Pro
Sentry Pro
Deep coverage

A high-performance appliance with a full enterprise-grade authenticated scanner on board, for credentialed internal assessment.

  • Full vulnerability scanner runs on-prem
  • Tens of thousands of checks
  • Authenticated web-application crawling
  • Credentialed scans against your hosts (insider view)
  • Customer data never leaves the LAN — only metadata
  • Includes everything Sentry Standard does
Request Sentry Pro
How an engagement runs

Request to report in five steps.

RequestScopeScanReportRetest tell us the assetsfixed, agreed scopeautomated + manualbranded, mapped PDFfree within 30 days 12345
What lands in your evidence package

A report your auditor accepts — and your team can act on.

Every finding is verified by an analyst before it reaches the page, written in plain English, and mapped to the exact control it satisfies.

Severity & CVSS

Each finding ranked and scored, so you fix what matters first.

SOC 2 + HIPAA mapping

Every finding tagged to the Trust Services Criteria or HIPAA control it touches.

Branded, confidentiality-stamped PDF

Client-ready output you can hand straight to an auditor or a prospect's security team.

Remediation + free retest

Clear fix guidance, then a no-charge retest within 30 days to prove it's closed.

YOUR LAN hosthosthosthost SENTRY scheduled scans → findings to your portal
Trustivum Sentry

Continuous coverage in a box.

A drop-in appliance that joins our private mesh network and runs industry-standard host-discovery, vulnerability, and internal share-exposure scans inside your LAN on a schedule. Findings stream into your portal with severity, CVSS, and remediation.

  • 🔒 Two AND'd locks — private-mesh membership and a per-device bearer token on every request
  • 🧱 No inbound firewall changes — the appliance reaches out; nothing reaches in
  • 📈 Quarterly trend reports — board- and audit-ready, out of the box
Questions

What auditors and founders ask.

Is the report accepted for SOC 2 and HIPAA audits?

Yes. Every finding is mapped to the relevant SOC 2 Trust Services Criteria or HIPAA control, and the branded, confidentiality-stamped PDF is built to drop straight into your evidence package.

What's the scope of the external pentest?

Up to three external assets — web applications, APIs, or domains — with automated scanning plus manual analyst verification. It's a limited-scope, fair-priced engagement designed around what audits actually require.

Do I have to install anything for Sentry?

No. The Sentry appliance ships pre-imaged, connects automatically over a private mesh, and needs no inbound firewall changes. Plug it in and scans run on your schedule.

What if you find something — do I pay for a re-check?

No. Every external pentest includes one free retest within 30 days, tracked through the platform from finding to remediation to verification.

Does our data leave the network with Sentry Pro?

No. Sentry Pro runs a full authenticated scanner on-prem; only finding metadata leaves the LAN. Your customer data stays inside.

Start here

Get the pentest your auditor is asking for.

Tell us your assets and we'll scope a fixed-price external pentest — report in seven business days, free retest included. Add a Sentry when you're ready for the other 364.

Request a Pentest → See the full platform