> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Penetration Testing as a Service: PTaaS on Hackrate

> Run structured penetration tests on Hackrate with verified ethical hackers — real-time findings, compliance-ready outputs, and HackGATE™ monitoring.

Penetration Testing as a Service (PTaaS) on Hackrate gives you the depth and discipline of a structured penetration test without the operational overhead of managing an external pentest engagement from scratch. Hackrate coordinates a focused team of verified ethical hackers, manages the testing timeline, and delivers real-time visibility into findings through the platform — so your security and engineering teams can begin remediation before the final report is even written.

## What makes PTaaS different from bug bounty

Bug bounty programs are open-ended and continuous: researchers test whenever and however they choose, within your defined scope. PTaaS is structured and time-boxed: a defined team tests a defined scope during a defined window, following a systematic methodology.

|                          | PTaaS                                                        | Bug Bounty                                         |
| ------------------------ | ------------------------------------------------------------ | -------------------------------------------------- |
| **Testing window**       | Fixed engagement period (days or weeks)                      | Ongoing / continuous                               |
| **Researcher selection** | Curated team selected by Hackrate                            | Community-driven; researchers apply or are invited |
| **Methodology**          | Structured, systematic                                       | Creative, adversarial                              |
| **Output**               | Formal engagement report + real-time findings                | Individual vulnerability reports                   |
| **Best for**             | Compliance audits, pre-launch reviews, deep-dive assessments | Continuous coverage across an evolving product     |
| **Pricing model**        | Project-based                                                | Platform fee + bounties                            |

<Note>
  PTaaS and bug bounty are complementary, not competing. Many organizations run both: PTaaS for structured assessments aligned to compliance cycles, and bug bounty for continuous coverage between formal tests.
</Note>

## Why PTaaS on Hackrate

### Verified researchers

Every researcher who participates in a PTaaS engagement on Hackrate has been identity-verified using KYC (Know Your Customer) services. Hackrate's Elite Club — a curated group of the highest-performing and most trustworthy researchers on the platform — is the preferred pool for PTaaS engagements. Researchers hold industry-recognized certifications including OSCP, OSCE, CISSP, and CEH.

<Tip>
  You are not working with an anonymous crowd. You know who is testing your systems, and those individuals have agreed to strict non-disclosure and professional conduct requirements.
</Tip>

### Real-time visibility into findings

Unlike traditional penetration tests where you receive a report weeks after testing concludes, Hackrate's PTaaS delivers findings in real time. Every vulnerability a researcher submits appears in your dashboard immediately. Your team can begin triaging and remediating critical issues while testing is still ongoing — dramatically shortening the time between discovery and fix.

### HackGATE™ monitoring

For organizations that require the highest level of transparency and control over their security testing, Hackrate offers integration with **HackGATE™** — a managed gateway appliance purpose-built for monitoring pentest projects. HackGATE is the industry's first comprehensive solution for monitoring ethical hacker activity during a testing engagement.

With HackGATE, you gain:

* Full visibility into the network traffic generated by testers
* Assurance that researchers are staying within the agreed scope
* Detailed audit logs of testing activity for compliance and legal purposes
* The ability to pause or terminate testing activity instantly if needed

<Note>
  HackGATE is available as an add-on to PTaaS engagements. Contact the Hackrate team to learn more about deployment options and requirements.
</Note>

### Flexibility across asset types

PTaaS on Hackrate supports a wide range of asset types:

<CardGroup cols={2}>
  <Card title="Web Applications" icon="globe">
    Full black-box, grey-box, or white-box testing of web applications, including authentication, business logic, API endpoints, and client-side security.
  </Card>

  <Card title="APIs" icon="code">
    REST, GraphQL, and SOAP API assessments — covering authentication, authorization, input validation, and data exposure.
  </Card>

  <Card title="Mobile Applications" icon="mobile">
    iOS and Android app assessments including static analysis, runtime testing, local data storage, and network communication security.
  </Card>

  <Card title="Network & Infrastructure" icon="network-wired">
    Internal and external network assessments, firewall rule reviews, and infrastructure hardening checks.
  </Card>
</CardGroup>

## How a PTaaS engagement works

<Steps>
  <Step title="Scoping and planning">
    The Hackrate team works with you to define the engagement scope, testing objectives, and timeline. You specify which assets should be tested, any restrictions (for example, production vs. staging environments, off-limit functionality, testing hours), and the depth of assessment required. A clear scope document is agreed upon before testing begins.
  </Step>

  <Step title="Researcher selection and onboarding">
    Hackrate selects a team of 5 to 20 verified researchers with the skill sets most relevant to your target assets. For specialized engagements — for example, a mobile app with specific iOS exploitation requirements — the team is assembled accordingly. Researchers sign NDAs and are briefed on the engagement rules before access is granted.
  </Step>

  <Step title="Testing and real-time reporting">
    Testing begins on the agreed start date. Researchers submit findings through the Hackrate platform as they are discovered. Each report is structured with title, severity, affected asset, reproduction steps, supporting evidence (screenshots, proof-of-concept code), and remediation guidance. Critical findings are flagged immediately for your team's attention.

    <Tip>
      You can communicate directly with the researcher who submitted a finding through the platform's messaging thread. This is especially valuable for understanding complex exploitation chains or requesting additional evidence.
    </Tip>
  </Step>

  <Step title="Remediation and retesting">
    Once your engineering team has addressed a finding, you can request a retest from the researcher who originally identified it. Retesting confirms that the fix is effective and that the vulnerability cannot be reintroduced through a variant of the original attack.
  </Step>

  <Step title="Final report and sign-off">
    At the conclusion of the engagement, Hackrate produces a formal engagement report summarizing all findings by severity, including evidence, impact descriptions, and remediation guidance. This report is structured for executive, engineering, and compliance audiences.
  </Step>
</Steps>

## Compliance-ready outputs

PTaaS engagements on Hackrate are designed to satisfy the evidence requirements of major compliance frameworks. The structured findings, severity ratings, and formal report are directly usable as supporting documentation for:

<CardGroup cols={2}>
  <Card title="ISO 27001" icon="certificate">
    Demonstrates regular penetration testing as required by Annex A controls on vulnerability management and technical compliance review.
  </Card>

  <Card title="SOC 2" icon="file-shield">
    Supports the availability, integrity, and confidentiality criteria by providing documented evidence of proactive security testing.
  </Card>

  <Card title="PCI DSS" icon="credit-card">
    Satisfies Requirement 11.3 for penetration testing of the cardholder data environment and associated systems.
  </Card>

  <Card title="NIS2 & GDPR" icon="shield-check">
    Supports organizational obligations around risk management, incident prevention, and data protection by design.
  </Card>
</CardGroup>

## Integrations for streamlined workflows

Vulnerability findings from PTaaS engagements can be pushed directly to your existing development and operations tooling:

* **Jira Cloud** — Automatically create Jira issues from Hackrate reports, keeping your engineering team's workflow in one place
* **GitHub** — Create GitHub issues or security advisories directly from reports, with status syncing when issues are closed or reopened
* **Microsoft Teams** — Receive real-time notifications in your Teams channels when new findings are submitted
* **Slack** — Get instant Slack notifications for new reports and status changes
* **Zapier** — Connect Hackrate to thousands of other tools through Zapier webhooks

Configure integrations from the **Integrations** section of your program management page.
