All capabilities
Fig 2.1

Pentest

A graded security pass you can hand to a customer.

Pentest is a one-time Optics add-on that finds the way into your own app before someone else does. Every weakness comes back rated by how much damage it could do, tracked until it is fixed, and the whole run graded A+ to F — with a report you can hand to a customer who asks.

§ 01 · How it works
01

Findings carry a state, not just a title

Every finding is open, fixed or accepted. A list of vulnerabilities with no state is a document; a list with state is a piece of work you can finish.

02

The score is weighted, not counted

One critical outranks a pile of lows, and passing checks count toward the total. A run scores out of 100 and carries a letter from A+ to F.

03

Every pass is kept

Runs stack up, so the grade moving from D to A is itself the evidence. That progression is usually what a customer actually wants to see.

§ 02 · What you get

Find the way in before someone else does.

  • Walks you through a full security check of your own app
  • Every weakness rated by how much damage it could do
  • A ready-made fix to hand a developer for each one
  • See whether you are getting safer run after run
§ 03 · The output
You end up with

A report you can send

Each pass has a shareable link showing the grade and the findings summary, without exposing the detail behind them.

Setup
Upload a run from your own tooling. The scoring and the report are what Optics adds.

§ 04 · Pricing
One-time purchase

$299

Pay once and Pentest is unlocked for your whole organization, on top of a Pro or Team plan. Not a subscription, and never priced per run.

Or get all three

Resilience Suite$619

Pentest, Load Testing, and DDoS Resilience in one purchase. 17% off buying them separately — save $128.

See the suite
§ 05 · Questions

What is a pentest run in Optics QA?

It is someone trying to break into your app on purpose, so you find the way in first. Optics walks you through the check, then scores what comes back: every weakness rated by how much damage it could do, marked open, fixed or accepted, and the whole run graded A+ to F with a report you can share.

Do tests run against my infrastructure?

Yes — against your own app, and only yours. Everything runs from your own environment against code and sites you own. What comes back to Optics is the scoring, the tracking, the fixes, and the report you can hand to someone.

Is this a subscription?

No. Pentest is a one-time $299 purchase that unlocks the capability for your whole organization, on top of a Pro ($69/month) or Team ($249/month) plan. You never pay per run.

How is the score calculated?

The score is weighted, not counted: a single critical finding costs more than a handful of lows, and passing checks count toward the total. Each run scores out of 100 and carries a letter grade from A+ to F, so the grade moving from D to A across runs is itself the evidence.

Can I share results with a customer?

Yes. Every run has a shareable report link showing the grade and the findings summary without exposing the detail behind each finding — the artefact a security questionnaire usually asks for.

Is Pentest included in the Resilience Suite?

Yes. The Resilience Suite bundles Pentest, Load Testing, and DDoS Resilience in one $619 one-time purchase — 17% off buying them separately, saving $128. One purchase unlocks all three for your whole organization.