Code badge

Startup PentestSHIP FAST. TEST FASTER.PAY ONLY FOR IMPACT

Built for startup speed: launch your penetration test in minutes, receive a compliance-ready report in 5 days, and only pay if we find an impactful vulnerability (CVSS ≥ 4.0).

What's included

What our startup pentest covers

External Attack Surface

Web apps, APIs, domains, subdomains, and IPs.

200+ Vulnerability Classes

OWASP Top 10, business logic flaws, authentication bypasses, injection attacks, mapped to CWE and CVSS 4.0.

Compliance-Ready Report

Structured report accepted for ISO 27001, SOC 2, PCI-DSS, and DORA audits.

Powered by AI

Hackian validates each finding with a proof-of-concept exploit and keeps false positives near zero.

Universidade do PortoSumol CompalNOSRenaultLeroy MerlinANAUniversidade do PortoSumol CompalNOSRenaultLeroy MerlinANA

FROM REQUEST TO PENETRATION TEST IN 5 DAYS

You select the assets you want to be tested, and Hackian gets to work immediately. We'll deliver a complete pentest report after 5 days, and you're only charged if we find an impactful vulnerability (CVSS ≥ 4.0).

Unlike traditional pentesting firms that schedule weeks out, our AI pentesting service launches in minutes - no NDAs to negotiate, no project kick-off calls.

T+0

Select your assets

Choose any public facing domains, IPs, or subdomains you want tested.

T+15 min

Hackian AI Pentester gets to work

Hackian, our AI penetration testing agent, autonomously probes your attack surface testing web apps, APIs, and network services across 200+ vulnerability classes aligned with OWASP and PTES methodologies.

T+5 days

Get your report in 5 days

Compliance-ready report delivered. You're only invoiced if we find a CVSS >= 4.0 vulnerability.

Trusted by those who can't afford to lose

"We have lots of security solutions, but I look at Ethiack first, because I know that when Ethiack alerts us, it's always valid and most probably serious!"
Pedro Zeferino

Pedro Zeferino

CISO @ NOS

"They quickly identify vulnerabilities even with our fast frequency of deployment. We can sleep better at night knowing that if something shows up, we'll know right away."
Paulo Ribeiro

Paulo Ribeiro

VP of Engineering @ Smartex

"Their in-depth testing of our systems has transformed how we approach cybersecurity. Ethiack teaches us to think like attackers."
João Annes

João Annes

CISO @ ANA Airports

"As the CEO of Zick Learn, I believe it's my role to make our company secure, not just today, but also tomorrow and the day after tomorrow. We treat a lot of client data, and protection is part of the product. Ethiack makes it possible for us to offer maximum security on every layer."
Matteo Penzo

Matteo Penzo

CEO @ Zicklearn

Who supports your startup launch?

We're developing the AI Hacking Agent that will protect organizations from AI-enabled threats. Born in Europe, we deliver professional penetration testing services to dozens of organizations and institutions - 24/7, at machine speed, with the precision of the world's best ethical hackers.

Pentesting reports accepted for

ISO 27001SOC 2PCI-DSSDORA

99.5%

Accuracy in finding exploitable vulnerabilities

100k+

Vulnerabilities identified with proof-of-concept exploit

75%

PortSwigger labs solved by our AI

200+

Different vulnerability classes covered (CWEs)

30x

Faster than a manual pentest

THE STARTUP PRICE FOR SERIOUS SECURITY

You're only charged if we find a CVSS >= 4.0 vulnerability. Even if we find nothing, your team gets a complete external pentest report to support launch readiness and compliance workflows.

+Start startup pentest

But how can this be free?

Because our AI is really good. It shocked DEFCON when it found 2 critical vulnerabilities, unassisted, during a live CTF, or when it found a one-click RCE on OpenClaw in under 2 hours.

We've made the math, and the chances of finding an impactful finding in your assets is so high we can give you this guarantee.

Startup launch offer

€8,000

€4,000

Spring Offer - 50% off

Traditional penetration tests cost
€15,000-€30,000+. Ours? Free if we find nothing.

  • One-time payment
  • Results in 5 days
  • Full pentest report
  • Compliance-ready
  • Pay only if CVSS >= 4.0 found

Frequently Asked Questions

What's an impactful vulnerability?

Any exploitable finding with a CVSS score ≥ 4.0.

Can I choose which assets to test?

Yes, you can select any public facing assets you want tested.

Will you withhold findings if we don't pay?

No, it's not ethical. You'll know of any findings we uncovered.

Can you test internal assets or mobile apps?

Not under this offer. Available as separate add-ons.

What if I already know about these vulnerabilities?

We assume that you patch findings as soon as they're uncovered, but you can let us know during sign up about any existing vulnerabilities.

Do I still get a report if you find nothing?

Yes, you'll get a compliance-ready pentest report no matter the outcome.

Do I need to install anything?

No installation required. We verify your ownership of the assets through a DNS record.

What penetration testing services does Ethiack offer?

Ethiack offers external penetration testing services for web applications, APIs, domains, subdomains, and network assets. Our AI-driven pentesting service (Hackian) covers 200+ vulnerability classes including the OWASP Top 10 and delivers a compliance-ready report in 5 days. Optional gray-box testing with authenticated sessions is available as an add-on.

What methodology does your penetration testing follow?

Our penetration tests are accepted for ISO 27001, SOC 2, PCI-DSS, and DORA compliance audits. Hackian, our AI pentesting agent, autonomously discovers and exploits vulnerabilities - including injection flaws, broken authentication, business logic issues, and misconfigurations - and validates each finding with a proof-of-concept exploit before reporting.

Is this pentest valid for compliance?

Yes, reports are compliance-ready for various frameworks including ISO 27001, SOC 2, PCI-DSS, and DORA.

SUBMIT AND START PENETRATION TEST

Submit the form and we'll begin your penetration test immediately. Your compliance-ready report will be ready in 5 days.

  • Compliance-ready report guaranteed
  • Pay only if CVSS >= 4.0 vulnerability found
  • Results delivered in 5 days

Gray Box Testing (optional)

Startup offer: get tested for €4,000. Limited-time campaign.