Skip to main content
A Quantum Group company Fixed fees  ·  Boston  ·  London
Thornbury Labs Penetration Testing Book a pentest
Fixed-fee pentest

Pentest booked this week, report in your hands in two

A customer, an auditor or an investor asked you for a pentest. Get a fixed fee in writing today, a named certified tester on your scope, and a report your auditor will accept. No discovery call, and no hourly surprises.

Authorised testing only. We test with your explicit written authorisation, inside a scope and rules of engagement agreed before any testing begins. Unauthorised testing is illegal under the Computer Fraud and Abuse Act (18 U.S.C. § 1030). We do not perform or condone it.

Four questions, about a minute. A written price back, usually within four working hours.

What a pentest costs with us

Fixed fees, agreed in writing before any work starts. So the number you approve is the number you pay.

Web application pentestfrom $5,900
External network pentestfrom $4,900
API pentestfrom $9,800
Internal network pentestfrom $12,500
Mobile app pentestfrom $11,900
Cloud configuration pentestfrom $14,500
Red team engagementfrom $34,000

Every price includes real manual testing hours, a named certified tester, an audit-ready report, an attestation letter and one retest. Because those are the parts that cost money, anyone quoting under $4,000 is selling you an automated scan.

Price my exact scope
Trusted by

The teams who buy a pentest from us

Security and engineering teams book with us to clear audits and customer reviews, and they do it without stalling the roadmap.

  • Cloudflare logo, a client who booked a pentest with Thornbury Labs
  • Snowflake logo, a client who booked a pentest with Thornbury Labs
  • Atlassian logo, a client who booked a pentest with Thornbury Labs
  • ServiceNow logo, a client who booked a pentest with Thornbury Labs
  • MongoDB logo, a client who booked a pentest with Thornbury Labs
  • Accenture logo, a client who booked a pentest with Thornbury Labs
  • Brex logo, a client who booked a pentest with Thornbury Labs
  • Plaid logo, a client who booked a pentest with Thornbury Labs
  • symplr logo, a client who booked a pentest with Thornbury Labs
  • Nebius logo, a client who booked a pentest with Thornbury Labs
  • Tenovi logo, a client who booked a pentest with Thornbury Labs
  • Taimei Technology logo, a client who booked a pentest with Thornbury Labs

Logos are the property of their respective owners.

Packages

Pentest packages, priced before you commit

Pick the shape that matches your scope. However, if none of them fits, send the form and we will build one that does, at a fixed fee.

Essential pentest

One application or one external network. The usual first purchase.

From
$5,900

Fixed fee, one asset in scope

  • 15+ manual hours, stated in your contract
  • Named tester, OSCP or CREST held
  • Audit-ready report and attestation letter
  • One retest inside 30 days
  • Report delivered in 10 working days
Get this priced
Most chosen

Standard pentest

Up to three assets. What most SOC 2 and PCI DSS buyers need.

From
$14,500

Fixed fee, up to 3 assets in scope

  • 45+ manual hours, stated in your contract
  • Web app, API and external network together
  • Live remediation call with your engineers
  • Critical findings reported the same day
  • One retest inside 30 days
Get this priced

Advanced pentest

Full scope, including internal, cloud or mobile. For a real attack picture.

From
$29,000

Fixed fee, scope agreed in writing

  • 90+ manual hours, stated in your contract
  • Internal network, cloud and mobile in scope
  • Attack-chain scenarios, not just a finding list
  • Board-ready summary for your investors
  • Two retests inside 60 days
Get this priced
Q4 books out four to six weeks ahead. Compliance deadlines cluster at year end, so the earlier you send your scope, the more dates you get to choose from.
Why us

Four reasons buyers pick our pentest

None of these are unusual to ask for. However, very few firms will put all four in writing before you sign.

01

Manual hours in the contract

Your contract states the number of hands-on hours you are buying. Because that single line is where most of the price difference between two quotes actually lives, we put it in writing rather than leaving it vague.

02

You meet your pentest tester first

We name the practitioner and the credential they hold before day one, whether that is OSCP, CREST CRT or GXPN. So you know exactly who is on your systems, not just which logo is on the invoice.

03

A retest is included

Fixing something you cannot prove you fixed is not much use in an audit. Therefore one retest is inside every package, and the retest letter is what your auditor actually wants to see.

04

Fixed fee, or we re-quote first

The fee is agreed before work starts, with inclusions and exclusions both written down. If the scope genuinely changes, we re-quote in writing and wait for your approval, so nothing lands on an invoice unannounced.

Before you compare quotes

Pentest or vulnerability scan: what you are paying for

This is where buyers lose the most money. Scans get sold at pentest prices, and the difference only surfaces later, when an auditor reads the report properly.

Vulnerability scan compared with a pentest
 Vulnerability scanOur pentest
Who does itA tool, running on a schedule.A named certified person, on your specific system.
What it findsKnown problems that match a database.Business logic flaws, broken access control, chains of small issues.
ProofA warning, often a false alarm.A demonstrated way in, with the exact steps.
Typical price$2,000 to $10,000$5,900 to $50,000, fixed before you start
RetestRarely included.Always included.
Passes an auditSometimes, until someone reads it closely.Yes. That is what it is built for.
Ask every firm you are comparing how many manual hours are included. If they cannot answer in one line, you are buying a scan at pentest prices.
Ask who will test, by name and credential. We answer that before you sign, in writing, every time.
Ask whether a retest is included or billed separately. That one line explains a lot of the gap between two quotes that look identical.
Your engagement

How your pentest runs, week by week

Five stages, following OWASP WSTG and NIST SP 800-115. So you always know which one you are in, and who is doing the work.

Scope and authorise

We agree what is in, what is off limits, and when. Because authorisation is not optional, you sign it in writing before anything is touched.

Meet your tester

You are told who runs your pentest and what they hold, whether that is OSCP, CREST or GXPN, and you are told before day one.

Manual testing

Three to ten days of hands-on work against your scope. Critical findings reach you the same day rather than waiting for the report.

Report and call

An executive summary a director reads in ten minutes, plus findings with real proof and also specific fixes for the engineers.

Retest

Included in every package, so you can prove the fix worked instead of just claiming it. That letter is what your auditor asks for.

The deliverable

What you get when your pentest ends

The report is the product. In short, it is what your auditor reads, what your customer asks for, and what your investor checks.

Executive summary

Ten minutes, no jargon. What was tested, what the real business risk is, and also the three to five things worth fixing first.

Findings with proof

Each issue in plain language, with severity, the exact request or screenshot that proves it, and the specific fix. In short, not a scanner export.

Pentest attestation letter

A one-page signed letter confirming the work happened and what it covered, so you can share proof but without handing over the findings.

Retest letter

After your fixes, written confirmation of what was closed. That is the document auditors and enterprise buyers actually want to see.

Ask us for a redacted sample before you buy. We will send one. A firm that will not show you a sample report is telling you something, and a report your engineers cannot follow is a report nobody acts on.

Transparent pricing

What changes the price of a pentest

Two quotes that look identical are usually separated by one of the four things below. However, most firms will not volunteer any of them.

Pentest price drivers
DriverEffect on your quote
Scope sizeThe biggest factor by far. Every extra application, API or user role adds testing days.
Manual hoursA $6,000 pentest is roughly 15 hours of human work. A $20,000 one is roughly 60. Most of the gap lives here.
Tester seniorityDay rates run $1,500 to $3,500 in the mid-market, and $4,000 to $7,000 at the top. A Big Four badge costs 2 to 3 times a boutique.
Retest includedOften the single line that explains why one quote looks higher. Ours is always included, so compare like with like.
Your fee is fixed before we start, with the scope written both ways. That is, what is included and what is excluded, because vague edges are how a pentest budget drifts 40 to 60 percent over.
Bundling saves money. Since reconnaissance is shared across assets, testing a web app and its API together costs less than booking two separate engagements.
Your tester

Who runs your pentest, and what they hold

Security buyers have no patience for vagueness. So here is the whole structure, with nothing left out.

Us

Thornbury Labs is the firm you contract with, and also the firm accountable to you. We scope the work, manage the engagement, run quality assurance on every report, and remain your single point of contact throughout.

Your pentest practitioner

Testing is performed by vetted independent practitioners under contract to us, holding credentials such as OSCP, OSWE, CREST CRT and CCT, or GXPN. Although they are not our employees, we name yours before the engagement starts.

What we will not claim

We are not a CREST-accredited company, and we do not describe the test itself as certified, because certifications are held by people rather than by tests. We also cannot promise to find every vulnerability, and neither can anyone else.

The question worth asking any firm. Not "are you certified", but "who specifically will test my systems, and what do they hold". We answer that in writing before you sign, and you can decline the assigned practitioner and ask for another.

Why you were asked

Which rules require a pentest

Most engagements are bought because something demands one. Therefore it pays to scope to the actual requirement instead of guessing at it.

Framework requirements
FrameworkRequired?How often
PCI DSSYes, explicitly (Requirement 11.4)Annually, and every six months for service providers
FedRAMPYes, explicitly (CA-8(2))Annually or after a significant change
CMMCYes, at Level 3 (CA.L3-3.12.1E)At least annually
DORAYes (Articles 24 to 27)Threat-led testing every three years, basic testing annually
SOC 2Not named as mandatory, but expected in practiceAnnually. Around 85 percent of Type II reports include one
ISO 27001Not mandated. Driven by your risk assessmentAnnex A 8.8 and 8.29

One more thing worth knowing. Since independence rules forbid it, the firm auditing you cannot also run your pentest. So buying the two separately is normal and expected, and it is not a sign that anyone is upselling you.

Where we are

Where your pentest is run from

You contract with Thornbury Labs wherever your engagement runs. Because work is coordinated across US and UK hours, findings get discussed the same working day rather than the next one.

Boston

Massachusetts, United States

1 Beacon Street
Boston, Massachusetts
United States

Eastern Time  ·  US engagements

London

United Kingdom

169 Piccadilly
London W1J 9EH
United Kingdom

Greenwich Mean Time  ·  UK and EU engagements

Before you book

Pentest questions buyers ask before booking

How much will my pentest actually cost?

Packages start at $5,900 for one asset and $14,500 for up to three. Most buyers land between $10,000 and $30,000. Send the four-question form and you get a fixed number for your own scope, usually within four working hours.

How quickly can you start?

Usually within one to two weeks, and the report follows about ten working days after testing ends. However, Q4 books out four to six weeks ahead, since compliance deadlines cluster at year end.

Is a pentest the same as a vulnerability scan?

No, and the gap is where most money gets wasted. A scan is automated and matches your systems against a database of known problems. Our pentest puts a named certified person on your system, finding the business logic flaws and chains of issues no tool can see.

Who will actually run my pentest?

A vetted independent practitioner under contract to us, holding credentials like OSCP or CREST. Although they are not our employees, we say so up front and name yours before the engagement starts. You can also decline and ask for a different practitioner.

Will the report pass a SOC 2 or PCI DSS audit?

That is what it is built for. Because scope, methodology and findings are documented the way auditors expect, you also get an attestation letter you can share with customers without exposing the findings themselves.

Can you guarantee you will find everything?

No, and walk away from anyone who says otherwise. A pentest proves what an attacker could do inside the agreed scope and time. But what we do commit to is real manual hours in your contract, a named tester, and a report that survives an auditor reading it closely.

Is there such a thing as a certified pentest?

Certifications are held by people, and accreditations by companies, so a test itself is never certified by anyone. What you should ask for instead is a tester who holds OSCP or CREST, named in writing before you sign. That is exactly what we provide.

Why is there no phone number on this site?

Because four written questions tell us more about your scope than a discovery call would, and it also respects your time. Answer them and you get a fixed price and a scope back rather than a calendar link.

Book now

Book your pentest in four questions

These four answers are genuinely what anyone needs to price the work. So we can send a fixed fee and a scope without putting you through a call first.

A fixed fee in writing, usually within four working hours.
No phone number requested, and no call required to book.
Your tester named before you sign anything.
Quotes are confidential and carry no obligation.
Step 1 of 2

Your scope

Pick “I am not sure” wherever that is the honest answer. It costs you nothing.

1. What needs testing?
2. How many of them?

One more step. No phone number required.

Why, and where to send it

3. Why do you need a pentest?
4. Do you want a retest afterwards?

We test only with written authorisation, inside an agreed scope.

Get my fixed-fee quote