Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Testing approach

White box penetration testing: full access, deeper findings

White box penetration testing gives the tester everything: credentials, architecture diagrams and often source code. So instead of guessing, they spend the hours finding weaknesses an outsider might take months to reach.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
White box penetration testing: share the internals, test with insight and fix root causes

Why white box penetration testing finds more

With code and diagrams, a tester sees how authorisation is meant to work. Therefore they can test every path, not only the ones they stumble on. Also, findings point to the exact line or setting, so fixes are faster.

What you share for white box penetration testing

The more you share, the deeper the result. However, everything is covered by confidentiality terms and nothing is retained afterwards.

  • Test accounts for every role
  • Architecture and data flow diagrams
  • Source code access, read-only
  • Configuration of key services

Are you ready for white box penetration testing?

Tick what you can provide. Each item deepens the result.

Your result appears here as you tick, so you can see what is still open.

Best uses for white box penetration testing

White box suits systems where a breach would be severe. For example, payment flows, admin consoles and multi-tenant isolation reward the extra depth.

SystemWhy full access helps
Payment and billingLogic flaws hide in edge cases, so code reveals them.
Admin consolesEvery privileged action can be checked.
Tenant isolationData access rules can be traced directly.

White box penetration testing and cost

It does not cost more per hour, but scope may grow because more paths become visible. So we agree the boundaries in writing and state the manual hours. The Advanced package, from $29,000, is the usual fit for full-scope white box work.

Is it still a penetration test?

Yes. The tester still exploits issues to prove impact, rather than only reading code. Also, the report follows the OWASP Web Security Testing Guide so your auditor recognises it.

White box penetration testing questions

Is white box penetration testing better than black box?

For depth, usually yes. However, black box is still the right view for your internet edge.

Is our code safe?

Access is read-only and covered by confidentiality terms, so nothing is retained after delivery.

Is it the same as a code review?

No. A code review reads code, while a white box test also exploits issues to prove impact.

Which package fits?

Usually Standard or Advanced, because full access exposes more paths to test.

Related guides

Scope white box penetration testing

Tell us the system and what you can share. We reply with a fixed fee and stated hours, so the depth is clear before you sign.

Get my fixed-fee quote