Annual assurance
Your pentest,
kept alive all year
A penetration test is a photograph. The day after the report lands you ship new code, new vulnerabilities are disclosed for software you run, and fixes introduce gaps of their own. Active Cover keeps the test you already paid for true for the whole year.
The problem with every pentest, including a good one
A report starts ageing the day it lands
This is not a criticism of point-in-time testing. It is what point-in-time means.
What decays, and how fast
New endpoints appear with the next release. A CVE lands on a component that was fine in March. A fix for one finding opens another. Within weeks the report describes a system that no longer exists, and by the next audit it is a PDF nobody fully trusts.
What usually happens instead
Nothing, until next year. In our own engagement data, 74% of reported findings were never submitted for a retest at all, and the ones that were came back correctly fixed first time in fewer than half of cases. The gap is rarely indifference - it is that verifying a fix costs someone a day they did not budget.
What the fee buys
Five things a one-off engagement cannot give you
Every one of them exists because the engagement is still open, rather than closed and archived.
Living validity
We re-check the scope we tested, on a cadence, so the report stays true. Regressions and newly exposed surface are caught when they appear, not at next year’s test.
Unlimited retests, included
Fixed something? We verify it is actually closed - as many times as you need, at no extra cost. This is the component customers feel first, and the one a one-off engagement structurally cannot offer.
CVE watch on your stack
When a serious vulnerability is disclosed for software you actually run, you hear it from us: whether you are affected, and what to do about it.
A living posture view
Open against fixed, risk over time, how long remediation is taking. Ready for a board or an auditor whenever they ask, rather than assembled the week before.
Priority expert access
The same engineers who ran your test, on tap. Every alert is reviewed by one of them before it reaches you - you get findings, not a queue of candidates to triage.
Same team, same standard
Continuous coverage does not mean handing you to a monitoring desk. The people are the people who know your system.
How it sits on the engagement you already buy
Complementary, not the same thing twice.
Your pentest is the deep dive. Active Cover keeps the lights on between dives.
The flagship engagement does not change: the same deep, manual assessment by engineers who read your system. Active Cover wraps around it - re-checks, free retests, CVE alerts and a live view for the rest of the year.
- Month 0 - the flagship penetration test, exactly as it is today.
- Months 1-11 - continuous coverage: re-checks, retests on demand, CVE exposure, the posture view.
- Month 12 - the next deep dive, informed by everything the year turned up.
Compliance
Audit-ready in between, not just in the same week
SOC 2, ISO 27001 and PCI-DSS 4.0 all expect an annual penetration test and current evidence that findings were dealt with. Active Cover produces that evidence continuously, so renewal is a download rather than a scramble - and the retest record shows an auditor not just that issues were found, but that they were closed and verified closed.
What it costs
Priced against your engagement, not as software
Roughly 15-25% of the engagement, per year. For a fraction of what the test cost, it stays current, and retests stop being a line item you think twice about.
One tier. No seats, no usage meter, no plan matrix. If you want more expert time than the tier includes, that is a conversation, not a checkbox.
Active Cover is agreed with the team that ran your engagement, usually when the report is delivered. There is no checkout for it here on purpose - continuous coverage is scoped against what we actually tested.
The questions you are actually asking
“Isn’t this just running a scanner?”
No. Automated coverage produces candidates; our engineers triage every one before it reaches you. You get reviewed findings, not tool output. The tooling is plumbing - the judgement is ours, and it is the same judgement that ran your test.
“How is this different from the pentest itself?”
The pentest is the deep human dive - business logic, authorization, the flaws that need someone to understand your system. Active Cover is vigilance between dives: regression checks, new exposure, instant verification.
“Why pay annually for something I bought once?”
Because what you bought once stops being true almost immediately. This is what keeps a five-figure investment valid for twelve months instead of a few weeks.
“What if we do not renew the test?”
Active Cover travels with the engagement. Renew the annual programme and coverage simply continues - same history, same dashboard, same team.
Worth a conversation?
The honest way to decide is to look at what your last report found and ask how much of it is still true. We are happy to do that with you.