> For the complete documentation index, see [llms.txt](https://docs.bypassec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.bypassec.com/the-platform/penetration-testing.md).

# Penetration Testing

## What is Penetration Testing?

A Penetration Test (Pentest) is a structured, hands-on security assessment where certified offensive security experts systematically simulate real-world cyberattacks against your applications, APIs, and infrastructure.

The primary goal of a pentest is to proactively uncover security vulnerabilities, evaluate the business impact of potential exploits, and provide full control over the testing methodology to guarantee complete 360° scope coverage, especially for sensitive and non-public applications.

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2FiDMkGkaxQwXxE48TbKbx%2FBeyond%20the%20Blockchain%20The%20Art%20of%20Breaking%20Things(1).png?alt=media&amp;token=d617a144-796c-4daf-a344-77e59aa753f2" alt=""><figcaption></figcaption></figure>

### Pentest vs. Hacking Competitions: Understanding the Difference

Both Penetration Testing and Hacking Competitions operate within defined timeframes, strict rules of engagement, and defined scopes, making both models fully compliant with market regulations and audit standards. However, they fulfill different tactical roles:

* <mark style="color:$primary;">**Penetration Testing:**</mark> Designed specifically for internal, sensitive, and non-publicly exposed applications. It provides complete control over the testing methodology and guarantees 360° deep coverage across every component, endpoint, and user privilege level within your scope.
* <mark style="color:$primary;">**Hacking Competitions:**</mark> Designed specifically for the external perimeter. By leveraging hundreds of independent specialists simultaneously, competitions maximize vulnerability discovery, finding on average 3x to 5x more flaws than a standard pentest on external-facing assets.

{% hint style="info" %}
Use Penetration Testing to secure your confidential internal applications with guaranteed 360° coverage and custom testing control. Use Hacking Competitions to maximize vulnerability discovery across your external, public-facing attack surface.&#x20;
{% endhint %}

## Testing Capabilities Across Various Scenarios

At Bypassec, our security researchers possess the technical depth and versatility to perform targeted penetration tests across diverse architectures, technologies, and operational environments. We adapt our testing procedures to evaluate your unique threat vectors and business context.

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2FksIm3D4rul56Xvs6bMON%2FApresenta%C3%A7%C3%A3o%20Vendas%20Pentest%20-%20Axians(1).png?alt=media&amp;token=31d78a28-d0fb-4a63-a237-1e9a6205a1ad" alt=""><figcaption></figcaption></figure>

## Testing Approaches

Depending on your security goals, architecture exposure, and threat model, Bypassec offers three standardized pentesting approaches:

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2Fs3lt0uMej8XvszPjTly5%2FBeyond%20the%20Blockchain%20The%20Art%20of%20Breaking%20Things.png?alt=media&amp;token=6f1a35c4-cd37-4fe4-a571-9889ebba0217" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}

### Black Box

* <mark style="color:purple;">**How it works:**</mark> Researchers are given zero prior knowledge about the target application's internal structure.
* <mark style="color:purple;">**Simulated Threat:**</mark> Represents an external, unauthenticated attacker attempting to breach your perimeter.
* <mark style="color:purple;">**Best Used For:**</mark> Evaluating initial access defenses and unauthenticated attack surfaces
  {% endstep %}

{% step %}

### Gray Box

* <mark style="color:purple;">**How it works:**</mark> Researchers are provided limited information, such as user credentials (low and high privileges), API documentation, or role architectures.
* <mark style="color:purple;">**Simulated Threat:**</mark> Represents an authenticated user, malicious insider, or attacker who has compromised a standard user account.
* <mark style="color:purple;">**Best Used For:**</mark> Deep assessment of business logic flaws, privilege escalation (vertical and horizontal), authorization bypasses, and multi-tenant isolation in internal/sensitive apps.
  {% endstep %}

{% step %}

### White Box

* <mark style="color:purple;">**How it works:**</mark> Researchers receive full transparency into source code, architecture designs, API specifications, and database schemas.
* <mark style="color:purple;">**Simulated Threat:**</mark> Represents a worst-case scenario with full insider knowledge or a comprehensive pre-release code review.
* <mark style="color:purple;">**Best Used For:**</mark> Identifying deep architectural flaws, complex logic vulnerabilities, and hidden code-level risks.
  {% endstep %}
  {% endstepper %}

## Compliance & Market Standards

Bypassec offensive security assessments fulfill the mandatory technical security requirements for major regulatory frameworks and industry certifications:

* <mark style="color:$primary;">**ISO/IEC 27001**</mark><mark style="color:$primary;">:</mark> Satisfies technical vulnerability management and security review requirements (Controls A.12.6.1 and A.18.2.3).
* <mark style="color:$primary;">**SOC 2 Type II**</mark><mark style="color:$primary;">:</mark> Demonstrates adherence to trust service criteria for Security, Confidentiality, and Availability.
* <mark style="color:$primary;">**PCI DSS 4.0**</mark><mark style="color:$primary;">:</mark> Meets Requirement 11.3 for regular technical security assessments of payment processing environments.
* <mark style="color:$primary;">**LGPD / GDPR & HIPAA**</mark><mark style="color:$primary;">:</mark> Proves due diligence in protecting sensitive personal identifiable information (PII) and health records.

{% hint style="info" %}
Generate formal, audit-ready compliance certificates directly from your Bypassec dashboard upon test completion.&#x20;
{% endhint %}
