Support

Frequently asked questions

Pricing, engagement models, turnaround, reporting and data handling. These are the questions teams ask us most before an engagement.

Do I need to pay anything upfront to start?

No. Share your scope with us, finalise the details, and testing can begin. There is no upfront payment required to get started.

How quickly can a penetration test start?

Once the scope is agreed, a focused engagement can begin within an hour. Larger, continuous programmes are scheduled around your release cycle.

What can you test?

Web applications, APIs, mobile apps, cloud environments, internal and external networks, and AI/LLM systems, plus full red-team adversary simulation.

What engagement models do you offer?

Three: a one-time pentest for a release or compliance milestone, continuous PTaaS for teams shipping frequently across many assets, and a managed bug-bounty programme.

What do I actually receive?

Operator-verified findings, with no raw scanner output, each with a proof of concept, CVSS severity, business impact and remediation guidance, delivered in a signed report, followed by a retest to validate the fixes.

Are your testers certified?

Yes. The team holds internationally recognised certifications including OSCP+, CREST (CRT / CPSA), CPTS, CRTA, CRTO, MCRTA and eWPTXv2.

How long do you keep our engagement data?

Final reports and signed deliverables are retained for 3 years; raw scan results and technical evidence for 6–12 months; credentials, API keys and tokens are deleted as soon as possible and within 90 days; temporary processing data within 24–72 hours.

Where are you based, and do you work with clients outside Bangladesh?

We are based in Dhaka, Bangladesh (ICT Tower, Agargaon, Dhaka 1207) and work with clients worldwide.

How do we get started?

Use the Schedule a Meeting button to book a slot, or email contact@pentesterspace.com with a short note about what you are building and what needs testing.

Still have a question?

Ask us directly.

Schedule a Meeting