Skip to content
PentestBX — Security is a continuous process
Resources

Frequently asked questions

Everything you need to know about PentestBX, security standards, and deployment options.

What is PentestBX?

PentestBX is a comprehensive cybersecurity platform that helps organisations manage their cyber risks proactively. It provides a suite of tools for vulnerability scanning, penetration testing, and risk management.

How can PentestBX help me improve my cybersecurity posture?

PentestBX can help you improve your cybersecurity posture in a number of ways:

  • Identify and remediate vulnerabilities: PentestBX scans your network and systems for vulnerabilities that could be exploited by attackers. Once identified, you can prioritise and remediate them to reduce your risk of attack.
  • Automate security tasks: Many time-consuming tasks such as vulnerability scanning and reporting are automated, freeing your security team to focus on more strategic initiatives.
  • Improve compliance: PentestBX helps you comply with a variety of security standards and regulations, such as PCI DSS and HIPAA.
  • Raise employee awareness: Raise employee awareness of cybersecurity risks through best practices, reducing the risk of human error — a leading cause of data breaches.
What are the benefits of using PentestBX?

There are many benefits to using PentestBX, including:

  • Improved security posture: Identify and remediate vulnerabilities, automate security tasks, and improve compliance.
  • Reduced risk of attack: By identifying and remediating vulnerabilities, you reduce your risk of being attacked by cybercriminals.
  • Lower costs: Automating security tasks and improving compliance lowers your overall cybersecurity spend.
  • Increased productivity: Your security team is freed up to focus on more strategic initiatives.
How does PentestBX work?

PentestBX works by using a combination of vulnerability scanning, penetration testing, and risk management tools.

  • Vulnerability scanning: Scans your network and systems for known vulnerabilities. This can run on a regular basis to identify new vulnerabilities as they are discovered.
  • Penetration testing: Simulates a cyberattack to identify weaknesses in your security defences, finding issues that vulnerability scanning alone may not detect.
  • Risk management: Assists you in assessing your cyber risks and prioritising remediation efforts, helping you optimise your security resources.
Is PentestBX easy to use?

Yes. PentestBX has a user-friendly interface that makes it easy to find and use the tools you need, and it ships with a library of pre-built scans and reports so you can get started quickly.

What is the difference between PentestBX and other cybersecurity solutions?

PentestBX is a comprehensive cybersecurity platform that provides a suite of tools for vulnerability scanning, penetration testing, and risk management. Other cybersecurity solutions may only focus on one or two of these areas.

What plans are available?

PentestBX is available in three plans: Professional, Premium, and Enterprise. Professional suits teams putting continuous scanning in place for the first time, Premium adds scheduling and comparative reporting for larger estates, and Enterprise covers on-premise data residency and the full module set.

What is PentestBX's pricing?

Pricing is based on the modules you enable, the number of assets in scope, and the plan you choose. Use the pricing configurator to size your estate and request a quote — a member of the team will come back to you with a tailored proposal.

How can I get support for PentestBX?

We offer a variety of support options, including online documentation, support tickets, live chat, and phone support depending on your plan. Contact us for more information on the support options available to you.

How does PentestBX ensure the reliability of scan results?

PentestBX uses vulnerability rules aligned with CVE and OWASP standards. All scans follow the same repeatable methodology, and scan logs are digitally signed with SHA-256. Data is encrypted with AES-2048 both in the cloud and on the appliance.

How is the accuracy of reports guaranteed?

Reports are normalised to make results comparable across different scans. This ensures consistency over time and guarantees both the validity and reliability of the reports.

Are independent security tests performed on PentestBX?

Yes. At least once a year, independent cybersecurity firms perform penetration tests at both the network and application levels, simulating real-world attacker behaviour.

Who can access penetration test results?

Full reports, which contain sensitive details, are accessible only to our authorised security team. Customers receive summary reports showing that critical findings have been resolved.

What deployment options are available for PentestBX?

There are two deployment methods:

  • Cloud Deployment: Each customer's data is stored in a dedicated, isolated database. Data transmission is secured with TLS 1.3 and data at rest is encrypted with AES-2048. Role-Based Access Control is enforced and all activities are logged.
  • On-Premise Appliance: A virtual appliance runs within the customer's own network. It connects to the cloud only via VPN with no direct internet access. Data is stored encrypted and isolated on the appliance, with strict access control and audit logging.
Where are PentestBX servers located?

Our cloud servers are hosted in high-security ISO 27001 and SOC 2 certified data centres located in Türkiye and Europe.

What commitments does PentestBX provide regarding customer data?
  • Data is always isolated, redundant, and encrypted.
  • Appliance access is restricted to VPN connections, preventing unauthorised access.
  • Network and host-level segmentation is enforced.
  • Logs and scan results are stored with guaranteed integrity and accuracy.
What is the main assurance for customers?

PentestBX ensures vulnerability scanning and data management fully aligned with industry standards. Security is maintained through encryption, RBAC, audit logging, and network isolation, as well as continuous security testing by independent firms. Customers can choose between cloud or on-premise deployment for maximum flexibility and control.

Still have a question?

Send us a message and a member of the team will get back to you within one business day.