AccessGranted Continuous Monthly pentest subscription

Real exploits. And every month, a pentester who walks through them with you.

Automated pentest of your attack surface every month, with real exploit attempts rather than signature matching. Once a month your pentester sits down with you, goes through the results and prioritizes with you what matters next.

Is this a pentest or a scan?

A pentest. The platform attempts the exploit instead of only reporting the version number.

A vulnerability scanner matches signatures. It detects a software version, looks up the matching CVE numbers and writes them into a list. Whether the flaw is actually exploitable in your environment stays open.

Our testing platform goes one step further. It runs real exploit attempts, follows privilege escalation paths, for example in your Active Directory environment, and documents whether and how far an attacker would get. In the end you know which vulnerabilities actually matter in your environment.

What the platform does in every cycle

  • Exploit attempts against your externally reachable systems
  • Privilege escalation paths in the internal network and Active Directory
  • Re-test of all open findings from the previous cycle
  • Documentation per finding: criticality, evidence, status

External endpoints are tested monthly. The cadence for internal exploit runs, especially in Active Directory, is agreed with you during scoping and may be somewhat lower depending on scope and criticality.

What happens in the monthly meeting?

Your pentester goes through the results with you in person – on a monthly rhythm.

The platform delivers findings. What they mean for your company gets settled in conversation. That is why every cycle includes a meeting with an AccessGranted pentester: a fixed point of contact who gets to know your environment over time and can judge which finding is actually critical for you.

Many scanning and attack simulation platforms stop at the dashboard. Questions go through a ticket or a chatbot. With us, someone who knows the results sits across from you and answers.

How the review meeting runs

  1. Go through last cycle's results

    What is new, what is fixed, what has come back.

  2. Rate criticality for your company

    A CVSS score does not know your processes. The pentester assesses what a finding means in your environment.

  3. Prioritize

    What your IT tackles next and what can wait.

  4. Clear up questions

    Your IT asks, the pentester answers. In conversation, with your systems in view.

  5. Record next steps

    So the next cycle shows whether the measures worked.

This is how one customer describes working with us on classic pentest projects. With Continuous, exactly that becomes a fixed monthly appointment.
“Florian was available to us as a competent point of contact at all times, answered questions quickly and thoroughly, and supported us in prioritizing and implementing appropriate measures.”
Bert Gross Head of IT & Medical Technology, Kreiskliniken Reutlingen

And between meetings?

The platform keeps testing, you can see the current state at any time, and fixed findings are automatically re-checked in the next cycle.

Platform
Status, findings and history at any time in your existing customer platform app.access-granted.de, not just in the final report.
Re-tests
Every fixed vulnerability is tested again in the next cycle. No extra quote, no re-commissioning.
Point of contact
The same pentester you know from the review meeting remains your point of contact.

What about your attack surface itself?

ASM automatically checks what's visible from the outside: subdomains, open ports, certificates, and domains that look confusingly similar to yours. That adds the outside view between cycles to complement the exploit tests.

Attack surface
Subdomains, open ports and running services are captured automatically, including the ones nobody remembers are still online.
Early warning
Expiring certificates, exposed config files and API keys left in the code show up before they turn into an incident.
Cadence
Automatic, once a week per domain. That's enough to catch new subdomains, expiring certificates, or freshly registered look-alike domains in time.
Works alongside Continuous
Bookable as an add-on to Continuous or entirely on its own, with no external or internal endpoints required.

What does it cost?

Enter your endpoints and ASM domains, pick a term, see the result instantly. The service fee covers the platform, reporting and the monthly review meeting.

Loading pricing configuration …
Pricing configuration could not be loaded. Please contact us directly for a custom quote.

Please select your endpoints and term first so we can put together a matching quote.

Externally reachable systems, e.g. web servers, VPN gateways, mail servers.

Internal endpoints incl. Active Directory environment. We align testing depth (e.g. AD exploit runs) with you during scoping, possibly at a reduced cadence depending on scope.

Domains monitored under Attack Surface Management. Can be booked without any external/internal endpoints.

Contract term

Monthly (net)
External testing
Internal testing
ASM
Service fee (platform, reporting, review meeting)
Discount (contract term)
One-time setup fee

Due once when booking at least one internal endpoint, not part of the monthly rate.

Always included in this price
Real exploits and privilege escalation, not just a scan
Re-tests every cycle, no extra cost
Monthly review meeting with your pentester
Live access to app.access-granted.de
Once a year, a certificate confirming a full year of continuous testing

And compared to a classic annual pentest?

A classic annual pentest is a thorough, deep assessment at a fixed point in time – and the right choice for many needs. Continuous spreads that depth across the whole year and adds re-tests plus a monthly conversation.

Classic annual pentest AccessGranted Continuous
Test frequency Classic annual pentest1× a year, in full depth AccessGranted Continuous12× a year, automated
Re-tests Classic annual pentestAvailable as a separate project AccessGranted ContinuousIncluded, every cycle
Results discussion Classic annual pentestPDF report by email AccessGranted ContinuousMonthly meeting with your pentester
Test depth Classic annual pentestFull-depth assessment on the agreed date AccessGranted ContinuousExploit and privilege escalation, fresh every month
Visibility of your attack surface Classic annual pentestIn the report at project close AccessGranted ContinuousLive on app.access-granted.de

How do we start?

  1. Scoping call

    Test scope, systems, framework conditions: 30 minutes that make the rest plannable.

  2. Setup and approvals

    Access and approvals for the automated testing platform, set up.

  3. First test cycle

    Full baseline test, including report and initial discussion.

  4. From here: every month

    • Automated tests
    • Re-tests
    • Review meeting
    • Annual certificate

More questions

On test cadence, outage risk, NIS2 and contract term.

External endpoints are tested automatically on a monthly rhythm. For internal testing depth, especially Active Directory exploit runs, we align the exact cadence with you during scoping. Depending on scope and criticality, a slightly reduced rhythm can make sense here.

Regardless of cadence: findings already reported are automatically re-verified (re-tested) in the following cycle, without you having to commission that separately.

We proceed in a controlled manner. Before the first test cycle, we jointly define rules of engagement: critical systems, maintenance windows, and escalation paths. Our automated testing platform is designed for stability and uses safety checks before executing riskier actions such as privilege escalation attempts.

A residual risk can never be fully excluded with real exploit simulation. That is why we deliberately align testing depth and scope with your environment during scoping, rather than running everything unfiltered on every system.

AccessGranted Continuous provides you with regular, documented test results and reports that can serve as a building block for evidencing the continuous effectiveness of your security measures, for example in the context of NIS2 (Art. 21) or Section 30 BSIG. Once a year, we also issue you a certificate confirming that the pentest was carried out continuously throughout the year.

Whether and in what form this is sufficient for your specific compliance evidence depends on your individual situation. We recommend aligning this with us during the first call and, if needed, with your legal advisor. We do not replace legal advice.

You start on a 1-year term by default, with no discount. Book 3 years and your monthly rate drops by 5%; 5 years drops it by 10%. The discount applies only to the recurring monthly rate, not to the one-time setup fee for internal endpoints.

Which term makes sense depends on how confident you are about your needs over the next few years. Growing companies with a changing endpoint count often prefer the flexibility of 1 year, while a stable footprint makes the discount add up significantly over the term. We are happy to advise you on this during the first call.

Classic annual pentest or Continuous?

Free first call: we show you how Continuous fits your environment and what a review meeting would look like for you.