ACCESSGRANTED CONTINUOUS

Tested once a year.
Not for 364 days.

Not a vulnerability scan. A real penetration test – with real exploits and real privilege escalation. That's how the classic annual pentest works: thorough, but a single point in time. New vulnerabilities don't appear once a year, though — they appear every day. AccessGranted Continuous tests your attack surface automatically every month, including a consultant who puts the results into context with you.

Annual pentest
AccessGranted Continuous
The math no provider shows you
0 days a year your attack surface keeps changing
tested with a classic annual pentest
12× tested by AccessGranted Continuous – automated, every month

Regular, documented tests support your evidence of continuous effectiveness – for example in the context of NIS2 (Art. 21) or Section 30 BSIG. Does not replace individual legal advice.

Why once a year isn't enough

Everything changes between two pentests

01

A new gap. Every day.

New deployments, new access, new CVEs. Your attack surface today is not the one from three months ago.

02

Re-tests? Included.

Every remediated vulnerability is automatically re-verified in the next cycle. No extra quote.

03

Everything live, at a glance

Status, findings, history – always available on your existing platform, app.access-granted.de.

04

A real pentester, not a bot

Most automated providers just hand you a findings list. With us, a real pentester puts the results into context with you every month – in a personal meeting.

No PDF graveyard

This is what you actually see – live, not once a year

A snapshot from your customer platform: every finding with criticality, status, and history. No waiting for next year's report.

app.access-granted.de / Findings
Last tested: 3 days ago -2 findings vs. last cycle
Critical Outdated VPN firmware with known CVEs Open
High Missing MFA on admin interface In remediation
Medium SMBv1 still enabled Verified fixed
The difference to pure automation

Tested automatically. Interpreted by a human.

Providers built purely on automated scanning or attack-simulation platforms hand you a list of findings and leave you to figure out the rest. With AccessGranted Continuous you also get a fixed point of contact: a pentester who discusses the results with you every month, ranks them by what actually matters for your business, and answers your questions.

Pure automation (e.g. vulnerability scanners)
Often just signature/CVE matching – no real exploit attempt
Findings list via dashboard or email, no context
Questions? A ticket or a chatbot
AccessGranted Continuous
Real pentest: actual exploits, privilege escalation, not just a scan
Plus: a monthly meeting with your pentester
Results prioritized for your business, not just listed

"You're talking directly to the person who puts the results into context for your business, not a dashboard."

Your pentester, in the monthly review meeting
Price calculator

What does monthly security cost?

Two numbers, one price: enter your external and internal endpoints, see the result instantly.

Loading pricing configuration …
Pricing configuration could not be loaded. Please contact us directly for a custom quote.

Please select your endpoints and term first so we can put together a matching quote.

01

Externally reachable systems, e.g. web servers, VPN gateways, mail servers.

02

Internal endpoints incl. Active Directory environment. We align testing depth (e.g. AD exploit runs) with you during scoping, possibly at a reduced cadence depending on scope.

03
Monthly (net)
External testing
Internal testing
Service fee (platform, reporting, review meeting)
Discount (contract term)
One-time setup fee

Due once when booking at least one internal endpoint – not part of the monthly rate.

Always included in this price
Real exploits & privilege escalation – not just a scan
Re-tests every cycle, no extra cost
Monthly meeting with your pentester (not a bot)
Live access to app.access-granted.de
The difference

Annual pentest vs. AccessGranted Continuous

AccessGranted Continuous Classic annual pentest
Test frequency
− 1× a year
+ 12× a year, automated
Re-tests
− Separate quote required
+ Included, every cycle
Results discussion
− PDF report by email
+ Monthly meeting with a consultant
Test depth
− Thorough – but only at that point in time
+ Exploit & privilege escalation, fresh every month
Visibility of your attack surface
− Only at project close
+ Live on app.access-granted.de
Process

How your Continuous subscription gets started

01

Scoping call

Test scope, systems, framework conditions – 30 minutes that make the rest plannable.

02

Setup & approvals

Access and approvals for the automated testing platform, set up.

03

First test cycle

Full baseline test, including report and initial discussion.

From here: every month

Automated tests, re-tests, review meeting.

…and repeats automatically, every month from here on.

FAQ

Frequently asked questions about AccessGranted Continuous

A scanner reports signatures of known vulnerabilities, nothing more. Our automated testing platform goes further: real exploit attempts, targeted privilege escalation paths, for example within an Active Directory environment.

The difference to classic SaaS scanners: you don't get a list of open ports, you get evidence of whether and how a vulnerability is actually exploitable – automated, repeated every month.

External endpoints are tested automatically on a monthly rhythm. For internal testing depth, especially Active Directory exploit runs, we align the exact cadence with you during scoping – depending on scope and criticality, a slightly reduced rhythm can make sense here.

Regardless of cadence: findings already reported are automatically re-verified (re-tested) in the following cycle, without you having to commission that separately.

You talk to a real consultant, not a PDF. Together we go through the last cycle's results, rate new findings by criticality, and clarify what's changed since.

The meeting is also the place for your IT team's questions and to prioritize your team's next steps.

AccessGranted Continuous provides you with regular, documented test results and reports that can serve as a building block for evidencing the continuous effectiveness of your security measures, for example in the context of NIS2 (Art. 21) or Section 30 BSIG.

Whether and in what form this is sufficient for your specific compliance evidence depends on your individual situation. We recommend aligning this with us during the initial consultation and, if needed, with your legal advisor – we do not replace legal advice.

We proceed in a controlled manner. Before the first test cycle, we jointly define rules of engagement: critical systems, maintenance windows, and escalation paths. Our automated testing platform is designed for stability and uses safety checks before executing riskier actions such as privilege escalation attempts.

A residual risk can never be fully excluded with real exploit simulation. That's why we deliberately align testing depth and scope with your environment during scoping, rather than running everything unfiltered on every system.

You start on a 1-year term by default, with no discount. Book 3 years and your monthly rate drops by 5%; 5 years drops it by 10% – the discount applies only to the recurring monthly rate, not to the one-time setup fee for internal endpoints.

Which term makes sense depends on how confident you are about your needs over the next few years – growing companies with a changing endpoint count often prefer the flexibility of 1 year, while a stable footprint makes the discount add up significantly over the term. We're happy to advise you on this during the initial consultation.