00Methodology

How we run continuous pentesting. In full detail.

No vague phases, no marketing-speak. The full pipeline, every guarantee, every artifact you receive at every step. If something here looks different from another vendor, ask them why.

01Lifecycle

Six phases. One continuous loop.

Every BugThrive engagement runs this lifecycle. Continuous engagements never leave the cycle — they re-enter discovery on every meaningful change.

01

Scoping & onboarding

Day 0 – Day 2

We meet your engineering and security leads, define in-scope assets, agree on testing constraints, and provision platform access.

You receive
Scope-of-work document with named assets and exclusions
Mutual NDA and rules-of-engagement
Provisioned dashboard, CLI, and CI integration
Named primary tester + secondary reviewer
02

Discovery

Day 2 – Day 4

Automated mapping of your external attack surface, internal asset inventory, dependency graph, and authentication boundaries.

You receive
Asset inventory with criticality scoring
Stack fingerprint and version diff
Auth boundary map (public, authenticated, admin, internal)
Initial coverage report
03

Baseline testing

Day 4 – Day 7

Automated probes across all in-scope surfaces — SAST on connected repos, DAST against staging/production endpoints, dependency analysis, secret scanning.

You receive
Baseline finding queue (raw + deduplicated)
Severity-banded priority list
Initial AI-assisted triage pass
Coverage gaps flagged for manual review
04

Manual exploitation

Rolling, continuous

Senior testers probe business logic, multi-step flows, federated auth edge cases, and any surface that automated tools cannot meaningfully assess.

You receive
Hand-crafted PoC for every confirmed finding
Severity assigned with business-context adjustment
Reproduction steps, screenshots, and request/response traces
Recommended remediation with code-level guidance
05

Reporting & routing

Real-time per finding

Each finding lands in your dashboard the moment it's verified — and is routed to the responsible team via your existing workflow tools.

You receive
Per-finding record with PoC, fix guidance, and owner
Two-way sync into Jira / Linear / GitHub Issues
Slack / PagerDuty alerts for criticals
Executive-ready PDF snapshot on demand
06

Retest & verification

Hours after fix

When you ship a fix, the original PoC re-runs automatically. If the exploit fails, a human tester confirms the close within hours.

You receive
Automated re-exploit attempt on fix branch
Human verification within one business day
Closed status with audit-trail evidence
Variant-class re-probe (we look for adjacent bugs)
Loop continues — every commit, every release
02Guarantees

Contractual guarantees — not aspirations.

These are written into the engagement. If we miss any of them, you get the engagement period refunded.

Zero false positives in your queue

Every finding is hand-verified with a working PoC before it appears in your dashboard.

Full audit trail on every action

Every probe, every severity bump, every retest is logged with timestamp, tester, and outcome.

Kill switch always available

One command pauses all probes — useful during incident response or sensitive launches.

Named human accountability

Each engagement has a primary tester and secondary reviewer. Neither rotates without notice.

03Coverage

Every surface a modern attacker uses.

Coverage is defined per engagement — we'll never bill you for surfaces you don't have. But here's the full menu.

Web applications

OWASP Top 10, business logic, auth flows, session management, browser-level abuse

APIs

REST, GraphQL, gRPC, WebSocket — authorization, rate limiting, mass assignment, idempotency

Mobile

iOS and Android binaries — local storage, cert pinning, deep links, reverse engineering

Cloud accounts

AWS, GCP, Azure — IAM trust paths, container escape, privilege escalation, supply chain

Network

External perimeter, internal pentest, AD tiering, segmentation validation

Smart contracts

Solidity audits, reentrancy, oracle abuse, cross-chain message-passing, flash-loan vectors

Source code

Manual SAST review, dependency analysis, secret hunting, CI/CD pipeline audit

Red team & social

Phishing campaigns, pretexting, physical recon, full adversary emulation

04Tester vetting

The humans behind every engagement.

We do not crowdsource. Every tester is a vetted employee or long-term contractor who passed a multi-stage technical and behavioral assessment. Here's that pipeline.

Acceptance rate
3.2%

of applicants make it through the full pipeline.

Stage 1
Application review
Reviewed against a published rubric — relevant offensive work history, public research, signal-not-pedigree.
Stage 2
Technical screen
Live walkthrough of a recent finding the candidate worked. We look for reasoning, not just exploit knowledge.
Stage 3
Practical assessment
Three-day hands-on engagement against a representative test environment. Output is reviewed by two senior testers.
Stage 4
Reference + background
Verified references plus a standard background check. We disclose this requirement up front.
Stage 5
Mentored onboarding
First 90 days under a senior tester. Findings are co-signed; severity calls are reviewed.
05Severity model

Severity is a call. Not a CVSS lookup.

CVSS is the starting point. Final severity is adjusted by asset criticality, business impact, and exploitability. You get to disagree — and we log the discussion.

Critical
CVSS 9.0+

Active exploit path to crown-jewel data or full account takeover.

High
CVSS 7.0–8.9

Exploit path requiring minimal preconditions; significant business impact.

Medium
CVSS 4.0–6.9

Exploitable but constrained — auth required, limited blast radius.

Low
CVSS 0.1–3.9

Information disclosure or hardening gap; no direct exploit path.

Info
Advisory

Defense-in-depth observation; recommended but not required to fix.

Disagree with a severity call?
Open a discussion thread on the finding. A senior reviewer responds within one business day. The full thread becomes part of the audit trail.
See sample audit log
06Data handling

Your data, your retention, your kill switch.

We treat customer data as a liability. The less we hold, the better for both of us. Here's exactly how we handle it.

Full security disclosure
Minimum data collection
We only ingest what is required to test in-scope assets. PII captured during testing is redacted before storage.
Customer-controlled retention
Default retention is 12 months. You can shorten to 90 days, or extend for compliance. Bulk export and deletion available on demand.
Encrypted at rest, encrypted in transit
AES-256 at rest, TLS 1.3 in transit, customer-managed keys available on enterprise tier.
Kill switch
One command pauses all probes against your stack. Useful during incident response, sensitive launches, or audit windows.
No data resale, no AI training
Customer data is never used to train shared models. Anonymized aggregate statistics are published only with explicit opt-in.

Ready to scope an engagement?

30-minute call, mutual NDA, named tester within 48 hours, first findings inside the first week.