For pentest consultancies
Take on more retest volume without taking on another head.
Retest work is mechanical, identical every engagement, and it runs on the most expensive capacity in the practice. The reproducing leaves your bench. The judgment stays on it, and every number here is one you can check.
What a retest round costs
One engagement's retest round, six retestable findings. Testing and write-up only.
By hand
An hour testing each finding, half an hour writing it up.
With RiftX
Two minutes to submit each finding, eight to review the evidence and sign it.
Access, credentials and waiting stay with your team either way. Reconciled against a ten person retest team at a mid-size consultancy.
The bottleneck is not demand. It is who has to do the work.
Three reasons it does not resolve itself, in the order an owner usually rules them out.
The queue scales with the book
Retestable findings are a minority, but criticals and highs get retested on every engagement. The queue tracks what you sell, not the bench you staff.
It runs on the senior bench
Whoever signs off has to be senior enough to defend the call to a client. That is the same person you need on scoping and in front of the buyer.
Hiring into it adds to the line you were compressing
Juniors are the cheapest-looking answer and it does not work. Slower to trust, still fully manual, and the cost lands on the line you were trying to shrink.
Your ceiling is the senior bench you will spend on the one part of delivery a client never sees.
What delivery looks like when the loop is unattended
Four operational changes, not four benefits, each checkable against a retest you ran.
Your retesters become reviewers
The finding goes in with the steps your pentester already wrote and comes back as a verdict with the evidence behind it. The hour of reproducing stops.
The fix gets attacked, not just re-run
Reproducing the original steps is what a client's own team can do. Deciding whether a partial fix still falls is the part that is automated here.
The evidence survives a client challenge
Every verdict ships with the traffic, the recording, the techniques tried, and a seal. When the client disputes it you have the file, not a recollection.
It abstains rather than guessing
When neither call clears the bar, the finding comes back to you as Needs Review. It is the outcome that makes Fixed and Not Fixed worth anything.
Where it sits in the cycle you already run
Nothing about how your team scopes, tests or writes findings changes. The retest step is the only one that moves, and it moves off your bench.
- 01
Engagement closes
You report as you always have. No new taxonomy, no change to how findings are written or scoped.
- 02
Remediation window
The client fixes. You get the retest scope clause signed at the same time, bounded to what you reported.
- 03
Retest is due
Submit the engagement in one request. Each finding is retested against the live target and attacked.
- 04
Report assembly
Verdicts and sealed evidence come back into your report tooling. Only Needs Review reaches your bench.
Scope is a contracts question rather than a security one. Retests run from a known source you name in the engagement scope.
Where the live target is off limits we retest a staging or re-hosted copy instead. The routes into an environment behind a VPN, an intranet or a login are on Integrations.
See it run
Watch it retest a finding you already know the answer to.
None of it settles whether the call holds on your work. Bring one finding from an engagement you have closed, and check our verdict against the answer you already own.
