Skip to content
RiftX

For pentest consultancies

Take on more retest volume without taking on another head.

Retest work is mechanical, identical every engagement, and it runs on the most expensive capacity in the practice. The reproducing leaves your bench. The judgment stays on it, and every number here is one you can check.

What a retest round costs

One engagement's retest round, six retestable findings. Testing and write-up only.

By hand

~9 hours

An hour testing each finding, half an hour writing it up.

With RiftX

~1 hour

Two minutes to submit each finding, eight to review the evidence and sign it.

Access, credentials and waiting stay with your team either way. Reconciled against a ten person retest team at a mid-size consultancy.

The bottleneck is not demand. It is who has to do the work.

Three reasons it does not resolve itself, in the order an owner usually rules them out.

The queue scales with the book

Retestable findings are a minority, but criticals and highs get retested on every engagement. The queue tracks what you sell, not the bench you staff.

It runs on the senior bench

Whoever signs off has to be senior enough to defend the call to a client. That is the same person you need on scoping and in front of the buyer.

Hiring into it adds to the line you were compressing

Juniors are the cheapest-looking answer and it does not work. Slower to trust, still fully manual, and the cost lands on the line you were trying to shrink.

Your ceiling is the senior bench you will spend on the one part of delivery a client never sees.

What delivery looks like when the loop is unattended

Four operational changes, not four benefits, each checkable against a retest you ran.

Your retesters become reviewers

The finding goes in with the steps your pentester already wrote and comes back as a verdict with the evidence behind it. The hour of reproducing stops.

The fix gets attacked, not just re-run

Reproducing the original steps is what a client's own team can do. Deciding whether a partial fix still falls is the part that is automated here.

The evidence survives a client challenge

Every verdict ships with the traffic, the recording, the techniques tried, and a seal. When the client disputes it you have the file, not a recollection.

It abstains rather than guessing

When neither call clears the bar, the finding comes back to you as Needs Review. It is the outcome that makes Fixed and Not Fixed worth anything.

Where it sits in the cycle you already run

Nothing about how your team scopes, tests or writes findings changes. The retest step is the only one that moves, and it moves off your bench.

  1. 01

    Engagement closes

    You report as you always have. No new taxonomy, no change to how findings are written or scoped.

  2. 02

    Remediation window

    The client fixes. You get the retest scope clause signed at the same time, bounded to what you reported.

  3. 03

    Retest is due

    Submit the engagement in one request. Each finding is retested against the live target and attacked.

  4. 04

    Report assembly

    Verdicts and sealed evidence come back into your report tooling. Only Needs Review reaches your bench.

Scope is a contracts question rather than a security one. Retests run from a known source you name in the engagement scope.

Where the live target is off limits we retest a staging or re-hosted copy instead. The routes into an environment behind a VPN, an intranet or a login are on Integrations.

See it run

Watch it retest a finding you already know the answer to.

None of it settles whether the call holds on your work. Bring one finding from an engagement you have closed, and check our verdict against the answer you already own.