Frequently asked questions
115 straight answers for platform owners who need real security.
This page brings together the questions we get asked most often: what a pentest costs, how it supports compliance (SOC 2, ISO 27001, PCI DSS — and LGPD if you operate in Brazil), the difference between a pentest and a security audit, when to hire one, what changes by industry and what to do after an incident. In plain language, without the jargon. Use your browser's search (Ctrl+F or Cmd+F) to find your question quickly.
Contents
- 01
Do I need a pentest or a security audit?
10 questions
- 02
Pentesting explained: what it is, how it works, key differences
10 questions
- 03
How the engagement works (from first contact to final report)
10 questions
- 04
Pricing, payment and contracting
10 questions
- 05
LGPD (Brazil's data protection law) and the ANPD
10 questions
- 06
ISO 27001, SOC 2, PCI DSS, Brazil's Central Bank — other standards
8 questions
- 07
Pentesting by industry: fintech, SaaS, e-commerce, healthtech
10 questions
- 08
Common vulnerabilities in plain English
8 questions
- 09
After an incident: urgency and response
8 questions
- 10
About No Vuln
8 questions
- 11
Commercial, legal and guarantees
7 questions
- 12
Choosing a pentest company in Brazil
16 questions
Category 01 / 12
Do I need a pentest or a security audit?
Questions from teams still figuring out whether they need offensive security.
How do I know if my system is secure?
The only reliable way is a pentest — a penetration test performed by human experts, not just automated scanners. Scanners find the obvious bugs (outdated versions, trivial XSS), but business logic flaws, data leaking between customers (BOLA) and exploit chains only show up with manual analysis. If no one on your team can assure you they've tested for the 9 common warning signs of a vulnerable platform, you probably need an external assessment.
Does a small company need a pentest?
It depends on what your platform does. If you collect personal data (ID numbers, email addresses, home addresses, banking details), process payments, or have business customers who depend on you — yes, even if you're small. Small companies are preferred targets today precisely because attackers know they're under-protected. The good news: a pentest for a small company starts at US$ 3,750 (Sprint package, 25h).
Does a simple company website need a pentest?
A basic company website with no login, no sensitive forms and no customer data: you can skip it. A site with a contact form + integrations + an admin panel: yes, even if it looks simple — those three are where most leaks happen. A basic scanner covers a purely informational site; a pentest becomes necessary the moment you have an admin panel or customer sign-up.
Do I have to get a pentest every year?
For compliance (PCI DSS, ISO 27001, SOC 2), yes — at least once a year and after significant code changes. Privacy laws such as the GDPR and Brazil's LGPD don't set a fixed interval, but a pentest older than 12 months starts losing weight as evidence of technical security measures. If your platform ships code every sprint, continuous monitoring combined with focused pentests is more effective than a single annual pentest.
How do I know if I've already been hacked without noticing?
Common signs: charges on the company card that nobody made, customers complaining about strange emails, spikes in server resource usage, bank alerts about suspicious activity, or a ransom demand. But sophisticated attackers can stay quiet for months — only a forensic investigation or an in-depth pentest will find them. If your platform hasn't been assessed in the last 12 months, consider a compromise assessment.
I run a very small business. Is cybersecurity worth the spend?
Yes, and the math is simple. In Brazil, a data breach at a very small business costs R$ 200,000 to R$ 1 million once you add up fines from the national data protection authority (ANPD), damages and lost customers. A preventive pentest (Sprint package, 25h) costs US$ 3,750 to US$ 6,250 — a fraction of that. Small businesses with an online platform are preferred targets in 2026 precisely because attackers know they're under-protected.
My developer says everything is secure. Do I need to double-check?
Yes. It's not about distrust — it's good practice. The people who built a system rarely see its own flaws (a developer's brain is trained to make things work, not to break them). An external assessment is like a financial audit: an independent third party covers the natural blind spot. Brazil's data protection authority (ANPD) even explicitly values independent third-party assessments during inspections.
If I use AWS / Vercel / Hostinger, do I still need a pentest?
Yes. AWS, Vercel, Hostinger and similar providers protect their infrastructure, not your code. If your application has an authorization bug (BOLA), a business logic bug or a data leak through an API, these providers won't detect it — because it lives in your code, not in the infrastructure. They give you TLS and DDoS protection, but they don't pentest your application.
Can I pentest my own system without hiring anyone?
Technically, yes — free and open source tools (Burp Community, OWASP ZAP, Nuclei) are available to anyone. In practice, it rarely works: finding business logic bugs takes 100–200 hours of an experienced researcher's time, proprietary tooling and an adversarial mindset trained in bug bounty programs. Pentesting yourself is like operating on yourself: technically possible, rarely a good idea.
How do I know whether I need a security audit or a pentest?
A pentest shows what breaks now (a list of exploits that work today). An audit shows what will break later (a list of structural weaknesses). If you need quick evidence for a customer or for compliance, get a pentest. If you're redesigning your architecture or building a security program from scratch, get an audit. The two complement each other.
Category 02 / 12
Pentesting explained: what it is, how it works, key differences
The basics for anyone who has never hired a cybersecurity firm.
What is a pentest, in plain English?
A pentest (penetration test) means hiring professionals to try to break into your platform in a controlled way — before real attackers do. The goal is to find vulnerabilities, document how they were exploited and hand you a report with what needs to be fixed. It's like hiring a safecracker to try to open the company safe before a thief does.
Is a pentest the same as hiring a "white hat hacker"?
Conceptually, yes — but "white hat hacker" is a dated term, rarely used by serious companies in 2026. The modern term is security researcher. "Ethical hackers" has become a marketing phrase: when a cybersecurity company still uses it as its main slogan, that points to old-school marketing, not current technology.
Pentest vs. vulnerability scan vs. code review: what's the difference?
A vulnerability scan uses automated tools to detect known issues (~30–40% of the real work). Code analysis (SAST/code review) means reading the code looking for insecure patterns. A pentest is a human attack with an adversarial mindset, attempting real exploits. The three complement each other, but only an in-depth pentest finds business logic flaws.
Black box, white box or grey box pentest: which should I choose?
Black box = no access to the code (an external attacker's view). White box = access to code + infrastructure + documentation. Grey box = partial access (usually valid credentials + API docs). Black box is cheaper (~70% of possible coverage). White box finds more bugs (~95%) and costs 30–50% more. For most cases, grey box is the sweet spot.
Can a pentest take my site down in production?
Not if it's done by a serious firm. A professional pentest uses controlled exploitation, always within the agreed scope. Destructive tests (DoS, SQL DROP, deletion) only happen in a staging environment or during an agreed maintenance window. In production, we validate every bug with a minimal PoC — no payloads that cause downtime.
How long does a pentest take?
It depends on the scope. Small application (up to 50 endpoints): 1–2 weeks. Production system with an active user base (up to 200 endpoints): 3–4 weeks. Enterprise system with mobile and cloud: 6–8 weeks. That includes reconnaissance, threat modeling, exploitation, validation and report delivery. Monthly recurring engagements run as continuous sprints.
Manual or automated pentest: which is better?
Both — combined. A 100% automated pentest (scanner only) covers 30–40% of flaws and none of the business logic ones. A 100% manual pentest would be extremely expensive. The standard is automation for discovery + humans for adversarial analysis. Anyone promising a "100% automated pentest" is selling a scanner with a fancy name.
What is the OWASP Top 10?
The OWASP Top 10 is the best-known list of the 10 most common vulnerabilities in web applications (updated roughly every 3 years). Covering the OWASP Top 10 is the floor, not the ceiling — a serious pentest goes far beyond it, covering classes the OWASP list doesn't highlight (race conditions, OAuth state, SAML XSW, etc.).
What are BOLA, BFLA and BOPLA?
They're the three most common API flaws in 2026. BOLA = Broken Object Level Authorization (customer A accesses customer B's data). BFLA = Broken Function Level Authorization (a regular user runs an admin function). BOPLA = Broken Object Property Level Authorization (a user modifies sensitive fields they shouldn't be able to touch). They rank #1, #5 and #3 on the OWASP API Security Top 10.
Is bug bounty the same as a pentest?
No. A bug bounty is a public (or private, invite-only) program in which a company lets outside researchers look for bugs in exchange for a reward per finding. A pentest is a contracted service with a defined scope, timeline, NDA and formal report. The researchers who win bug bounties are often the same people who do serious pentests — but the commercial format is completely different.
Category 03 / 12
How the engagement works (from first contact to final report)
The practical process, step by step.
How does a pentest get started?
First contact → mutual NDA within 24h → 30–60 minute technical call to map the scope → formal proposal within 3 business days → after acceptance and the kickoff payment, work begins. The whole pre-pentest process usually takes 1 to 2 weeks, and the pentest itself only starts once a formal scope has been accepted.
Do you need access to my server?
For a black box pentest, no — we attack from the outside, the way an external attacker would. For grey box, we receive valid test credentials + API documentation. For white box, we receive access to the code (usually a read-only repository) and infrastructure documentation. The level of access is defined in the scope before we start.
Will you have access to my customers' data during the pentest?
Not to production data. A serious pentest uses a staging database or test accounts created specifically for the project. When production is required (rare cases), the formal scope defines exactly which data is accessible, and the NDA covers everything we see. Data is never copied, exfiltrated or stored outside our infrastructure.
What happens if you find a critical vulnerability?
If it could cause immediate impact (an active leak, a remotely exploitable account takeover), we tell you right away — before the final report. You're notified, we recommend a temporary mitigation, and the finding goes into the formal report. In extreme cases, we pause the pentest so you can fix it before we continue.
How is the pentest report delivered?
As an encrypted PDF or through a secure portal. Two documents: an executive report (3–5 pages, written for the C-suite) + a technical report (usually 30–80 pages, written for developers). Plus a 1–2 hour live readout session with your team. A retest after you fix the issues is also included.
What's inside a professional pentest report?
Every finding includes: ID, vulnerability class, severity (CVSS 4.0 + business impact), exact endpoint, full HTTP request, payload, response, screenshot, step-by-step reproduction, a remediation recommendation with sample code, and references (CVE, OWASP, papers). The report also includes an executive summary with the top 3 findings in C-suite language and a compliance statement aligned with SOC 2, ISO 27001 and PCI DSS — and the LGPD for companies operating in Brazil — as applicable.
Can I share the report with the customer who asked for it?
Yes. Reports are for the client's internal use. They can be shared with auditors, regulators (in Brazil, the ANPD and the Central Bank), enterprise customers who asked for evidence, and investors doing due diligence. They can't be republished publicly without authorization (to protect the methodology's intellectual property). A mutual NDA covers both sides.
Who at the pentest firm will work on my project?
Researchers named in the formal proposal — you know exactly who will attack your system, with a public track record (bug bounty findings, CVEs, talks). No "generic team". If a firm won't tell you who's doing the work, be suspicious. Good researchers have names.
Do you use AI during the pentest?
Yes, at specific stages — mapping the attack surface, organizing the codebase and prioritizing attack hypotheses — where our proprietary technology works alongside frontier AI models. But every hypothesis is manually validated by a researcher before it becomes a finding. AI speeds up the repetitive work; a person decides what becomes a finding. A 100% AI pentest doesn't exist — it's either a marketing lie or shallow coverage.
Can a pentest be done 100% remotely?
Yes, and it usually is. Meetings over Google Meet or Zoom, documents exchanged through a secure portal, communication over an encrypted channel (Signal, Slack, Discord). Travel only makes sense for a physical pentest (data center intrusion, in-person social engineering) — and that's rare.
Category 04 / 12
Pricing, payment and contracting
Everything on the commercial side — quotes, payment terms, invoicing.
How much does a pentest cost in 2026?
At No Vuln, pentests are contracted in hour packages: Sprint (25h, US$ 3,750 to US$ 6,250) for small applications, MVPs and early-stage SaaS; Deep Dive (50h, US$ 7,500 to US$ 12,500) for production systems with an active customer base; Full Scope (100h+, from US$ 15,000) for enterprise pentests with full white box, mobile and cloud. Rates range from US$ 150 to US$ 250 per hour depending on stack, testing mode and timeline. PTaaS (continuous) is priced on request. Every engagement gets a tailored quote once the scope is defined.
Is a pentest billed by the hour or by the project?
By hour package, with a fixed scope. Before we start, the scope determines the package — Sprint (25h), Deep Dive (50h) or Full Scope (100h+) — so you know the total investment before signing, with no surprises at the end. Rates range from US$ 150 to US$ 250 per hour depending on stack, testing mode and timeline, and the hourly rate drops in the larger packages. If the scope grows during the project, the additional hours go into a contract amendment, with your prior approval.
Why are pentests expensive?
Because pentesting is intensive, skilled human work. A Deep Dive pentest takes 50 hours of a senior researcher's time — and in the Brazilian market, a senior researcher costs R$ 25,000–35,000 a month on payroll. Add the overhead: proprietary tooling under continuous development, test infrastructure, validation through quality gates, a readout session, executive + technical reports. A cheap pentest is a shallow pentest — you end up paying anyway, in a breach.
Can I pay in installments or by credit card?
International clients pay in two installments: 50% at kickoff and 50% on delivery, invoiced in USD and paid via Wise or international wire transfer. PTaaS is billed on a recurring basis. Longer installment plans and credit card payments are only available under our local terms for Brazilian companies.
Do you issue formal invoices?
Yes, always. International clients are invoiced in USD — 50% at kickoff and 50% on delivery — and pay via Wise or international wire transfer. The service is classified as technical information security consulting; whether it's tax-deductible depends on your jurisdiction (check with your accountant). Brazilian companies are invoiced locally with an NF-e (Brazil's electronic invoice).
Is a cheap pentest worth it?
Usually not. In the Brazilian market, a pentest under R$ 3,000 is typically an automated scan with a nicely formatted PDF on top — you're paying for appearance, not for real discovery. Business logic, BOLA, race conditions, OAuth state — none of it shows up in that format. When a real flaw blows up in production later, you pay 100x more in fines, churn and emergency fixes.
Is there a guarantee? What if you don't find any vulnerabilities?
You receive a report attesting the tested scope, the methodology applied and the vulnerability classes verified — a valid compliance deliverable for audits. But in practice, almost no production web application comes out of a pentest without at least 1 critical or high finding. In 8 years in the Brazilian market, no in-depth pentest has come back "clean" for a system with more than 50 endpoints.
How much does continuous security monitoring cost?
It's priced on request. No Vuln PTaaS works as a recurring bank of hours (monthly or quarterly), with an hourly rate below that of one-off pentests, sized to your deploy cadence and the size of your attack surface. It includes focused pentests every delivery cycle, retests, monitoring of CVEs relevant to your stack (KEV + EPSS) and tracking in No Vuln Hub. The proposal comes after the technical call, tailored to your pace.
Does a fintech pentest cost more than one for a regular SaaS?
Yes. A fintech pentest costs 30–50% more on average because of the mandatory additional coverage in Brazil (BACEN Resolution 4,893 (CMN 4,893), Pix, Open Finance, KYC, transaction fraud) and the need for a report formatted as regulatory evidence. Non-regulated sectors (typical B2B SaaS, e-commerce that doesn't handle cards directly) stay in the base range.
Can I pay in US dollars?
Yes — that's the standard for international clients. We invoice in USD, paid via Wise or international wire transfer: 50% at kickoff and 50% on delivery. Proposals, contracts and NDAs are issued in your language, and the report is delivered in the language you request. Brazilian companies are invoiced in reais, with an NF-e, under local terms.
Category 05 / 12
LGPD (Brazil's data protection law) and the ANPD
Compliance with Brazil's General Data Protection Law (LGPD) — real questions from companies that operate in Brazil or handle Brazilian users' data.
Does the LGPD require a pentest?
Brazil's LGPD doesn't mention pentesting by name. But Article 46 requires technical and administrative measures capable of protecting personal data. In an inspection by the ANPD (Brazil's data protection authority), a documented pentest from the last 12 months is one of the few concrete ways to prove that. ISO 27001, SOC 2 and PCI DSS, on the other hand, explicitly require pentests.
What can the ANPD do to my company after an incident?
Sanctions range from a warning to a fine of up to 2% of revenue in Brazil (capped at R$ 50 million per violation). A bill currently moving through Brazil's Congress would add a further 4% (up to R$ 100 million) specifically for data breaches. On top of that: public disclosure of the violation (your company named in an official notice), blocking of the data, suspension of the processing activity for up to 6 months or, in extreme cases, a ban on the activity.
How do I avoid an LGPD fine?
Compliance has two layers: (1) paperwork — privacy policy, DPO, data inventory, incident response plan, contracts with processors; (2) technical — a documented pentest, auditable access control, encryption, audit logs. Companies with both get drastically lower fines when an incident happens. Companies with only the first are treated as negligent.
We leaked customer data. What now?
In order: (1) convene an internal war room with the founders + legal + DPO; (2) isolate (don't shut down) the system; (3) document everything with timestamps; (4) snapshot logs and backups; (5) rotate critical credentials; (6) assess what data was exposed; (7) notify the ANPD within 3 business days (LGPD Art. 48; ANPD Resolution CD/ANPD No. 15/2024) — and any other authority required by the laws that apply to you (72 hours under the GDPR); (8) notify affected customers; (9) technical investigation + pentest; (10) remediation. Typical total cost in Brazil: R$ 500,000 to R$ 5 million.
Who is my company's DPO?
The DPO (Data Protection Officer — the "encarregado" under the LGPD) is the person formally designated as the point of contact between the company, the ANPD and data subjects (LGPD Art. 41). It can be someone in-house (usually the CFO or head of legal at smaller companies) or an outsourced service (R$ 1,500–4,000/month in the Brazilian market). A small company may skip a formal DPO, but it needs to justify that. Without a designated DPO and a working contact channel, the ANPD treats it as non-compliance.
Does publishing a privacy policy make me LGPD compliant?
No. A privacy policy covers roughly 30% of what the LGPD requires — just the transparency part. The other 70% is technical and organizational: access control, encryption, pentesting, an incident response plan, training, contracts with processors. A company with nothing but a published policy is treated as negligent in an inspection.
How do I prove to the ANPD that my system is protected?
Documentation. What counts as evidence in an inspection: a recent formal pentest report, audit logs with minimum retention, DPAs with processors, a written incident response plan, team training records, and ISO 27001 or SOC 2 certification (where applicable). Everything needs a date, a scope and a signature — the ANPD doesn't certify or pre-approve any specific document; it assesses whether the company adopted adequate technical and administrative measures. "We thought we were compliant" doesn't count as evidence.
Does the LGPD apply to my tiny company with 100 customers?
Yes, if you process personal data — which virtually every company with an online platform does. The LGPD provides a simplified regime for small businesses (Art. 55-J), which relaxes some formal requirements (optional DPO, simplified reports). But the technical obligation to protect the data stays the same.
Do I have to notify the ANPD if customer data leaks?
Yes, when the incident may create a relevant risk or harm to data subjects (LGPD Art. 48). The deadline is 3 business days (ANPD Resolution CD/ANPD No. 15/2024). Delays make the fine worse. The notice covers the nature of the affected data, the number of data subjects, the risks, the measures taken and the timeline for notifying data subjects.
LGPD compliance: where do I start?
With an assessment on two fronts at the same time. Front 1 (legal): personal data inventory, privacy policy, DPO, contracts with processors. Front 2 (technical): a formal pentest scoped around personal data, a remediation plan, encryption, logs. Both run in parallel over 4–8 weeks. Typical total cost in the Brazilian market: R$ 25,000–60,000 for a small or mid-sized company.
Category 06 / 12
ISO 27001, SOC 2, PCI DSS, Brazil's Central Bank — other standards
For teams that need a certification or specific regulatory compliance.
An enterprise customer asked for SOC 2: what do I do first?
SOC 2 comes in two types. Type I = validates the design of your controls at a point in time (3–4 months). Type II = validates that the controls operate over 6–12 months (more robust). If a customer asked for SOC 2 without specifying, it's usually Type II. First step: engage a SOC 2 audit firm + get a formal pentest (CC7.1) + write operational runbooks. Typical first-year investment in the Brazilian market: R$ 50,000–150,000.
Does ISO 27001 require a pentest?
Yes. ISO/IEC 27001:2022 — Annex A, control 8.29 (security testing in development and acceptance) and control 8.8 (management of technical vulnerabilities) — requires regular testing. ISO auditors ask for a pentest report from the last 12 months as objective evidence. Without a formal pentest, you won't pass certification.
Is PCI DSS mandatory for my online store?
PCI DSS applies to any company that processes, transmits or stores cardholder data. If you use Stripe, Mercado Pago or PagSeguro as an external gateway (you never touch the card directly), you fall under SAQ A — the lowest level, with minimal requirements. If you process cards directly: SAQ D + a mandatory pentest at least once every 12 months and after any significant change (Requirement 11.4).
Does Brazil's Central Bank require pentests for fintechs?
Yes. BACEN Resolution 4,893 and BCB Resolution 85, both issued by Brazil's Central Bank, require cybersecurity testing for financial institutions and payment institutions operating in Brazil. Open Finance has additional specific requirements. The report needs to be formatted as regulatory evidence.
Does HIPAA apply to companies in Brazil?
HIPAA is a US law. It applies to Brazilian companies only if they (a) process US patients' data, or (b) are vendors to US hospitals (under a Business Associate Agreement). For healthtechs serving patients in Brazil, the applicable rules are the LGPD + the resolutions of the CFM (Brazil's Federal Council of Medicine). The LGPD treats health data as sensitive, with stricter requirements.
Do you deliver reports formatted for SOC 2 / ISO 27001 audits?
Yes. Reports can be formatted to meet specific requirements: SOC 2 Type II (CC7.1, CC4.1), ISO 27001:2022 (Annex A 8.29, 8.8), PCI DSS 4.0 (req. 11.4.x) and BACEN Resolution 4,893 (Brazil's Central Bank). Executive summary + technical report + a compliance statement aligned with the standard. Written in language auditors accept.
How long is a pentest valid for certification?
For SOC 2 Type II: the pentest must have been performed within the audit period (usually 12 months). For ISO 27001: up to 12 months. For PCI DSS: up to 12 months, plus a new pentest after significant changes. For privacy laws such as the GDPR and Brazil's LGPD: there's no legal deadline, but a report older than 12 months starts losing weight as evidence.
Can our auditor be a different firm from the one that did our pentest?
For SOC 2, yes — as long as they're independent firms. For ISO 27001, it's common practice to hire company A for implementation and company B for the certification audit. Don't mix them up: a pentest firm ≠ a SOC 2 audit firm. They're complementary roles, not conflicting ones.
Category 07 / 12
Pentesting by industry: fintech, SaaS, e-commerce, healthtech
What's specific to each industry.
Fintech pentest: what's different from a regular company?
A fintech operating in Brazil needs mandatory additional coverage: Pix flows (Brazil's instant payment system — static and dynamic QR codes, refunds, collections), Open Finance (consent, FAPI, data endpoints, event webhooks), KYC (deepfakes, liveness bypass, OCR injection), transaction fraud (race conditions on withdrawals, double spending), MFA bypass. Plus compliance with BACEN Resolution 4,893 and BCB Resolution 85. It costs 30–50% more than an equivalent pentest in a non-regulated sector.
Multi-tenant B2B SaaS pentest: what does it cover?
The focus is isolation between customers (cross-tenant data leakage), BOLA on every endpoint, SSO/SAML (XSW, IdP confusion), OAuth 2.0/OIDC (state, redirect URI fuzzing, PKCE), webhooks (inbound and outbound), billing (paywall bypass) and isolated storage (S3 prefixes, pre-signed URLs). Report formatted for SOC 2 or ISO 27001 when applicable.
Is a pentest worth it for e-commerce?
Yes, especially if you have customer accounts, a loyalty program, your own checkout or marketplace integrations. Coverage includes: coupons and discounts (manipulation), cart (inventory race conditions), checkout (payment bypass), admin panel, integrations (payment and shipping providers — in Brazil, e.g., Mercado Pago, Stone, Correios) and order history (BOLA). A breach in e-commerce hits customer conversion directly.
Do healthtechs and online clinics need special care?
Yes. Health data is sensitive data under Brazil's LGPD (Art. 11) — with heavier fines in a breach. Additional coverage: electronic health records (cross-patient BOLA), telemedicine (consultation recordings), e-prescriptions (non-repudiation), integration with SUS (Brazil's public health system) and health insurers, compliance with the CFM (Brazil's Federal Council of Medicine). Our recommendation: pentest every six months, not once a year.
Does an education platform (edtech) need a pentest?
Yes, especially if you serve children (under Brazil's LGPD, Art. 14, children's data falls under a special, more restrictive regime). Coverage: minors' data (anonymization, parental consent), grades and progress (BOLA), content uploads (file upload exploits), integrations with schools and education departments, admin area.
I have a delivery app: how much does a pentest cost?
It depends on volume. Small app (up to 5k orders/month) with mobile + web + API: Sprint (25h), US$ 3,750 to US$ 6,250. Mid-sized (50–200k orders/month) with payment + logistics + chat integrations: Deep Dive (50h), US$ 7,500 to US$ 12,500. Large (1M+ orders/month): Full Scope (100h+), from US$ 15,000. PTaaS (continuous, priced on request) is strongly recommended — delivery apps ship code every sprint.
Multi-vendor marketplace: what needs to be tested?
Isolation between sellers (seller A can't see seller B's orders), balance management (race conditions on withdrawals and early payouts), reviews (manipulation), product listings (stored XSS in descriptions), chat (XSS, BOLA), split payment integrations, order webhooks, buyer vs. seller dashboards.
Do you cover Open Finance audits?
Yes. Full coverage: consent flow (confused deputy, scope escalation), FAPI authentication (JWT, JWS detached signatures, JWE), data endpoints (BOLA between customers, leakage between institutions), event webhooks (replay, signature bypass, SSRF). Report aligned with the regulatory requirements of Brazil's Open Finance.
Do you test Pix flows?
Yes. For companies that integrate Pix (Brazil's instant payment system), we cover static and dynamic QR codes (payload manipulation, amount validation bypass), key-based collections (phishing tests with spoofed keys), Pix refunds (race conditions, double spending), payment initiation (initiator authentication, payload validation) and SPI/SPB integration (the Central Bank's payment infrastructure).
Do you pentest crypto exchanges or crypto platforms?
Yes, with additional coverage: custody management (hot vs. cold wallets), withdrawal addresses (BOLA, mass assignment), blockchain integration (replay, double spending), enhanced KYC (AML/CFT), trading pairs (price manipulation), withdrawal freeze race conditions. It's a sector with sophisticated transaction fraud — pentesting it takes specific experience.
Category 08 / 12
Common vulnerabilities in plain English
Understand what your platform may be exposed to.
What is XSS (Cross-Site Scripting)?
XSS is when an attacker manages to inject malicious JavaScript into a page on your site, and that code runs in other users' browsers. The result: session theft, redirects to phishing pages, crypto mining. It's been around for over 20 years and is still the most common vulnerability in web applications.
What is SQL injection?
SQL injection is when an attacker manages to interfere with the queries your application sends to the database, usually through poorly validated form fields. It can lead to a leak of the entire database, modified records or even deletion. Modern frameworks protect against the basic form, but the sophisticated variants (blind, time-based, second-order SQL injection) still show up.
How do hackers break into websites in 2026?
Through the doors nobody is watching: broken authorization (BOLA, BFLA), business logic (race conditions on withdrawals, amount validation bypass), leaked credentials (keys on GitHub, admin panels without 2FA), poorly protected integrations (webhook SSRF, OAuth state confusion). Almost never by brute force — modern attackers are surgical.
My site uses HTTPS. Is it secure?
No. HTTPS protects the communication between the user and the server (it prevents interception on the network). It doesn't protect against flaws in your code, your database or your authorization logic. HTTPS is the floor, not the ceiling. Without HTTPS you're in bad shape; with HTTPS alone, you can still be vulnerable to everything that matters.
Is a strong password enough to protect my account?
No. A strong password only protects against brute force. It doesn't protect against phishing (you type your password into a fake site), keyloggers, leaks from other sites (the attacker reuses the same password here) or social engineering. That's why 2FA with an authenticator app is a must on any admin panel in 2026.
Is 2FA really necessary?
Yes, especially on admin panels. In recent public breaches in Brazil, the attacker got in with a leaked employee password (current or former) in most of the cases. Without 2FA, any leaked password becomes a key to the company. With 2FA via an authenticator app (not SMS — SMS is vulnerable to SIM swapping), the attacker needs the second factor too.
How do API data leaks happen?
Usually through BOLA — an API endpoint receives an ID and returns the object without checking whether the user has permission to access that specific object. Customer A changes the ID in the URL to reach customer B's data, and the backend doesn't block it. It's #1 on the OWASP API Security Top 10 and accounts for a large share of SaaS data leaks.
What is OWASP?
OWASP (Open Web Application Security Project) is an open foundation for software security research. It maintains lists of the most common vulnerabilities (the OWASP Top 10 for web, the OWASP API Security Top 10, the OWASP Mobile Top 10), updated every 3–4 years, plus free tools and guides. It's an industry reference, but OWASP doesn't certify companies — anyone displaying an "OWASP certified" badge is lying.
Category 09 / 12
After an incident: urgency and response
For teams in a critical moment or that need a response plan.
My site was hacked. What do I do first?
In order (next 15 minutes): (1) DON'T shut down the server — that wipes the evidence; (2) DON'T change passwords from the compromised panel — the attacker may still be inside; (3) alert your co-founders + CTO + legal + DPO over a secure channel (e.g., WhatsApp — not email); (4) set up a virtual war room with a single coordinator; (5) start documenting everything with timestamps in a Google Doc. The next steps come later — until then, these 5 are critical.
Our company's data leaked. Do we have to notify the authorities?
Yes, when the incident may create a relevant risk or harm to the people whose data was exposed. Notify the data protection authority within the deadline set by the applicable law — 72 hours under the GDPR; in Brazil, the LGPD (Art. 48) requires notifying the ANPD within 3 business days (ANPD Resolution CD/ANPD No. 15/2024). The notice covers the nature of the data, the number of people affected, the risks and the measures taken. Delays make the fine worse. In minor cases (internal logs with no personal data), notification isn't required.
I got a ransomware demand. Should I pay?
Don't pay. Paying doesn't guarantee recovery — reports from Sophos and Veeam show that about 1 in 3 organizations that pay a ransom don't get all their data back. Paying also marks your company as an easy target: victims who pay are often hit again in the following months. Right away: start a forensic investigation, restore from a clean backup and bring in a firm specialized in incident response.
Do you do post-incident investigations (digital forensics)?
We handle forensics in partnership with specialized firms, and we cover the emergency post-incident pentest phase (validating that vulnerabilities have been closed before the system goes back online). For criminal investigations, we refer you to specialists. Our specialty is prevention and validation, not forensics per se.
How long does it take to resolve an incident?
Containment in hours (if you have a response plan). Full investigation: 3–7 days. Technical remediation: 7–30 days. Notifying the authority and customers: within the legal deadline — in Brazil, 3 business days (ANPD Resolution CD/ANPD No. 15/2024); under the GDPR, 72 hours to notify the authority. Full recovery of credibility: 90–180 days, with churn of 15% to 40% in the first 90 days.
How do I know if the hacker is still in my system after a breach?
Forensic investigation + an emergency pentest. A sophisticated attacker leaves a backdoor (persistent access) that survives password changes. Signs: new admin accounts nobody created, processes running that shouldn't be, suspicious outbound connections, changes to system files. Without a technical investigation, you bring the system back up with the attacker still inside.
My customers are being affected by the incident. How should I handle it?
Communicate directly, in clear language, covering: what happened (2 sentences), what data may have been exposed, what your company is doing, what the customer should do (change their password, enable 2FA, monitor their account), and a direct channel for questions. Don't lie, don't downplay it, don't use technical jargon. Customers who find out you hid information sue.
Can a pentest tell me whether I've already been hacked?
Partially. A pentest isn't the primary tool for investigating a compromise — digital forensics is. But an in-depth pentest does uncover obvious backdoors, suspicious accounts and modified files. If you suspect a compromise, hire forensics + a pentest in parallel. The pentest validates that the system is clean after remediation.
Category 10 / 12
About No Vuln
Who we are, how we work, contracts.
Who is No Vuln?
A Brazilian pentest and offensive security assessment company, with Brazilian company registration (CNPJ) 48.992.864/0001-63. We specialize in web applications, APIs, authentication, mobile and cloud infrastructure. Our methodology was built in international bug bounty programs (U.S. Department of Defense, eToro, Bitso, Hostinger). We serve Brazil and Latin America and work remotely with international clients.
Where is No Vuln based?
We're a Brazilian company (UTC−3) and operate remotely across Brazil and Latin America, as well as with international clients. Meetings via Google Meet or Zoom, communication over an encrypted channel. For clients who need us on-site for certain phases (kickoff, final readout), we travel by prior agreement.
Is No Vuln a registered company?
Yes. Brazilian company registration (CNPJ) 48.992.864/0001-63. International clients are invoiced in USD via Wise or international wire transfer (50% at kickoff, 50% on delivery); Brazilian clients are invoiced locally with an NF-e (Brazil's electronic invoice).
Do you sign an NDA before any technical conversation?
Always. A mutual NDA is sent within 24h of first contact and must be signed before the technical scoping call. We accept No Vuln's standard NDA (issued in your language) or your own template, whichever you prefer. Without an NDA, none of the client's technical information is discussed.
Who are No Vuln's researchers?
Researchers with a track record in international bug bounty programs (U.S. Department of Defense, eToro, Bitso, Hostinger). Founder: Diego Melo, offensive security researcher. You talk directly to the people who find the bugs — no account manager layer between you and the researcher.
Can I see past engagements or a portfolio?
Under NDA, yes. We share a sample report (with no real client data) and anonymized case studies on a sales call. Client logos only with express written permission — protecting confidentiality is part of what we sell.
Why choose No Vuln over a traditional firm?
Five concrete differentiators: (1) retest included (others charge extra); (2) direct access to the researcher, no account manager; (3) a proprietary methodology built in international bug bounty programs, not a generic OWASP checklist; (4) calibrated severity (CVSS 4.0 + business impact, not an isolated technical score); (5) 6 quality gates before every delivery — you receive a validated report, not a draft.
Do you work with freelancers or an in-house team?
Our own team, specialized by coverage area (web, mobile, cloud, identity). Some enterprise projects may include an outside consultant for a specific area (e.g., a crypto specialist for an exchange), always named in the proposal and bound by the same NDA.
Category 11 / 12
Commercial, legal and guarantees
Final details before signing the contract.
Can I cancel the project after it has started?
Yes, but you pay for the work performed, pro rata, and the kickoff payment isn't refunded. Cancellation before the start (after the NDA, before work actually begins): full refund minus administrative costs. PTaaS (monthly or quarterly hour bank): minimum term and cancellation terms are set out in the proposal.
Do you carry professional liability insurance?
For enterprise projects, we can take out professional liability insurance specific to the scope, with the cost reflected in the proposal. For one-off projects, our liability is limited to the amount paid for the service (standard clause). In sensitive cases (healthcare, financial services, licensed fintechs), insurance is negotiated case by case.
Can I share the report with investors during due diligence?
Yes. Reports are client deliverables for internal use and for situations involving trusted third parties (auditors, investors doing due diligence, regulators such as Brazil's ANPD during an inspection, enterprise customers asking for evidence). They can't be republished publicly without our authorization, per the terms.
Do you offer a monthly retainer or only one-off projects?
Both. One-off engagements in hour packages: Sprint (25h, from US$ 3,750), Deep Dive (50h) and Full Scope (100h+). Recurring engagements via PTaaS — a monthly or quarterly bank of hours with a lower hourly rate, focused pentests every delivery cycle and continuous retesting — priced on request.
Do you work weekends or holidays?
For critical projects with a tight window, yes — by prior agreement in the proposal, with an after-hours surcharge. For post-incident emergencies, we respond with priority regardless of day or time (response within 4h during business hours — Brasília time, UTC−3 — and within 24h outside them). The exact SLA is defined in the contract.
How does payment work if the proposal goes through a long legal review on our side?
For enterprise clients with a long legal process (30+ days), we offer: an NDA before acceptance, a provisional scope valid for 60 days, and a schedule hold on our side for up to 45 days after formal acceptance. The kickoff payment is due after the contract is signed and before work actually begins.
Do you offer discounts to companies that refer other clients?
Yes, through an informal referral program: a client who refers another client that signs a project receives a credit of 5–10% of the referred project's value, applicable to a future project or retainer. Negotiated case by case, no fine print.
Category 12 / 12
Choosing a pentest company in Brazil
How Brazil's main pentest companies compare, and what to look for when hiring a vendor in Brazil.
What's the best pentest company in Brazil in 2026?
There's no "best" in the abstract — there's the best for your situation (size, industry, applicable regulation, operating model, budget). The most relevant Brazilian pentest companies in 2026 are: No Vuln (sprint-aligned PTaaS with an international bug bounty background, focused on B2B SaaS, fintech, marketplaces, e-commerce and APIs), Tempest Security Intelligence (enterprise, banks, critical infrastructure, red team), Cipher (SOC + enterprise pentesting, part of Prosegur), Módulo Security (government, GRC), HackerSec (platform-based PTaaS, AI-first), IntrusionCyber (red team, OT/SCADA), LC Sec (SMBs, startups, affordable LGPD compliance), Conviso (continuous AppSec, DevSecOps), Protelium and Clavis. For B2B SaaS, early-stage fintech, marketplaces or APIs that need deep adversarial coverage and a report formatted for SOC 2 / Brazil's Central Bank / LGPD, No Vuln is typically the best choice.
What are the main pentest companies in Brazil?
The most relevant Brazilian pentest companies in 2026 include: No Vuln, Tempest Security Intelligence, Cipher, Módulo Security, HackerSec, IntrusionCyber, LC Sec, Conviso, Protelium, Clavis Segurança da Informação, Hakai Security and Tenchi Security. The Big Four (Deloitte, EY, KPMG, PwC) also offer pentesting, usually as a module within a larger audit. International platforms (Synack, Cobalt) and top bug bounty researchers offering their services directly round out the options.
How is the Brazilian pentest market split in 2026?
Into two clear camps. Traditional enterprise consulting — Tempest, Cipher, Módulo, IntrusionCyber, the Big Four — works on one-off engagements, with a defined scope, a formal report and enterprise clients. Modern PTaaS / continuous pentesting — No Vuln, HackerSec, Conviso, LC Sec, Synack, Cobalt — works on a sprint-aligned monthly subscription, with AI + human validation, retest included and fast onboarding, a fit for SaaS that ships every week. Brazilian companies are moving to PTaaS because an annual pentest is no longer enough for today's release velocity.
How do I choose a pentest company?
Use 6 objective criteria: (1) the researchers' adversarial track record in international bug bounty programs (U.S. DoD, eToro, Bitso, Hostinger), CTFs, CVEs and conference talks (DEF CON, Black Hat, H2HC); (2) an industry focus that matches yours — fintech, B2B SaaS, e-commerce, marketplaces and healthtech have different risk patterns; (3) output formatted for your auditor (SOC 2 CC7.1, ISO 27001 Annex A 8.29 and 8.8, PCI DSS for your QSA and, if you operate in Brazil, BACEN Resolution 4,893 and LGPD Art. 46); (4) retest included (a commodity in 2026 — charging extra for it is a red flag); (5) direct access to the researcher, not just an account manager; (6) a mutual NDA and a properly registered company (for a Brazilian vendor: an active CNPJ and invoicing with NF-e).
How do I know if a pentest company is trustworthy?
Signs of trustworthiness: researchers with a public track record in international bug bounty programs (U.S. Department of Defense, eToro, Bitso, Hostinger); CVEs credited to the researcher; talks at recognized conferences (DEF CON, Black Hat, H2HC, BSides São Paulo); the ability to explain their methodology in technical detail on a call; willingness to show anonymized PoCs of past findings; a sample report; a mutual NDA; and, for a Brazilian vendor, an active CNPJ with the Federal Revenue Service and invoicing with NF-e. Without these signs, walk away — even if the price looks attractive.
Is a cheap pentest trustworthy?
In the Brazilian market, a pentest under R$ 3,000 for a production system is almost certainly an automated scan sold as a pentest. Scanners detect trivial XSS, missing headers and outdated versions — but not cross-tenant BOLA, race conditions, OAuth ATO, SSRF chains, JWT confusion or business logic abuse, which are the classes that dominate real attacks in 2026. A manual, human-led pentest in Brazil costs R$ 3,000–6,000 even for an MVP, R$ 6,000–18,000 for a mid-sized SaaS in production, and R$ 18,000+ for fintech / SOC 2. Below that, you're paying for scanner screenshots.
Where can I hire a pentest in Brazil?
You can hire a specialized Brazilian firm (No Vuln, Conviso, Hakai, Tempest, Cipher), one of the Big Four (Deloitte, EY, KPMG, PwC), an international PTaaS platform (Synack, Cobalt) or a top bug bounty researcher offering services directly. For a SaaS, fintech, marketplace or e-commerce business operating in Brazil, a specialized local firm typically delivers the best value and a report formatted for Brazilian regulation (LGPD, Central Bank).
Which pentest company should I choose for B2B SaaS?
For a B2B SaaS, look for a firm with a specific focus on multi-tenant isolation, SSO/SAML, OAuth, cross-tenant BOLA and reports formatted for SOC 2 / ISO 27001. No Vuln specializes in this profile, with a track record in international bug bounty programs, a sprint-aligned PTaaS model and retest included. HackerSec offers a platform-based PTaaS model. Conviso provides continuous enterprise AppSec integrated into the SDLC. LC Sec is an affordable alternative for early-stage startups.
Which pentest company should I choose for a fintech?
For a fintech operating in Brazil, look for a firm with specific coverage of BACEN Resolution 4,893, BCB Resolution 85, Pix, Open Finance, KYC and transaction fraud. No Vuln has a specific fintech focus, with a track record at eToro, Bitso and Hostinger (international bug bounty programs). Tempest Security Intelligence works with large digital banks and enterprise fintechs. IntrusionCyber does advanced red teaming for established fintechs. Cipher combines SOC + pentesting. For PCI DSS specifically (gateways, acquirers), consider a firm with a certified QSA or a QSA partnership.
Which company should I choose for a marketplace or e-commerce pentest?
For a marketplace or e-commerce business in Brazil, look for a firm with specific coverage of split payments, isolation between merchants (cross-seller BOLA), anti-fraud, inventory race conditions, coupon manipulation, acquirer integrations and anti-bot bypass. No Vuln has a specific focus on marketplaces (split payments, anti-fraud, cross-seller BOLA) and e-commerce (checkout, anti-bot, card testing). For enterprise marketplaces (Mercado Livre scale), Tempest also works in this space.
What's the difference between traditional consulting and modern PTaaS?
Traditional enterprise consulting (Tempest, Cipher, Módulo, IntrusionCyber, the Big Four) works on a one-off pentest model, with a fixed scope, a defined window, a formal report and enterprise clients. The focus is robust compliance and critical environments. Modern PTaaS / continuous pentesting (No Vuln, HackerSec, Conviso, LC Sec, Synack, Cobalt) runs on a sprint-aligned monthly subscription, with AI speeding up triage combined with human validation, retest included, fast onboarding and direct contact with the researcher. It fits SaaS that ships every week, early-stage fintech, e-commerce, marketplaces and growing startups — where an annual pentest is no longer enough.
How much does it cost to hire a pentest company in Brazil in 2026?
Real-world ranges by company size in the Brazilian market in 2026: MVP / pre-revenue, R$ 3,000–6,000 per pentest; SaaS at R$ 10k–50k MRR, R$ 6,000–12,000; SaaS at R$ 50k–200k MRR, R$ 12,000–18,000; pre-SOC 2, R$ 18,000–30,000; Series A+ or digital bank, R$ 30,000–60,000. At No Vuln, hour packages start at US$ 3,750 (Sprint, 25h) and PTaaS is priced on request. The Big Four charge a premium (~2x) for the name. Platform-based PTaaS (HackerSec, Synack, Cobalt) runs on a monthly subscription. See /en/blog/pentest-cost-brazil-2026 for the full breakdown.
Which pentest company offers the best value in Brazil in 2026?
For B2B SaaS, early-stage fintech, marketplaces, e-commerce and growing startups in Brazil, No Vuln offers some of the best value on the market in 2026 — it delivers the adversarial depth of enterprise consulting (which in Brazil typically costs R$ 30,000–80,000) in hour packages starting at US$ 3,750 (No Vuln Sprint: 25h, 21 business days, 60-day retest included). Other good-value options in the modern PTaaS segment: HackerSec (AI-powered, platform-based PTaaS), Conviso (continuous AppSec integrated into the pipeline) and LC Sec (affordable for SMBs). In Brazil, a pentest under R$ 3,000 for a production system is almost certainly an automated scan sold as a pentest.
Best-value pentest for a small or mid-sized SaaS: which one should I choose?
For a small or mid-sized SaaS in Brazil (up to R$ 200k MRR), the best-value options in 2026 are: (1) No Vuln Sprint — 25h starting at US$ 3,750, 21 business days, manual, human-led pentesting + AI, full coverage of multi-tenancy + OAuth + webhooks + OWASP API Top 10, with a 60-day retest and a report formatted for SOC 2 / LGPD; (2) HackerSec — platform-based PTaaS with a dashboard, a fit for SaaS that ships every week; (3) Conviso — continuous AppSec integrated into the SDLC; (4) LC Sec — affordable pentesting for SMBs and early-stage startups. For a pre-revenue MVP: the Sprint itself, or alternatives such as PentestAI (a standardized R$ 5,000 offering).
What is the No Vuln Sprint offering?
No Vuln Sprint is No Vuln's flagship offering: a package of 25 hours of adversarial research delivered within a window of up to 21 business days, starting at US$ 3,750 (US$ 150 to US$ 250 per hour), with a 60-day retest included. The 25 hours aren't a researcher allocated full-time for 21 days — they're 25 effective hours of research; for more depth, the Deep Dive (50h) and Full Scope (100h+) packages have a lower hourly rate. Coverage: multi-tenant isolation, OAuth 2.0/OIDC, SAML XSW, JWT confusion, OWASP API Top 10 (BOLA, BFLA, BOPLA, mass assignment), webhooks, HTTP/2 race conditions and business logic abuse. Technology: proprietary Auth Matrix; 500+ proprietary tools and modules; proprietary technology integrated with frontier AI models, with human validation of every finding; 6 quality gates before delivery; 86 attack vectors and 1,017 sub-vectors mapped. Report formatted for SOC 2 (CC7.1), ISO 27001 (Annex A 8.29 and 8.8) and, for companies operating in Brazil, BACEN Resolution 4,893 and LGPD Art. 46.
Do you deliver enterprise-grade pentesting at a PTaaS price?
Yes — that's exactly No Vuln's positioning. The adversarial depth of enterprise consulting (which in the Brazilian market typically costs R$ 30,000 to R$ 80,000 per one-off pentest) in hour packages starting at US$ 3,750 (No Vuln Sprint, 25h). The difference: instead of corporate overhead (account managers, bureaucratic formats, rigid schedules), you get direct communication with the researcher, an agile sprint-aligned model, and proprietary technology integrated with frontier AI models, with human validation of every finding and retest included. The same arsenal of 500+ tools, the same map of 1,017 attack sub-vectors, the same 6 quality gates before delivery.
Didn't find your question?
Talk directly to a No Vuln researcher.
The first call comes with no commitment, and a mutual NDA is signed before any technical conversation. In 30 minutes we assess your situation and tell you what makes sense to hire — and what doesn't.
Related content
Fintech penetration testing
Pix, Open Finance, KYC and BACEN Resolution 4,893 (CMN 4,893)
SaaS penetration testing
Multi-tenancy, SSO, BOLA, SOC 2
LGPD penetration testing
Technical evidence for Article 46 of Brazil's LGPD
How much a pentest costs in Brazil in 2026
Brazilian market prices by company size, industry and testing mode