Who can use this feature
Available as an Add-On for all plans. Contact your CSM to know more.
Scrut's Penetration Testing as a Service (PTaaS) is a managed security program. This article explains who conducts your testing, what they test for, how findings are validated before reaching you, and why the reports PTaaS produces are accepted by auditors, enterprise customers, and regulators.
What is PTaaS?
PTaaS (Penetration Testing as a Service) is Scrut's managed penetration testing service, not a one-off test. Scrut's certified Security Experts (SEs) run the testing program, validate every finding before it reaches you, and verify every fix you submit. Your role is to onboard your targets, remediate verified findings, and mark fixes as done.
Testing Credentials & Accreditations
CREST-Accredited
Scrut holds CREST accreditation, a formal recognition by an independent body backed by government and industry that Scrut's processes, methodologies, tools, and people meet stringent, regularly audited standards for penetration testing. CREST accreditation is not self-certified. It requires Scrut to demonstrate that its testing methodology, tooling, and personnel consistently meet professional norms. You can verify Scrut's CREST status directly on the CREST website.
CREST accreditation functions similarly to the accreditation an audit firm holds when certifying your SOC 2 or ISO 27001 compliance: it is an independent signal that the organization performing the assessment has been vetted against a recognized professional standard and can be trusted to produce defensible results.
Individually Certified Security Experts
Every Security Expert (SE) who conducts a pentest on your application holds globally recognized offensive security certifications, including Certified Ethical Hacker (CEH), eCPPTX, eWPTX, and Red Team expert credentials. These are not organizational certifications. They are individual certifications, which means each person who does your assessment has been independently evaluated on advanced offensive security skills.
When you share a PTaaS report with an enterprise customer or a regulator, you can state with accuracy that the testing was performed by individually certified pentesters working within a CREST-accredited organization, and that both can be independently verified.
Testing Approaches
Scrut's Security Experts establish the testing approach at the start of each engagement and explain it to you before work begins. The three approaches used are:
Approach | What it means |
|---|---|
Black-box | Testing is conducted without credentials or prior knowledge of the application's internals, simulating an external attacker with no privileged access. |
White-box | Testing is conducted with full access to application architecture, source code, and credentials, enabling the deepest possible coverage. |
Grey-box | Testing is conducted with partial knowledge, typically including authenticated user credentials but not source code. This is the most common approach for web application pentests. |
The approach used for your engagement, and the rationale for any credentials requested, is documented in your engagement report.
Tooling
Scrut uses professional-grade commercial tools that are widely used by penetration testers globally to simulate realistic attacker behavior and achieve broad coverage across known vulnerability classes. This is distinct from running a free or commodity scanner. Commercial tooling combined with certified expert analysis is what allows Scrut to discover complex vulnerability chains and business logic flaws that automated-only approaches miss.
How Findings Are Validated Before You See Them
Every finding, whether from the automated DAST and AI agent scans or from the manual expert pentest, goes through review by a Scrut Security Expert before it is published to your account. You never see raw, unvalidated scanner output.
This expert review gate has two consequences for you:
First, you see no false positives. Every finding in your account is a confirmed vulnerability that a real attacker could exploit.
Second, every finding is backed with expert advisory: human-authored remediation guidance for Critical and High findings, with context on business impact and, where applicable, code-level suggestions. This is not a generic description of a vulnerability class. It is remediation guidance specific to how the vulnerability was found in your application.
What Your Reports Include
After every Full Pentest, Scrut delivers two reports:
The Preliminary Report is a point-in-time snapshot of the assessment, generated once all findings from the automated and manual phases have been published. It is available regardless of your remediation progress and can be used to unblock compliance timelines or to share with enterprise customers during security reviews.
The Final Report is generated after you complete remediation and request it. It is the primary compliance deliverable.
Both reports include:
Executive summary
Scope of testing and assumptions
Testing methodology and approach
Tools used during the engagement
Testing phases and timeline
Detailed findings with evidence, reproduction steps, impact, and remediation guidance
Remediation status for each finding
Risk posture assessment
The combination of CREST accreditation, individually certified pentesters, documented methodology, commercial-grade tooling, and the level of finding detail in these reports is what allows customers to present PTaaS reports as credible, defensible evidence to auditors, regulators, and large enterprise customers.
How PTaaS Maintains Continuous Security Coverage
A single annual pentest produces a point-in-time snapshot of your security posture. That snapshot begins to decay immediately as your code changes, new dependencies are introduced, and new vulnerability classes are published. PTaaS is designed to address that decay through two types of activities that run in a continuous cycle across the year.
Full Pentests run twice a year. Each pentest combines automated scanning (DAST + AI agents) with manual expert testing. After every pentest, Scrut delivers an audit-ready report you can share with auditors, enterprise customers, your compliance team, and other stakeholders.
Release Scans run monthly. Release Scans are automated and check for regressions (previously fixed vulnerabilities that have reappeared in new code). However, they do not include manual testing and do not produce a formal report.
Every finding, whether from an automated release scan or a pentest, goes through expert review before it reaches your account. You will only ever see verified, actionable findings.
Note: Scan timing is managed by Scrut's Security Expert team based on your program calendar. You cannot trigger scans manually.
How PTaaS Supports Your Compliance Evidence Requirements
For most compliance frameworks, including SOC 2, ISO 27001, and PCI-DSS, auditors require evidence of recent, qualified penetration testing. With two Full Pentests per year by default, your most recent PTaaS report is at most six months old at any point in the year. This satisfies the evidence cadence requirements of most major frameworks.
Because every report documents CREST accreditation, certified pentester credentials, the testing methodology, and the complete finding detail, the reports are structured to be directly usable as audit evidence without additional interpretation or supplementary documentation.
When compliance evidence mapping ships, findings will also map directly to specific controls in SOC 2, ISO 27001, and other frameworks, linking your security testing posture to your compliance posture in a single view.
Heads Up!
Compliance evidence mapping will be available in a future release. Your CSM will notify you when it becomes available.
Reach out to support@scrut.io or contact your CSM for further assistance.