> Source: https://planckproof.ai/faq  |  Plain-Markdown twin of the page.

FAQ

# Questions, answered plainly

These are the questions we hear most often from security leads, engineering managers, and procurement teams. The answers below are the same ones we give on a call. If yours is not covered, write to us and a practitioner will reply within one business day.

Engagements

## Scoping, models, and timelines

How do we start an engagement?

Write to [info@planckproof.ai](mailto:info@planckproof.ai) or use the form on our [contact page](https://planckproof.ai/contact). We reply within one business day, execute a mutual NDA, and then hold a short scoping call to understand your targets, objectives, and constraints. Within a few days of that call you receive a fixed proposal covering methodology, team composition, timeline, and price. Once you approve it, we agree on dates and lock the team.

Do you sign an NDA before scoping?

Yes, always. Scoping requires architecture detail, URLs, and sometimes documentation you would not share with an outside party otherwise, so a mutual NDA comes before any of it changes hands. We have a standard template ready, and we are equally comfortable signing yours if it covers mutual obligations.

How are scope and price set?

Operator is priced per protected API by endpoint volume, on a decreasing per-endpoint curve. Pro includes four runs a month; more runs raise the price. Development, staging, and production cost the same. Your First Scan is free. Final scope and price are quoted.

Scope is defined by what needs testing and to what depth: the number of APIs and user roles, API operations, and the objectives you care about. If testing reveals that the environment is materially larger than described, we tell you and agree on next steps before expanding anything. We would rather resize a scope openly than deliver shallow coverage quietly.

What is the difference between black box, gray box, and white box testing?

The difference is how much knowledge and access we start with. Black box begins from an outside position with no credentials, which models an opportunistic external attacker but spends a share of the schedule on discovery. Gray box adds test accounts and documentation, so more of each day goes into depth rather than reconnaissance; it is the model we recommend for most application and API work. White box adds source code or configuration access and delivers the highest assurance per hour of testing, since we can trace a suspicious behavior straight to its cause. The right choice depends on the question you want answered, and we help you pick during scoping.

How long does an engagement take?

A single web application, API, or external network assessment typically runs one to three weeks of active testing, depending on size and depth. Internal network work, cloud reviews, and multi-asset scopes run longer, and red team operations are measured in weeks rather than days by design. Your proposal states the exact schedule, and the report follows within five business days of the last test day.

Do you test production or staging?

Either, and we decide together during scoping. Production gives the truest picture of what an attacker faces, and we test it carefully: no destructive payloads, agreed testing windows, rate limits respected, and an emergency contact on both sides. Staging is the right place for intrusive test cases and load-sensitive components, provided it mirrors production configuration closely. Many clients split the difference, running intrusive cases against staging and verifying a subset of findings in production.

Packages & Frequency

## Packages, testing frequency, and support

Can I buy just one penetration test per year?

Yes. The Annual Assessment is a single scheduled agentic API penetration test, run once a year. It is a point-in-time engagement, not continuous scanning. Every finding ships with request and response evidence, reproduction steps, and a CVSS v3.1 vector. Scope and price are confirmed in your [quote](https://planckproof.ai/contact).

How does annual testing differ from recurring scans?

They are different cadences. The Annual Assessment is one scheduled test per year. Pro runs recurring scans through the year, wired into your integrations, so operations are re-tested as your API changes; running more scans raises the price. Choose the annual option for a periodic checkpoint, and Pro when you want ongoing coverage between releases. See the [pricing page](https://planckproof.ai/pricing) for both.

Is support available 24/7?

Pro includes 24/7 support for scan-related questions and issues, so you can reach us about a running or completed scan at any time. This is scan support, not 24/7 threat monitoring or continuous manual testing. Unless separately agreed, it does not imply a guaranteed response time, a dedicated analyst, or an SLA.

How is the free First Scan different from the startup program?

Your First Scan is free: one complete agentic API penetration test that tests every operation and proves each finding with a reproducible proof-of-concept, self-serve, with no demo or quote. The [startup design-partner program](https://planckproof.ai/startups) goes further for teams actively building an API: two additional full agentic penetration tests, free. Eligibility and terms are on the startups page.

Deliverables & Support

## What you receive and what happens after

What is in the report?

An executive summary written in plain language for leadership, followed by technical findings. Each finding includes a description, the affected assets, step-by-step reproduction instructions, supporting evidence such as request and response data or screenshots, a CVSS v3.1 rating, and remediation guidance aimed at the team that will implement the fix. The report closes with a methodology and coverage appendix, so you know exactly what was tested and what was not. Every report is followed by a live debrief call with the testers. For the broader controls we check against, see our [API security best practices](https://planckproof.ai/blog/api-security-best-practices) checklist.

Do you use CVSS?

Yes. Every finding carries a CVSS v3.1 vector and score. We also add a short written justification for each rating, because a vector string on its own can mislead: a technically severe issue behind three layers of authentication is a different problem from the same issue on an unauthenticated endpoint. The score gives you a common language for tracking; the justification gives you the context to prioritize honestly.

Is a retest included?

It is. Every assessment includes one retest of fixed findings at no additional cost. When your team has remediated, we verify each fix against the original reproduction path, check that the change did not introduce an obvious regression nearby, and issue an updated report marking each finding as resolved or still open. Retests are typically scheduled within an agreed window after report delivery.

Do you help engineering fix the issues?

Yes, within the bounds of an assessment. Remediation guidance in the report is written for implementers, not auditors, and the debrief call is a working session where your engineers can ask the testers anything. During the remediation window the engagement team remains reachable for follow-up questions about specific findings. If you want deeper involvement, such as reviewing a proposed redesign, we can scope advisory time separately.

Who sees the report and how is it delivered?

Only the recipients you designate. Reports are delivered over an encrypted channel agreed at kickoff, typically PGP-encrypted mail or a secure transfer link, never as a plain email attachment. Inside our firm, access is restricted to the engagement team, and engagement material is retained and destroyed on the schedule set in your agreement. Our [Trust & Data Handling](https://planckproof.ai/trust) page describes the full lifecycle.

Working With Us

## People, data, and long-term programs

Who actually does the work?

Senior practitioners who work for us. We never outsource or subcontract delivery, and there is no junior bench learning on your systems. The people on your scoping call are the people who execute the engagement, and you communicate with them directly throughout. That is a structural choice: small teams of experienced testers produce better findings than large teams of interchangeable ones.

How do you handle our data?

On the principle of least data for the shortest time. We collect only what the engagement requires, store evidence encrypted at rest, restrict access to the assigned team, and destroy engagement material on the schedule defined in your agreement. Findings are never reused, anonymized into marketing, or shared across clients. The full policy is documented on our [Trust & Data Handling](https://planckproof.ai/trust) page.

Do you offer continuous testing programs?

We do. Beyond one-time assessments, we run standing programs: recurring assessments aligned to your release cycle, quarterly external testing, or a retainer that lets your team pull us in when a significant change ships. Continuity has a compounding benefit, because the same testers return each cycle carrying real knowledge of your architecture, your history, and where regressions tend to appear.

Get Started

## Ask us the question that is not here

Send the specifics of your situation and a senior practitioner will answer within one business day. An NDA is ready before any sensitive detail changes hands.

[Talk to an Expert](https://planckproof.ai/contact)

[Our Methodology](https://planckproof.ai/methodology)
