All capabilities
Fig 2.1

Pentest

A graded security pass you can hand to a customer.

Pentest is a one-time Optics add-on that finds the way into your own app before someone else does. Cheap checks finish in under a minute on a typical app, under three minutes on a large repo; a full review of your own code follows in the same purchase. Every weakness comes back rated, tracked until it is fixed, and graded A+ to F.

01 · How it works
01

Cheap checks run first

Cookies, GitHub Actions, editor hooks, packages, source maps, stack traces and caller-supplied URLs are checked before the graded review. Each finding is open, fixed or accepted.

02

The score is weighted, not counted

One critical outranks a pile of lows, and passing checks count toward the total. A run scores out of 100 and carries a letter from A+ to F.

03

Every pass is kept

Runs stack up, so the grade moving from D to A is itself the evidence. That progression is usually what a customer actually wants to see.

02 · What you get

Find the way in before someone else does.

  • Walks you through a full security check of your own app
  • Cheap checks finish in under a minute; a full review of your own code follows in the same run.
  • Session cookies and tokens left in the browser
  • GitHub Actions that run untrusted pull requests with secrets
  • Editor hooks that run a shell when a folder or session opens
  • Install scripts that pipe a remote shell, and planted package names
  • Tracked JavaScript source maps, and remote scripts with no integrity check
  • Error stack traces returned to the client
  • Fetches and redirects of a URL the caller supplied
  • Every weakness rated by how much damage it could do
  • A ready-made fix to hand a developer for each one
  • See whether you are getting safer run after run
03 · The output
You end up with

A report you can send

Cheap checks cover cookies, GitHub Actions, editor hooks, packages, source maps, stack traces and caller URLs. Each pass has a shareable link showing the grade and the findings summary, without exposing the detail behind them.

Setup
Run the skill probes (`optic preflight`), then a full review. Scoring and the report are what Optics adds.

04 · Pricing
One-time purchase

$299

Pay once and Pentest is unlocked for your whole organization, on top of a Pro or Team plan. Not a subscription, and never priced per run.

Or get the bundle

Resilience Suite: $619

Pentest, Load Testing and DDoS Resilience in one purchase. 17% off buying them separately, saving $128.

See the suite
05 · Questions

What is a pentest run in Optics QA?

It is someone trying to break into your app on purpose, so you find the way in first. Optics walks you through the check, then scores what comes back: every weakness rated by how much damage it could do, marked open, fixed or accepted, and the whole run graded A+ to F with a report you can share.

How long does a run take?

Cheap checks finish in under a minute on a typical app, and under three minutes on a large repo. A full review is a session of work on your own code, not a second purchase.

What do the cheap checks look at?

Session cookies and tokens left in the browser. GitHub Actions that run untrusted pull requests with secrets. Editor hooks that run a shell when a folder or session opens. Install scripts that pipe a remote shell, and planted package names. Tracked JavaScript source maps, and remote scripts with no integrity check. Error stack traces returned to the client. Fetches and redirects of a URL the caller supplied.

Do I upload one file or two?

Two shapes, never mixed. Cheap probes go up as `_security/preflight.json` with `--engine preflight` (or `optic preflight`). A full pipeline upload is `_security/findings.json` with `--engine native` or `talon`.

Do tests run against my infrastructure?

Yes — against your own app, and only yours. Everything runs from your own environment against code and sites you own. What comes back to Optics is the scoring, the tracking, the fixes, and the report you can hand to someone.

Is this a subscription?

No. Pentest is a one-time $299 purchase that unlocks the capability for your whole organization, on top of a Pro ($69/month) or Team ($249/month) plan. You never pay per run.

How is the score calculated?

The score is weighted, not counted: a single critical finding costs more than a handful of lows, and passing checks count toward the total. Each run scores out of 100 and carries a letter grade from A+ to F, so the grade moving from D to A across runs is itself the evidence.

Can I share results with a customer?

Yes. Every run has a shareable report link showing the grade and the findings summary without exposing the detail behind each finding — the artefact a security questionnaire usually asks for.

Is Pentest included in the Resilience Suite?

Yes. The Resilience Suite bundles Pentest, Load Testing and DDoS Resilience in one $619 purchase: 17% off buying them separately, saving $128. One purchase unlocks every part of it for your whole organization.