Requesting a pentest
Step-by-step of the test creation wizard.
A pentest in HAS is requested through a 4-step wizard inside your company. This guide covers what you fill in at each step and how pricing works.
Step 1 — Scope
In the first step you define what will be tested and when:
- Test level: AI-Native or AI-First. The table in Test level explains the difference.
- Assets: URLs, IPs or specific domains to test. You don't need to say what each one is: the platform identifies it as you type and shows a tag next to the asset. See Filling assets for accepted formats.
- Start date: when our pentesters should begin. We schedule up to 3 months ahead.
Step 2 — Authentication
Here you decide whether to provide any access:
- No credentials: 100% Black Box test. Our pentesters simulate an external attacker with no prior access.
- Provide credentials: Gray Box test. In this case, we ask whether the asset is internet-accessible or on a private network.
Asset on a private network
If the asset isn't on the internet, you need to grant access to our IPs. HAS shows 4 ways (load balancer/CDN, firewall allowlist, bastion host, or Cloudflare Tunnel). See Granting access for internal networks for details.
Step 3 — Details
Fill in:
- Test name: a short identifier to locate the test later.
- Goal and instructions: describe what should be validated, relevant context and limitations. Minimum 40 characters.
- Attachments (optional): up to 4 files of 200 MB each. Accepts VPN configs (
.ovpn), technical docs (.pdf,.docx), mobile APKs/IPAs, certificates, etc.
Step 4 — Confirmation
Final review with a summary of what was entered, grouped by asset type.
Test level
Chosen in step 1, together with the assets:
| Level | Scope |
|---|---|
| AI-Native | Yaga (AI) tests. Humans follow along and validate. |
| AI-First | Yaga (AI) tests. Humans validate and go deeper. |
How it's billed
Depends on your company's plan:
- Pay-per-test: one-time payment per test via card, PIX or boleto. Price based on assets and chosen level.
- Monthly or Annual (allocation): the test consumes assets from your monthly quota. If you exceed it, you can buy an additional Pay-per-test.
After submitting
Once confirmed, the test shows up under Tests with status Requested. Our team validates within 48h and starts on the scheduled date. You follow everything in real time.