Security Attestation Letter
A signed attestation letter with every pentest
When an auditor or an enterprise customer asks whether your app was independently security tested, you need proof on paper. Every TurboPentest pentest ships a signed third-party attestation letter - not a blockchain gimmick, a plain signed letter - you can hand straight to SOC 2 auditors and vendor-security reviews.
See a sample report →What is a security attestation letter?
A security attestation letter is a short, signed document from the firm that tested your application, confirming that an independent penetration test actually took place. It records the scope, the testing dates, and a summary of methodology, and it is signed by the party that did the work. It is the artifact you reach for when someone outside your company asks "can you prove you were pentested?" - without handing over a report full of live vulnerabilities.
That is the key difference from the full report. The report is the detailed, confidential record of what was found and how to fix it - for your engineers. The attestation letter is the shareable, external-facing proof that testing happened - for your auditors and your customers. TurboPentest delivers both from the same run, and the letter is backed by IntegSec, the offensive-security firm behind the platform, which is what gives the attestation its weight.
Signed
a plain third-party attestation letter, issued and signed by IntegSec
IntegSec
Hours
fully autonomous pentest returns results, and the letter, in a few hours
Autonomous engine
$99
per target, flat - the attestation letter is included, not an add-on
TurboPentest pricing
What a penetration testing attestation letter contains
Enough for an auditor or a procurement team to trust it, and deliberately nothing that would expose your live vulnerabilities.
Scope of the engagement
The target that was tested - the domain, application, or API - so a reader knows exactly what the attestation covers and, just as importantly, what it does not.
Testing dates
When the pentest ran. Auditors and procurement teams want recent evidence, so the date range on the letter is what tells them the testing is current.
Methodology summary
A plain description of how the test was performed - the black-box and white-box coverage across network, web app, API, and source code - without disclosing sensitive findings.
Statement that testing was performed
A signed declaration that an independent security test took place, issued by IntegSec, the offensive-security firm behind TurboPentest and its credential-holding operators.
The letter arrives alongside the rest of your deliverables: the full PDF report, the attack surface map, the STRIDE threat model, and the retest commands to confirm every fix landed.
Who accepts an attestation letter
The two most common audiences are SOC 2 auditors, who ask for evidence that a penetration test was performed during their examination period, and enterprise procurement and vendor-security reviews, where a prospective customer wants proof your product has been independently tested before they sign. A signed third-party attestation letter is the standard artifact both groups expect.
One honest caveat, stated plainly: the attestation covers the autonomous agentic pentest performed by TurboPentest and is backed by IntegSec. It is an attestation of testing performed, not a compliance certification - SOC 2 and ISO 27001 are separate audits, run by different assessors, that you would still complete. The letter is typically one input to those audits, not a substitute for them.
How to get your attestation letter
Buy a pentest and prove you own the target
$99 per target, self-serve. Sign in with email, confirm ownership of the domain, and accept safe harbor - no sales call, no scoping meeting.
The agents run the pentest end to end
Fully autonomous coverage across network, web app, API, subdomain discovery, SSL/TLS, and external attack surface - with white-box source analysis when you connect a repo.
Paladin AI validates the findings
Each candidate finding is confirmed and classified before anything goes in the report, so what the attestation stands behind is real testing.
Download your signed letter and report
In a few hours you get the signed attestation letter alongside the PDF report, attack surface map, STRIDE threat model, and retest commands.
The letter is one piece of the deliverable
See exactly what lands in your inbox, how the attestation supports your compliance work, and what a full engagement includes.
Attestation letter FAQ
What is a security attestation letter?+
A security attestation letter is a short, signed document from the party that tested your application, confirming that an independent penetration test was performed. It states the scope, the dates, and a summary of methodology. You hand it to auditors, enterprise customers, or procurement teams as proof that your app was security tested - without having to share the full findings report.
What is in a penetration testing attestation letter?+
It contains the scope of the engagement (what target was tested), the testing dates, a summary of the methodology used, and a signed statement that the testing was performed. It deliberately does not include the detailed vulnerabilities - that lives in the full PDF report - so the letter is safe to share externally.
Will a SOC 2 auditor accept it?+
SOC 2 auditors and enterprise vendor-security reviewers commonly ask for evidence that a penetration test happened, and a signed third-party attestation letter is the standard artifact for that. TurboPentest's letter is backed by IntegSec, a real offensive-security firm, which is what gives it weight. It attests that testing was performed - it is not itself a SOC 2 or ISO certification, which are separate audits you would still complete.
Is an attestation letter the same as a SOC 2 report?+
No. An attestation letter is proof that a penetration test was performed, signed by the firm that ran it. A SOC 2 report is a separate compliance audit performed by a licensed CPA firm against the Trust Services Criteria. The attestation letter is often one of the pieces of evidence a SOC 2 auditor asks to see, but it does not replace the SOC 2 audit itself.
How much does it cost and how fast do I get it?+
$99 per target, flat. The pentest runs fully autonomously and returns results in a few hours, with the signed attestation letter delivered alongside the PDF report, attack surface map, STRIDE threat model, and retest commands.
Get a signed attestation letter. $99.
One flat price per target, results in hours, with the signed letter and full report included. See pricing
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.