Our Methodology
TurboPentest follows the same testing methodology proven over 30 years of human-led penetration testing - now delivered by AI agents at self-serve speed. Two pillars:
Pillar 1 - Primary
Testing methodology
How we test. The standards, phases, and technique mappings every TurboPentest pentest follows - the same playbook IntegSec consultants use on human-led engagements.
- •PTES - 7-phase pentest workflow
- •OWASP Testing Guides - WSTG, MASTG, API Top 10, LLM Top 10
- •MITRE ATT&CK - adversary technique IDs
- •OWASP Top 10 - auditor cross-reference
Plus NIST SP 800-115, MITRE ATLAS, OWASP ASVS / MASVS, AI Testing Guide - see full list →
Read the testing methodologyPillar 2 - Companion
Compliance mapping methodology
How findings map to compliance framework controls - SOC 2 TSC, ISO 27001 Annex A, PCI DSS v4.0 Req 11.4.x, HIPAA Security Rule. Versioned mapping, public, used in every evidence package.
Read the compliance mappingThe same methodology used in IntegSec's human-led red team engagements - automated by Paladin, TurboPentest's AI agent. Same playbook, two delivery modes: human consultant or self-serve AI.