Our Methodology
TurboPentest follows the same testing methodology proven over 30 years of human-led penetration testing - now delivered by AI agents at self-serve speed. Two pillars:
Testing methodology
How we test. The standards, phases, and technique mappings every TurboPentest pentest follows - the same playbook IntegSec consultants use on human-led engagements.
- •PTES - 7-phase pentest workflow
- •OWASP Testing Guides - WSTG, MASTG, API Top 10, LLM Top 10
- •MITRE ATT&CK - adversary technique IDs
- •OWASP Top 10 - auditor cross-reference
Plus NIST SP 800-115, MITRE ATLAS, OWASP ASVS / MASVS, AI Testing Guide - see full list →
Read the testing methodologyCompliance mapping methodology
How findings map to compliance framework controls - SOC 2 TSC, ISO 27001 Annex A, PCI DSS v4.0 Req 11.4.x, HIPAA Security Rule. Versioned mapping, public, used in every evidence package.
Read the compliance mappingAbout this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.