Fix your findings on your schedule. We re-test every patched vulnerability within 48 hours and reissue your updated Clean Report and Attestation Letter at zero additional charge.
Most security consultancies deliver a report with critical vulnerabilities, then disappear. When you patch the flaws and need a clean report for a major customer deal or SOC 2 audit, they quote thousands of dollars and make you wait three weeks for tester availability.
When you notify us that fixes are deployed to staging, our certified pentesters re-execute proof-of-concept exploits within 48 hours, so your customer deals don't stall.
Retesting is fundamentally part of a penetration test. We include retesting standard across all 7 testing services with no surprise line items or hourly invoices.
Upon verifying that findings are remediated, we immediately reissue your updated Executive PDF report and official Letter of Attestation confirming clean posture.
| Feature | Lorikeet Security Canada | Traditional Pentest Firms |
|---|---|---|
| Retest Cost | $0 CAD (Included Standard) | $2,500 - $6,000+ CAD Extra |
| Retest SLA | Within 48 Hours | 2 - 4 Weeks (Subject to Booking) |
| Retest Window | 90 Days from Initial Report | Strict 14 - 30 Days |
| Attestation Letter | Updated & Reissued Instantly | Often requires separate sign-off fee |
| Assigned Tester | Same Senior Lead Pentester | Random junior resource assigned |
Your engineering team applies the code, cloud configuration, or network fixes to your testing or staging environment following the remediation notes in our initial report.
Send a quick notification to your dedicated Canadian engagement lead citing the finding IDs and environment target URL. We acknowledge receipt within 2 business hours.
Within 48 hours, our lead tester re-runs exploitation scripts and delivers your retest validation certificate, updated PDF report, and signed Attestation Letter.
All of them. Whether you book Web App, API, Mobile, Cloud, Cloud Config Review, Internal, or External Network Penetration Testing, retesting is included automatically at zero additional charge.
If our tester verifies that a vulnerability is still exploitable or only partially resolved, we provide direct feedback and curl/HTTP request traces showing why it failed, allowing your developers to finish the fix before issuing the final letter.
You have a generous 90-day window from the date your initial final report is delivered. This allows your team plenty of time to schedule fixes into regular development sprints.
Certified OSCP/CEH testers, flat CAD rates, and an ironclad 48-hour retesting SLA.