Final pentest report
- One document for management and the technical team: plain-language risk summary, technical report with evidence and guide to what to fix first.
GDPR is about managing personal data responsibly and proving you can protect it. It is not about compliance theater or documentation alone. We run the penetration testing that shows your data protection controls actually work: real weaknesses found and fixed, in evidence your regulators accept.
30 minutes to scope it.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We will write back within one business day to scope it.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















A vulnerability scan lists technical issues. A pentest proves what an attacker could actually do with personal data, and whether your data protection controls hold when tested.
GDPR sets no fixed interval, it says 'regularly'. In practice that means testing at least once a year, and again whenever you change something that touches personal data: a new app, a cloud migration, a big change to how you handle accounts or identity.
A DPIA describes the security measures you have planned. A pentest checks whether they hold, and leaves the technical proof that goes with that assessment.
When a supervisory authority flags a gap, what answers it is evidence: what was tested, what was found, what was fixed, and what the retest confirmed.
Moving personal data to another system, to the cloud or into a newly integrated platform opens new paths. We test the ones that lead to that data before someone else finds them.
After an incident, patching is not the end: you have to show the path is closed. We run the attack again against the fix and leave the closure on record.
GDPR sets no interval, it says regularly. A review once a year keeps the proof alive that your security measures are still working.
We deliver a full security cycle, not a document: real weaknesses found, their impact shown, a prioritised fix list and closure with a retest.
From day one, findings live in our platform, not just in a document: managed, assigned and closed with full traceability, and exportable as evidence for your GDPR compliance file.
We at Etnia highly value our collaboration with Asperis Security.
If something here doesn’t match your situation, that’s the call: bring the edge case and we’ll scope around it.
No, and anyone who tells you it does is overselling. GDPR compliance is broad: lawful basis, records, consent, data-subject rights, privacy notices and more, most of which is legal and organisational work. A pentest covers the security side, the evidence that the personal data you hold is actually protected. It is an important piece of compliance, not the whole of it.
The ones that touch personal data, not your whole estate. That means web apps and their APIs, mobile apps, the cloud, the internal network, and the places the data actually ends up: databases, backups and file stores.
We scope from your record of processing activities (Article 30), which already sets out what you process, why, and who receives it. What the record does not say is which systems it lives in, so we walk that part with you in the introductory meeting, one system at a time, instead of testing everything or guessing.
Our recommendation is after you have written it and before the processing goes live. A DPIA sets out the security measures planned for high-risk processing (Article 35(7)(d)); the pentest checks whether those measures hold up and produces the technical proof that sits alongside that assessment.
There is no date to give here, and we will not invent one. What GDPR does say is that the assessment gets reviewed when the risk changes (Article 35(11)), and that is your cue to test again: a change in the processing, not a date in the diary.
No. A pentest finding is a vulnerability, not a breach. The 72 hours start with a breach of security that destroys, loses or alters personal data, or leads to unauthorised disclosure of or access to it, and it is reported unless it is unlikely to put the people affected at risk (Articles 4(12) and 33). Finding the route in before an attacker does is the opposite.
There is one exception, and we flag it as soon as we see it: if the test turns up traces that somebody has already been inside, that may be a breach. Reporting is your call with your counsel; we supply the technical evidence.
You, and whoever you choose. We do not publish it, pass it on or use your name as a reference without your permission. Even the sample report never goes out by email; we walk you through it on a call.
The people who ask for it are usually not certification auditors: your Data Protection Officer, a customer exercising its audit right over you as a processor (Article 28(3)(h)), or the supervisory authority. All three get the same thing: the report, the retest with the closure documented, and the platform export with every finding and its audit trail.
As long as the risk allows, because GDPR names no deadline. Article 32 asks for measures that match the risk and for regular testing of how well they work, so what stands up to an auditor is not speed: it is having prioritised well and being able to show it (Article 5(2)).
The report ranks the fixes by real impact, and the retest is included, at no cost and with no time limit. When you close something, we verify it and document that it is closed. There is no window for you to miss.
No. We do not act as your Data Protection Officer, run your privacy programme or give legal advice, and there is no GDPR certificate for us to issue: GDPR is a law, not a certification scheme. We perform the penetration testing that evidences the security of the personal data you process. Many clients pair us with their DPO or legal counsel, and the roles fit together cleanly.
Yes. We walk you through it on the call, so you can see the level of detail, the clarity of the reporting and the evidence format, and ask about whatever matters to you. We do not email it out on its own.
GDPR compliance is a data protection partnership. You manage the systems, we test the security, we deliver the proof. Clear findings, immediate remediation paths, rapid revalidation.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
Got it. We reply within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.