"Nobody would bother attacking my site" is the wrong starting assumption
Most sites that get breached are not high-value targets picked out by a patient attacker. They're mid-traffic sites running a known CMS version, an exposed admin panel, or a login form that never got tested for authentication bypass. Automated scanners and bots probe the entire public internet continuously — not because your site is interesting, but because checking is free for the attacker and finding one weak site among millions is enough.
A penetration test is different from the automated scanning that's already happening to you. Instead of a bot running a signature list, a pentest actively tries to exploit what it finds, confirms whether a weakness is real and reachable, and tells you exactly what an attacker could do with it — not just "this endpoint might be vulnerable."
The reason most small and mid-size teams skip this step isn't that they don't care. It's cost and friction: a consultancy-run pentest typically starts around $5,000 and takes weeks to schedule. That's why we're running this pilot — to remove both barriers for a limited number of new accounts and let you see what a real, evidence-backed report looks like before you decide whether to make it a habit.
What "free" actually includes
The pilot gives new AssurePort accounts one run of the Web Pentest engine — the same engine sold at $69 under the Starter plan — at no cost. That includes:
- OWASP Top 10 coverage: injection, broken access control, security misconfiguration, and the rest of the standard risk categories
- Real exploitation attempts against your live target, not a passive signature match
- A reproducible proof-of-concept attached to every confirmed finding, so your developers can verify and fix it without guessing
- A downloadable PDF report with severity scoring and remediation guidance, kept in your console permanently
Nothing about the report format or engine depth changes for the free run. What's limited is capacity: this is offered to new signups while pilot spots remain, and covers one scan per new account, not ongoing free scanning.
How the process actually works
We want to be direct about the shape of this offer, because "free instant pentest" is a phrase that invites skepticism — and it should. Here is exactly what happens, in order:
- You create an AssurePort account. No card required to claim the pilot entitlement.
- You submit your target domain and any scope notes. This is also where you confirm you own the domain or are legally authorised to test it — the same authorisation requirement that applies to every scan on the platform, free or paid.
- Our security team reviews the request. We check the target is eligible and the authorisation is in order before anything runs.
- The scan runs, and findings are reviewed again before delivery. This is the step that makes the report trustworthy: nothing ships to your console unverified.
- Your report appears in your console, typically within 2–3 business days of submission.
Why the delay is the point, not a flaw: An instant, fully automated "free scan" with no human review is easy to build and easy to distrust — false positives, unverified findings, no accountability. The review steps take a few days precisely because they're what makes the result something you can act on, not just a list of maybes.
What happens after the free scan
Your report and the underlying findings stay in your AssurePort console for good — there's no expiry and no obligation to buy anything afterward. If the report surfaces issues worth tracking over time, or you simply want testing on a regular cadence instead of a single point-in-time snapshot, you can move to a paid plan (Starter, Pro, or Business) whenever you're ready. If not, you keep the report either way.
For teams evaluating whether continuous testing makes sense beyond a single free run, our post on annual pentests vs continuous AI testing covers the tradeoffs in more depth.
Frequently Asked Questions
Is AssurePort's free web penetration test really a full pentest?
Yes. New accounts that join during the pilot get the same Web Pentest engine sold at $69 (Starter) — OWASP Top 10 coverage, real exploitation attempts, and a reproducible proof-of-concept for every confirmed finding. Nothing is stripped down for the free run.
How long does the free scan take to deliver?
Findings are reviewed by AssurePort's security team before the report is released, which typically takes 2 to 3 business days from the time you submit your target domain and scope notes.
Do I need a credit card to claim the free scan?
No. Signing up and claiming the pilot's free scan does not require a card. You will need to confirm you own or are legally authorised to test the domain, the same authorisation rule that applies to every scan on the platform.