Prove your defenses hold, with a report your reviewers accept. Penetration Testing
Adversarial testing of your AI surface, MCP servers, applications, and infrastructure. Findings, reproduction steps, and a retest report your procurement team or security review requires.
FEDLIN scopes the engagement, structures deliverables against your target framework, and ensures the documentation produced feeds directly into your compliance or authorization package.
What's driving the test?
Where this fits
Adversarial proof the controls hold.
Once the AI you run is secured or a node is built, a penetration test is how you prove it holds under attack. Findings feed your Risk Register and the CA-8 evidence a review asks for. We test the agentic surface against the OWASP Agentic Top 10, alongside your applications, infrastructure, and cloud.
AI Surface & MCP Testing
For teams running self-hosted AI, MCP servers, and agentic pipelines
Your AI's external surface (the tool-call chains, MCP server authorization boundaries, context scoping, and prompt injection vectors) is a test surface that web and infrastructure testing doesn't reach. We run the adversarial test against what your AI can access and what can access it, covering the OWASP Agentic Top 10 attack classes.
Dozens of MCP CVEs have been disclosed since the protocol reached production adoption. NSA and CISA have published advisories on AI-driven automation security. The attack surface is real, and most pentest firms are not yet running structured tests against it.
Best for
- → MCP servers running on self-hosted or cloud infrastructure
- → Agentic pipelines that call external tools or access internal data
- → Self-hosted AI environments being assessed for NIST AI RMF readiness
- → Regulated environments where AI is part of the attack surface a reviewer will probe
What you get
- →MCP server authorization boundary findings with reproduction steps
- →Prompt injection coverage across tool-call chains
- →Context boundary and data-leakage path findings
- →OWASP Agentic Top 10 coverage
- →Findings mapped to NIST AI RMF govern and measure controls
- →One retest and a verification report
Web & API Testing
For teams shipping web apps and APIs
We test the application the way an attacker would: authentication and session handling, access control, injection, business logic, and the API behind it. Coverage follows the OWASP Web Security Testing Guide and API Top 10, tested by hand, going beyond an automated scan.
Best for
- → A SaaS or web product facing a customer security review
- → An API that moves sensitive data or money
- → A release you want tested before it ships
What you get
- →Findings with CVSS scores and CWE references
- →Reproduction steps your engineers can follow
- →One retest after you remediate
- →A technical report and an executive summary for the security review
- →NIST 800-53 CA-8 evidence mapping
Network & Cloud Testing
For teams defending infrastructure
We test from where the attacker starts: the internet-facing perimeter, an assumed breach already inside the network, or your cloud accounts. Service exposure, misconfigurations, wireless, privilege escalation, lateral movement, and cloud IAM paths, exploited and documented.
Best for
- → An on-prem or hybrid network with a real perimeter
- → AWS, Azure, or GCP accounts you have not had tested
- → A mandate that requires infrastructure testing
What you get
- →Exploited findings with reproduction steps
- →Lateral-movement and privilege-escalation paths
- →Cloud IAM and exposure findings
- →Remediation guidance and one retest
- →NIST 800-53 CA-8 evidence mapping
When a pentest is required
Customer & vendor reviews
Enterprise security questionnaires ask when your last penetration test was. A formal report from a qualified tester gives procurement teams the independent validation they require to proceed.
Compliance mandates
NIST 800-53 CA-8 requires penetration testing as an assessment control. SOC 2 CC7.1 pulls it in for vulnerability management. The CA-8 evidence artifact from the retest is what authorization packages need.
AI surface & NIST AI RMF
NSA and CISA have published advisories on AI-driven automation security. NIST AI RMF measure controls call for adversarial testing of AI systems. Dozens of MCP CVEs since production adoption mean the attack surface is active and growing.
Coverage
What we test
AI Surface & MCP
MCP server authorization, prompt injection, agentic tool-call chains, context boundaries, supply chain via MCP plugin
Authentication
Login flaws, session management, password policies, MFA bypass
Authorization
IDOR, privilege escalation, broken access control, tenant isolation
Injection
SQL injection, XSS, command injection, template injection
API Security
Authentication, rate limiting, data exposure, mass assignment
Infrastructure
Network exposure, misconfigurations, lateral movement paths, cloud IAM
Configuration
Security headers, TLS, error handling, information disclosure
Business Logic
Workflow bypass, price manipulation, feature abuse
Process
What to expect
Every engagement follows the same five-phase structure regardless of scope. The output at each phase is a documented artifact, delivered at each phase.
Scoping & Authorization
Define target environment, rules of engagement, test window, and deliverable format. Before testing begins: NDA executed, SOW signed, and a written authorization letter from your authorized representative. Third-party provider authorization (AWS, Azure, GCP) obtained where applicable.
Active Testing
Manual exploitation attempts against agreed scope. Findings documented in real time with reproduction steps, CVSS scores, and CWE classifications.
Draft Report
Technical report for your engineering team plus an executive summary for procurement reviewers and authorizing officials. Delivered within 5–7 business days of test completion. You have a review period to dispute findings or provide context before the report is finalized.
Remediation Window
Your team addresses findings. We remain available to clarify specific findings during the remediation period.
Retest & Verification
We retest remediated findings and issue a formal verification report. This is the CA-8 evidence artifact your authorization package requires.
What You Receive
Deliverables
- Technical findings report, ordered critical to informational
- Executive summary for leadership and procurement
- Per-finding CVSS score, business impact, reproduction steps, and remediation
- Risk assessment matrix
- Strengths and weaknesses summary
- A review period before the report is final
- Compliance control mapping (SOC 2, NIST 800-53)
- One retest, delivered as a Remediation Validation and Re-test Report
- Every retested finding marked remediated, residual, or not verified
- NIST 800-53 CA-8 evidence artifact
Remediation Validation & Re-test Report
After you remediate, we re-test and issue a formal validation report. Every finding is marked remediated, residual, or not verified, so you see exactly what was closed and what still needs work, finding by finding. This is the documentation procurement teams and authorizing officials need, and it maps directly to NIST 800-53 CA-8 evidence requirements.
Evidence & Data Handling
Any sensitive data encountered during testing (credentials, PII, PHI) is not retained beyond what's needed to document the finding. Screenshots and proof-of-concept artifacts are stored encrypted, shared via secure link, and deleted after final report acceptance. Reports are delivered as encrypted PDFs.
Common questions
How long does a penetration test take?
A typical web application penetration test takes 2–3 weeks from kickoff to final report delivery. This includes scoping, testing, report writing, and a retest after remediation. Infrastructure and AI-surface engagements are scoped individually.
What's included in the penetration test report?
You'll receive a detailed technical report with CWE classifications and CVSS scores, an executive summary for leadership and procurement, and a remediation verification report after retest. These documents satisfy enterprise security questionnaires and agency procurement requirements.
What testing methodology do you follow?
Web application testing follows OWASP Web Security Testing Guide (WSTG) and OWASP API Security Top 10. Infrastructure testing is structured against NIST 800-53 CA-8 requirements. Primary tooling includes Burp Suite, Caido, and Metasploit for exploitation and privilege escalation. AI-surface testing covers LLM integrations, MCP server scope, and agentic pipeline boundaries.
How much does a penetration test cost?
Every test is scoped to your application and target framework, then quoted as a fixed price. Schedule a scoping conversation to walk through scope and get your quote.
Do you test AI systems, MCP servers, and agentic pipelines?
Yes. FEDLIN's AI-surface testing covers LLM integrations, Model Context Protocol server authorization boundaries, agentic pipeline tool-call chains, and prompt injection vectors. Findings are mapped to NIST AI RMF govern and measure controls. This is a distinct test surface from web application or infrastructure testing, and it's scoped separately.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan identifies known CVEs and misconfigurations automatically. A penetration test goes further: a tester attempts to exploit findings, chain vulnerabilities, escalate privileges, and reach sensitive data, then documents the full attack path. The test produces a report that auditors and reviewers accept as independent validation; a scan report alone typically does not.
Can you fix what you find? What happens after the test?
Remediation is a separate engagement, not bundled into the penetration test. FEDLIN's vulnerability remediation practice can run as a follow-on sprint that drives findings to closure with the same evidence standard. Scoping the two engagements together often makes sense when there is an upcoming audit window or a client security review with a deadline.
What compliance frameworks does the report satisfy?
The report and its artifacts are structured to satisfy NIST 800-53 CA-8 (penetration testing control), SOC 2 CC7.1 (vulnerability management), and common enterprise vendor security questionnaire requirements. The executive summary is written for procurement teams and non-technical reviewers. Additional framework mapping is available on request.
Who performs the testing?
Testing is performed by a senior principal in partnership with FeemCoTech, a specialized penetration testing firm. FEDLIN scopes and coordinates the engagement, provides the client interface, and delivers the final report. Subcontracted capacity allows FEDLIN to run tests at a level of specialization that would be impractical for a single-practitioner firm.
Do you retest after remediation?
Yes. A verification retest is included in the engagement scope. After you remediate findings, FEDLIN re-tests the specific vulnerabilities to confirm closure and produces a remediation verification report. This document is what most auditors and customer security reviews require to close out a finding.
Often scoped together
Related engineering, delivered on its own or folded in
Vulnerability Remediation
The pentest findings become the intake document. A remediation sprint closes the prioritized queue with evidence attached.
GRC Engineering
Translate findings into a structured remediation program: NIST 800-53 control mapping, IAM hardening, and audit-ready evidence.
Edge Security
Close the web, email, and API attack surface identified in the pen test: WAF, headers, and domain authentication.
How we scope a pentest
The size of the job tracks what you point us at. One web app is a small test; a whole network, your cloud, and a red-team exercise on top is a large one. How deep you want us to go, and whether a compliance requirement is driving it, move it from there. Test a few things together and it costs less than testing each alone. Tell us what you want covered on a call and we size it with you.
Ready to scope a test?
Start with a scoping call. We map the actual attack surface and define the engagement around what your architecture requires.
From the Blog
Related reading

Do You Need a Penetration Test?
Could a contractor-level account in your environment be the starting point for something worse? It's the question we commissioned a penetration test to ask — and the right question for your environment too.

Anthropic's Mythos is Coming. Is your business ready?
Mythos autonomously discovers and chains zero-day vulnerabilities. The barrier to sophisticated exploitation has collapsed — and the pool of actors who can target your organization has expanded to match.
Not sure where to start? Tell us where you are.
Evaluating your security posture before a funding round, compliance deadline, or enterprise deal?