EXTERNAL10Get tested

01 / External attack simulation

A real penetration test. Fixed price. No sales calls.

Sign up with your work email. Starting from that domain, we map everything your organisation exposes to the internet and attack it the way a real adversary would, then come back with a written report and a debrief meeting.

Price
1 000 EUR, excl. VAT
You get
Written report + 60-min debrief
Turnaround
Report within 10 business days
A lone figure at the base of a monumental concrete wall, lit by a narrow slit of light

Stronger
systems start
outside.

02 / Why now

The attackers are getting help too.

AI is handing real offensive capability to people who never had it, and sharpening the ones who did. Reconnaissance, exploit-writing and scanning that used to take a skilled team days now runs in minutes, at scale, against everyone at once.

Criminal crews and state actors are the early adopters. The gap between a weakness being exposed and being exploited is closing fast, and when it closes on you it is not a slow leak. It is your operations, your data and your name, all at once.

Far better to find what's weak yourself, on your terms, than to learn it from someone who wants you gone.

Attack. Understand. Strengthen.
03 / How it works

One engagement. Your internet-facing estate, attacked the way a real adversary would.

No internal access, no credentials from you, no hints. We start from the same position an attacker on the internet starts from: your domain name.

  1. 01

    Reconnaissance

    We map what your organisation exposes to the internet, starting from your domain: related domains, hosts, services, mail, web apps, forgotten subdomains.

  2. 02

    Exploitation

    We attempt real attacks against what we find, the way an outside adversary would, and record how far each one gets. 5 business days of active testing.

  3. 03

    Report

    A written penetration test report within 10 business days: what we found, how we got in, how severe it is, and what to fix first.

  4. 04

    Debrief meeting

    A 60-minute video call within 5 business days of the report, with the tester who did the work. We walk your team through the findings and answer questions.

04 / What you get
EXTERNAL10

Penetration
test report

External attack simulation.
Hardened systems.

  • Executive summary for management
  • Every finding with severity (CVSS), evidence and reproduction steps
  • Prioritised remediation list
  • Attack narrative: how far we got and how
ConfidentialWithin 10 business days
02

Debrief
meeting

Report in hand.
Questions answered.

  • Findings walkthrough, ranked by risk
  • What to fix first, and how
  • Open questions from your team

Held within 5 business days of the report, with the tester who did the work.

video call60 minutes
05 / Pricing

One engagement, one price

1 000EUR

per external attack simulation · excl. VAT

Own or advise several companies? Portfolio pricing on request.

Prices exclude VAT. Spanish IVA (21%) is added for customers in Spain. EU businesses with a valid VAT number are invoiced under reverse charge. Customers outside the EU pay no VAT.

Nothing to pay up front. We invoice 1 000 EUR once the report is delivered and the debrief meeting is done. Bank transfer or card, 14 days.

Included

  • External reconnaissance of your domain
  • Exploitation attempts against exposed services
  • Written penetration test report
  • 60-minute debrief video call with your team

Scope and terms

  • 5 business days of testing, report within 10
  • Invoiced after the report and debrief. Nothing up front

Out of scope

  • Denial-of-service or anything that degrades availability
  • Phishing or social engineering of your staff
  • Physical access and on-site testing
  • Internal testing, and testing with credentials you give us. We never receive passwords from you
  • Third-party SaaS you do not operate yourself
06 / Authorization

We only test what you own.

A penetration test without authorization is an attack. Our sign-up is built so that the person requesting the test is demonstrably part of the organisation being tested.

  1. 01

    Your work email sets the target

    You sign up with a corporate address. That domain is our starting point: we discover the related domains and internet-facing assets your organisation owns, and the engagement letter lists exactly what we test.

  2. 02

    No free or shared mail providers

    Gmail, Outlook, iCloud, Proton and similar addresses are rejected at sign-up. A corporate domain ties the request to the organisation we test.

  3. 03

    Authorization comes later, in writing

    We review the lead, map what your organisation exposes to the internet, and send an engagement letter that lists exactly what we will test. The engagement letter carries an authorization link. Clicking it, as an authorized signatory, is what authorizes the test — nothing is tested before then.

Authorization terms

The same terms every customer confirms before we start, set out in the engagement letter and authorized by the link in it.

  1. 01The customer authorizes SCORE10 SL (EXTERNAL10) to perform security testing of the domains, subdomains and internet-facing systems the customer owns or is entitled to approve — identified from the customer's domain and listed in the engagement letter — for 30 days from confirmation.
  2. 02Testing may include vulnerability scanning, controlled attempts to exploit weaknesses, and limited attempts with default or commonly used passwords against publicly known accounts. It will not intentionally damage data, lock out users or disrupt operations.
  3. 03Testing of third-party systems requires separate permission.
  4. 04All results are treated as confidential and reported to the customer, who may request that testing stops at any time.
07 / Who runs this
Jens Berlips

Founded by Jens Berlips.

EXTERNAL10 was founded by Jens Berlips, a serial entrepreneur and hands-on engineer. He co-founded and chairs ApoEx, and advises the SecureDNA Foundation on safeguarding DNA synthesis against misuse.

His return to building with AI is the same shift now arming attackers, and the reason EXTERNAL10 exists.

08 / Get tested

Sign up to be tested.

Your work email and company are all we need to start. Its domain is our starting point. One engagement, 1 000 EUR excl. VAT, report and debrief meeting included.

Free and shared mail providers are not accepted.

No commitment and no payment now. We store your details to get in touch about a test. See our privacy policy.