Security for the public sector and business

Secure your websites and systems before an attacker does

Pentua provides penetration testing of websites and systems for municipalities and smaller businesses. We offer continuous protection as a subscription — regular retests at a fraction of the first test's cost.

First small-scope test free • Just your name and email • Reply within 2 business days

We test against recognised standards

OWASP Top 10OWASP ASVSPTESNÚKIB guidanceGDPR

Why now

Attacks are now faster, cheaper and automated

Artificial intelligence has dramatically lowered the bar for attackers. Vulnerability scanning, phishing and exploitation run at scale and around the clock — regardless of an organisation's size.

Automated attacks

Bots continuously scan the internet for vulnerable sites and systems. A small municipality or business is just as visible as a corporation.

AI-generated phishing

Convincing fraudulent emails and impersonations are created in minutes. The human factor remains the most common entry point.

Faster exploitation

It often takes only hours from a vulnerability's disclosure to its mass exploitation. A one-off audit every few years is no longer enough.

Responsible security in the age of AI

We use AI as a tool — not a replacement for expertise

AI is changing both sides of the fence. We use it for faster analysis and broader coverage, but every finding is verified and interpreted by an experienced human tester. No auto-generated reports without review.

We also take responsibility for the data we handle. We test strictly on the basis of written authorisation, within an agreed scope, and with the utmost care not to endanger your systems or disrupt their operation.

Our approach

A human verifies every finding

AI speeds up data gathering, but severity classification and recommendations are done by a tester. We eliminate false alarms.

Safe data handling

We keep sensitive data only as long as necessary, encrypted, in line with GDPR. After the test we securely dispose of it.

Ethics and authorisation first

We only test what is contractually approved. No destructive techniques without explicit consent.

Understandable output

We write reports so that even a non-technical founder or official can follow them — with clear priorities and remediation steps.

What we test

A complete view of your security

We focus on real, exploitable vulnerabilities — not a theoretical checklist. We tailor the scope to the size and needs of your organisation.

Web applications and portals

Notice boards, forms, e-shops, booking and client portals. Injection, authentication, permissions, data leaks.

External infrastructure

Everything you expose to the internet — servers, VPN, mail and DNS services, misconfigurations and open ports.

Internal network and systems

Simulating an attacker inside the network: shared drives, Active Directory, permissions, lateral movement.

Phishing and the human factor

Controlled phishing campaigns and staff awareness. People remain the most common cause of incidents.

Retests and monitoring

Verifying that reported issues were actually fixed, and tracking newly emerging vulnerabilities over time.

Consulting and awareness

Clear recommendations, remediation prioritisation and training for your people — without needless jargon.

How we work together

Security is not a one-off event, but a process

A classic audit every few years only gives you a snapshot. Your environment, code and threats change every week. That's why Pentua works as a subscription.

Cheaper retests

The first in-depth test is the most demanding. Every further retest within the subscription is significantly cheaper — it pays to stay with us.

Ongoing protection

We regularly check whether new vulnerabilities have appeared and whether previous fixes still hold.

Predictable costs

Instead of occasional large expenses, your security is spread into a stable monthly or annual payment.

Priority support

Subscription clients get priority when a critical vulnerability is found, plus faster response times.

24 h
Response to critical findings
100 %
Ethical, authorised approach
€0
Entry test for new clients
Retests within a subscription

How it works

From a form to safer systems in 4 steps

1

You fill in the form

Just your company ID, name and basic details. We verify you're authorised to order testing and agree on the scope.

2

Free entry test

We run a free basic scan of your website or system so you can immediately see where you stand.

3

Report and recommendations

You get a clear overview of findings with priorities and specific remediation steps.

4

Subscription and retests

You choose a level of protection. We test regularly, verify fixes and watch for new threats.

Protection levels

Choose based on size and needs

Your first small-scope test is free. More detailed testing depends on the chosen scope and is always tailored — which is why we don't publish a price list. An orientation across levels:

Free entry test

Small scope, no commitment, no payment

  • Basic scan of one website or service
  • Overview of the most serious findings
  • Brief report and recommendations
  • The ideal first step — see how we work
Get a no-obligation offer

Standard

Regular protection for smaller firms and municipalities

  • In-depth penetration test of web and infrastructure
  • Regular retests at a discounted price
  • Fix verification and tracking of new vulnerabilities
  • Clear reports and email support
Get a no-obligation offer

Continuous protection

For organisations with higher demands

  • Everything in Standard at a higher frequency
  • Phishing campaigns and staff training
  • Priority response to critical findings
  • Regular consultations and advisory
Get a no-obligation offer

The first small-scope test is free and no-obligation. We set the price of more detailed testing by the agreed scope after a no-obligation consultation.

References

What our clients say

Sample references — we'll replace them with real ones with clients' consent.

Thanks to regular retests we finally stopped dealing with security in bursts. The reports are clear even for our council.
F
First Last
Office secretary · Municipal office (placeholder)
The free entry test was an eye-opener. Within days we knew where our gaps were and had a clear remediation plan.
F
First Last
Managing director · Small business (placeholder)
I appreciate that there's a real person behind every finding to discuss context with. No automated nonsense.
F
First Last
IT administrator · Public organisation (placeholder)

FAQ

What you ask most often

Is the entry test really free?
Yes. The first small-scope test is completely free and no-obligation. More detailed testing then depends on the chosen scope and is arranged to measure. We want you to see the value first-hand before deciding to work with us.
Why don't you publish a price list?
The scope and complexity of testing differ from one organisation to the next. The first small-scope test is free; we set a fair price for more detailed testing by the agreed scope — after a no-obligation consultation you start by submitting the form.
Won't testing endanger our systems?
We test strictly within the agreed scope, with written authorisation and the utmost care. We use destructive techniques only with explicit consent and in a test environment.
How do you handle our data?
We keep data only as long as necessary, protected and in line with GDPR. After the engagement ends we securely dispose of it. Details are in the Privacy section.
Who are the services for?
We focus mainly on municipalities, towns, public organisations and smaller businesses that want to handle their security continuously and understandably.
How does the subscription work?
You choose a protection level and testing frequency. We then test regularly, verify fixes and watch for new vulnerabilities. Thanks to the subscription, every retest is significantly cheaper.

Find out for free where you stand

Fill in a short form and we'll prepare a free entry test of your website or system. No commitment.

I want a free first test

First small-scope test free. Just your name, email and agreement to the terms.