AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
Back to documentation
PTaaSPTaaSDelivery

PTaaS engagement lifecycle

Version 1.04 min readLast updated September 23, 2026

How an expert-led engagement runs end to end — scope, staffing, testing, retest, certification and billing.

Crowd-sourced testing gives breadth; an expert-led PTaaS engagement gives scheduled depth with evidence that stands up to review. This document follows an engagement from planning to closure.

1. Planning

  • Asset lifecycle setup — the assets in scope are defined, and each is classified and tiered. The same scope definition used by crowd-sourced programs is reused here, so nothing is tested twice by accident and nothing is missed by omission.
  • Engagement model — fixed-scope, tiered or subscription. Fixed suits a point-in-time assessment; subscription suits continuous coverage with a named team.
  • Rules of engagement — boundaries, prohibited techniques, testing windows and data-handling rules agreed before anyone logs in.
  • Success criteria — what the engagement is expected to produce: findings, coverage evidence, a compliance artefact, or all three.

2. Staffing

  • Named testers — the engagement staffs to specific people rather than a pool.
  • Scheduler and staffing coordination — availability is planned against the engagement window.
  • Dedicated tester pools — continuity for organisations that want the same testers each cycle, so environment knowledge accumulates. This is Enterprise-tier.
  • Expert gates — each tester must hold the expert role, be covered by the organisation's entitlement, and accept the engagement invitation before receiving any access. See Identity and access.

3. Access and confidentiality

  • NDA acceptance is recorded per tester with a timestamp.
  • Credential locker distributes testing credentials under control, scoped to the engagement.
  • VPN access is provisioned where internal systems must be reached, and revoked when the window closes.
  • Access expiry is a property of the engagement, not a manual step someone has to remember.

4. Testing

Testing combines black-box and white-box work depending on what the engagement needs:

  • External and internal network testing within the agreed scope.
  • Application and API testing against documented business flows.
  • Source code review where a repository is in scope, so white-box depth complements black-box findings.
  • CI integration so offensive security activity can be triggered and evidenced from the delivery pipeline.
  • Risk scoring and attack paths to prioritise by realistic exploitability rather than raw severity alone.

Progress and collaboration happen in-platform: testers, program owners and engineering share the same record, with realtime chat and notifications rather than email threads.

5. Reporting

Output is structured rather than a slide deck:

  • Findings with severity, affected assets, reproduction, evidence and remediation guidance.
  • Compliance report exports formatted for the obligation in question.
  • Delta and regression reporting between cycles — new, resolved, recurring and carried-over findings. See Remediation and verification.

6. Retest and certification

  • Retest confirms that a fix closes the finding, within the engagement scope.
  • Certification produces an attestation artefact for stakeholders and auditors, tied to the engagement record rather than assembled by hand afterwards.
  • Recertification on a subscription keeps the attestation current instead of expiring annually.

7. Billing and metering

  • Usage metering tracks consumed effort transparently during the engagement, visible to both sides.
  • Billing models — fixed, tiered or subscription, with invoicing generated from the metering and engagement records.
  • Overage follows pre-agreed thresholds and rates, so exceeding a tier does not become a billing dispute.

8. Closure

An engagement closes with a defined set of outputs recorded on the same platform record: findings and their remediation state, the retest result, the certification artefact where applicable, the metered effort, and the invoice. Nothing about the engagement exists only in a document that someone has to find later.

Availability and limits

  • Engagement creation, scoped assets, rules of engagement, invitations, NDA tracking, retest and reporting are available wherever PTaaS is licensed.
  • Dedicated tester pools, SLA response guarantees and custom severity scoring are Enterprise-tier.
  • VPN access, source code review, retesting, compliance exports and CI integration are Professional-tier.
  • The platform provides structure and evidence for an engagement. The assurance it produces is bounded by the scope that was agreed.