CHELYS SECURITY
FAQ // ENGAGEMENT BRIEF · SYSTEM STATUS: NOMINAL

Autonomous Penetration Testing

Scan FAQ

Everything worth knowing before you initiate an engagement — pricing, timing, authorization, and what lands in your hands afterward.

[ The scan ]

An autonomous engagement run by a coordinated swarm of AI agents. They map the assets you put in scope, build a live attack graph, and isolate real exploit chains — not a flat list of CVEs — then hand you a clear account of what's exploitable and how to close it.

The domains and/or IP addresses you want tested, and a signed authorization. That's enough to start. If your scope touches operational technology or safety-critical systems, there's one short extra step — see Will testing disrupt my systems? below.

Most scans complete within a day. The exact time depends on how large the scope is, what services are running, and the attack paths the swarm uncovers — deeper work like password or hash cracking can run longer.

We'd rather be thorough than chase an artificial deadline, so we don't promise a fixed turnaround. Once you're booked, we confirm your start time by email.

Scans start at $8,000, covering up to five in-scope IPv4 addresses, with each additional IPv4 address at $2,000. IPv6 is quoted separately.

Most penetration tests are bought and delivered one-and-done — a single point-in-time snapshot that leaves your systems untested until the next annual cycle. A Chelys engagement runs continuously instead: up to three scans per month, so your attack surface is re-tested as it changes, not once a year. Traditional manual engagements run $15K–$100K+ per snapshot.

Fee covers an annual (365-day) engagement window. See the Pricing page for details.

Pay once and you're covered for up to 12 months (365 days). Unlike a one-and-done snapshot, that window is a live engagement — you can run repeat scans across it as your environment changes, with no rebooking or new quote each time.

Up to three per month across your annual coverage window — so you can re-test after a fix, a deployment, or an infrastructure change rather than waiting for the next annual audit.

Just email help@chelys.io with the additional domains or addresses. We'll send back pro-rated pricing to add those IPv4 addresses for the remainder of your annual term — no need to wait for renewal. IPv6 is quoted separately.

[ Getting started ]
  1. Sign the document packet — mutual NDA, Pentest Application, Master Services Agreement, and Data Processing Agreement.
  2. We invoice you; payment typically clears within three business days.
  3. Once funds clear, we confirm your scan start time by email.
  4. The swarm runs the engagement, then we follow up through your point of contact with an optional results review.

Email help@chelys.io for booking, scoping questions, or anything else.

[ Reports & data ]

You receive a self-contained HTML report — a single .html file you open in any browser, with the findings, severity ratings, and exploit paths interactive and searchable. It's delivered securely and never parked on a third-party website we don't control. We also offer an optional 30–60 minute review meeting to walk through the findings with you.

Every finding we confirmed, rated by severity, with the exploit path demonstrated and clear remediation guidance — so your team knows exactly what to fix and in what order.

Under a mutual NDA, a Data Processing Agreement, and a Responsible Disclosure Policy, backed by SOC 2-aligned security controls. Your results are yours, and we treat everything we see as confidential.

[ Legal & safety ]

Yes — with your authorization. Before any testing begins, you sign a Pentest Authorization that grants scoped consent under the CFAA and ECPA, covers third-party and cloud-hosted assets, and includes multi-state consent where it's required. No signature, no scan.

The swarm maps assets and isolates exploit paths without disrupting operational infrastructure. Every action is gated in real time by a deterministic Safety Oracle that limits payloads and intercepts anything outside the agreed bounds.

If your environment includes operational technology, industrial control systems (ICS/SCADA), or medical devices, we require a separate written agreement before we touch them — so safety-critical systems are never in scope by accident.

If an engagement surfaces a genuine zero-day, we take it through a formal responsible-disclosure process: a documented CVE write-up submitted through a CVE Numbering Authority, with a severity rating recorded in the NIST National Vulnerability Database. You're kept informed throughout. See our Disclosure Policy.

Ready to deploy your first assessment?

See how the autonomous swarm maps assets, builds live vulnerability graphs, and isolates exploit paths — without disrupting operational infrastructure.

Initiate Engagement