Penetration testing services
Penetration testing services in Canada
Web application, API, network, cloud, wireless and red team testing that proves what is exploitable and how to fix it.
A scanner lists what might be wrong. Our testers break in, chain the weaknesses, show you what they reached and help you close it. Reports built for developers, auditors, insurers and enterprise customers.
Get your penetration testing proposal
Tell us what you want tested. You will have a fixed scope and price in writing within one business day.
By submitting, you agree that Canada Create™ may contact you about your request. No spam, ever.
What a penetration test gives you
Proof of real exploitability
What an attacker could reach, demonstrated, not guessed from a scanner score.
A fix for every finding
Reproduction steps and specific remediation your developers can act on.
Audit and customer evidence
Reports and an attestation letter for SOC 2, PCI DSS, insurers and procurement.
Confirmed closure
A retest of closed findings is included in the quote.
What is included in our penetration testing services
Manual testing by experienced testers, scoped in writing and reported for two audiences.
- Web application and API testingOWASP Top 10 and business logic testing of custom apps, WordPress, SaaS and portals.
- External network testingYour internet-facing perimeter, remote access and forgotten assets.
- Internal network testingLateral movement, privilege escalation and Active Directory weaknesses.
- Cloud testingMicrosoft 365, Azure, AWS and Google Cloud identity, storage and configuration.
- Wireless and physical testingWi-Fi, rogue devices, badge and tailgating attempts within agreed rules.
- Social engineeringTargeted phishing and phone pretexting to test people and process.
- Red team engagementsGoal-based, multi-week operations that test detection and response.
- Remediation support and retestHelp closing findings and a retest with attestation letter.
Penetration testing pricing
Scope decides price: applications, network size, cloud footprint and whether red team is included.
Application or network test
Quoted in writing
A defined set of applications, APIs, external or internal networks or cloud tenants
- Written rules of engagement
- Manual testing and exploitation
- Technical report and executive summary
- Remediation support and retest
- Attestation letter
Red team engagement
By proposal
Organizations with a security team or MDR that want detection and response tested for real
- Goal-based, multi-week operation
- Minimal notice to defenders
- Phishing, network and physical vectors as agreed
- Full debrief for executives and defenders
Annual testing programs and combined testing plus managed security are priced with a discount in your proposal.
Ethical hacking with a purpose
Find out what an attacker would find
Penetration testing that shows what an attacker could actually do
A vulnerability scanner lists things that might be wrong. A penetration test has an experienced person try to break in, chain small weaknesses into real access, and show you exactly what they reached: the customer database, the admin panel, the payroll system, the domain controller. Canada Create™ penetration testing services deliver that proof, with a fix for every finding and a retest to confirm it is closed.
We test for organizations across Canada that need results they can act on and hand to someone else: developers who need reproduction steps, auditors who need evidence for SOC 2 or PCI DSS, insurers who ask for a recent test, and enterprise customers whose procurement team will not sign without one.
Types of penetration testing we perform
Web application and API penetration testing
Manual testing of your web applications and APIs against the OWASP Top 10 and beyond: authentication and session flaws, access control, injection, business logic abuse, file handling, insecure direct object references and the mistakes that automated tools miss. Covers custom applications, WordPress and WooCommerce sites, SaaS platforms, customer portals and mobile app back ends.
External network penetration testing
Everything you expose to the internet: perimeter firewalls, VPNs, remote access, mail systems, exposed services and forgotten subdomains. We map your external attack surface the way an attacker would, then attempt to get in.
Internal network penetration testing
Assumes an attacker already has a foothold, whether through phishing, a rogue device or a compromised contractor. We test how far they could go: lateral movement, privilege escalation, Active Directory weaknesses, shared credentials and paths to your most sensitive systems.
Cloud penetration testing
Microsoft 365, Azure, AWS and Google Cloud configurations, identity and access policies, storage exposure, serverless functions and the connections between your cloud and on-premises systems.
Wireless, physical and social engineering
Wi-Fi security, rogue access point testing, badge and tailgating attempts, and targeted phishing or phone pretexting, always within written rules of engagement.
Red team engagements
A red team assessment is a goal-based, multi-week operation with minimal notice to your defenders. The objective might be reaching a specific system or data set. The point is to learn whether your monitoring, response and people actually work under a realistic attack, not just whether a particular server has a patch missing. Ethical hacking with a clear objective and a full debrief for both your executives and your security team.
What you receive
Every test ends with two documents. The technical report lists each finding with severity, evidence, reproduction steps and a specific remediation. The executive summary explains business impact in plain language for owners, boards, customers and insurers. Findings are ranked by real exploitability, not scanner scores, so your team works on what matters first. Remediation support and a retest of closed findings are included in the quote, and you receive an attestation letter suitable for customers and auditors once the retest is clean.
Methodology and standards
Testing follows recognized methodologies including the OWASP Testing Guide, the Penetration Testing Execution Standard and NIST guidance, and is scoped with written rules of engagement that define targets, timing, exclusions and emergency contacts. Testing that could affect availability is agreed in advance and scheduled outside business hours where needed. Your data is handled under a signed agreement and evidence is destroyed on a schedule you approve.
Who needs a penetration test
SaaS and technology companies before a SOC 2 audit or an enterprise deal. Healthcare organizations protecting patient records under PHIPA. Law and accounting firms holding privileged client data. Financial services firms answerable to OSFI and provincial regulators. E-commerce businesses within PCI DSS scope. Manufacturers whose operations cannot afford a ransomware outage. Any business renewing cyber insurance. And any company launching a new application, after a major change, or annually as good practice.
Penetration testing pricing
Price depends on scope: number of applications, size of the network, cloud footprint and whether a red team component is included. A single web application test and a multi-site internal test are very different engagements. Tell us what you want tested and you will have a fixed price in writing within one business day. Ongoing programs combine testing with managed security services so what we find stays fixed.
Book your penetration test
Get a proposal in one business day, or call +1 (800) 808-9235 any time. Part of our cyber security services for Canadian businesses.
Talk to a strategist
Ready when you are!
Get a proposal in one business day.
Tell us your goals, budget and timeline. You get a plan, a price and a named strategist, with no long-term contract.
How a penetration test runs
Scoped, authorized, scheduled around your operations and reported clearly.
- Scoping and rules of engagement Day 1 to 3
Targets, timing, exclusions, emergency contacts and the evidence you need, in writing.
- Reconnaissance Week 1
Mapping your attack surface the way an attacker would.
- Exploitation Week 1 to 2
Manual testing, exploitation and chaining of findings with your approval.
- Reporting Week 2 to 3
Technical report with fixes and an executive summary, ranked by real risk.
- Remediation and retest Week 3 to 6
Support closing findings, then a retest and attestation letter.
What clients say on Google
Reviews pulled live from our Google Business Profile.
Free review, no obligation
Not sure where to start? Send us what you have.
Share your current site, campaign or brief. A strategist reviews it and replies within one business day with a written recommendation and a fixed quote.
Why Canada Create™ for penetration testing
Testers who build
We have built and hosted web applications since 2008, so we know where developers cut corners.
BBB Accredited, A+
An A+ rating with the Better Business Bureau and zero complaints.
Recognized methodology
OWASP, PTES and NIST guidance with written rules of engagement.
Quoted in writing
Fixed scope and price before testing starts. Get a proposal in one business day.
Fixes included
Remediation support and a retest are part of the engagement.
24/7* support
Call +1 (800) 808-9235 any time, day or night.
Penetration testing questions
What is penetration testing?
An authorized, simulated attack on your systems by experienced testers who try to exploit weaknesses the way a real attacker would, then report what they reached and how to fix it.
How is a penetration test different from a vulnerability scan?
A scan is automated and lists possible weaknesses. A penetration test is manual, exploits and chains those weaknesses, and shows real business impact. Auditors and customers usually require the test.
How much does penetration testing cost in Canada?
It depends on the number of applications, the size of the network and whether cloud or red team components are included. Every test is quoted in writing within one business day.
How long does a penetration test take?
Most single-scope tests take one to two weeks of testing plus a week for reporting. Red team engagements run several weeks.
What is a red team assessment?
A goal-based operation with minimal notice to your defenders that tests whether your monitoring, response and people work under a realistic attack, not just whether a system is patched.
Will testing take our systems down?
Rules of engagement define what can be tested, when and how. Anything that could affect availability is agreed in advance and scheduled outside business hours.
Is penetration testing required for SOC 2 or PCI DSS?
PCI DSS requires penetration testing at least annually and after significant changes. SOC 2 auditors expect regular testing as evidence of control effectiveness. Cyber insurers increasingly ask too.
Do you test WordPress and e-commerce sites?
Yes. WordPress, WooCommerce, Shopify integrations and custom storefronts are among the most attacked applications in Canada, and we have built and hosted them since 2008.
Do you help fix what you find?
Yes. Remediation support and a retest are included, and because we build and host web systems, we can implement many fixes directly.
How often should we test?
At least annually, after any major change to applications or infrastructure, and before launching anything that handles customer data.


Every untested application is a test someone else will run
Attackers scan Canadian businesses every day. Find your weaknesses under controlled conditions, with a fix attached.

