Parameter

[ PCI pentest ]

Pentests for PCI DSS 11.4,after every change.

Agents pentest your payment systems after every change and turn each run into an audit-ready 11.4 report. Fixes are re-tested and coverage never lapses, so you pass audits faster and prove security to customers.

See first findings in 24 hours

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ what PCI DSS asks ]

What Requirement 11.4 asks,and what a run gives you.

PCI DSS v4.0 is explicit about penetration testing, and explicit that the annual test comes from a qualified tester. Here is where each part lands.

3 covered by every run · 1 shared with your assessor · 2 not covered

11.4.1 · A defined methodology

A documented methodology, implemented, with results retained for at least 12 months. The same method applied identically on every run, and every run's report kept.

covered by every run

Evidence to keep: methodology, 12 months of reports

11.4.4 · Corrected and re-tested

Exploitable vulnerabilities and weaknesses corrected, then re-tested. Every finding exploited before it is reported, then re-tested on fix, in the same report.

covered by every run

Evidence to keep: finding, fix, re-test

11.4.2 and 11.4.3 · After significant change

Internal and external testing after any significant change. Every release is tested as it ships, so the test after a change has already happened, with its report.

covered by every run

Evidence to keep: report dated to the change

11.4.2 and 11.4.3 · The annual test

At least once every 12 months, by a qualified internal resource or a qualified, organizationally independent third party. Not required to be a QSA or ASV. Parameter gives that tester a current, proven baseline to start from.

shared with your assessor

Evidence to keep: the tester's report

11.4.5 and 11.4.6 · Segmentation

Segmentation controls tested at least annually and after changes, and every six months for service providers. Network work for your annual tester.

not covered

11.3 · Vulnerability scans

Quarterly internal scans and external scans by an Approved Scanning Vendor. Parameter is the exploit-proven layer above an ASV scan, not a replacement for it.

not covered

[ how it works ]

Connect

A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.

Test every release

Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.

Hand over the run

Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.

[ definition ]

What PCI DSS asks of a pentest

PCI DSS v4.0 Requirement 11.4 asks for internal and external penetration testing at least every 12 months and after any significant change, performed by a qualified tester, with exploitable weaknesses corrected and re-tested. Parameter's agents supply the second half of that sentence on every release: the test after each change, the proof, and the re-test. A qualified tester performs the annual test and the segmentation testing, starting from those results.

[ FAQ ]

Frequently asked questionsabout PCI pentest

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.