Skip to content
Glossary

What is a penetration test?

The test enterprise customers ask to see a report from. Here is what it proves, and what it does not.

Plutonapps Engineering1 min read

In short

A penetration test is an authorised, simulated attack on an application or system by security testers, who try to exploit weaknesses the way a real attacker would and report what they could reach. Unlike an automated vulnerability scan, which lists known issues, a penetration test proves which weaknesses can actually be used, and how far.

Also called: Pen test, Pentest, Ethical hacking

Why it matters when your prototype goes to production

A penetration test is most useful once the obvious gaps are closed. Run against an AI-built app nobody has reviewed, it mostly finds what a code audit would have found more cheaply: tables without row-level security, keys in the browser, endpoints that trust the client. Fix those first, then pay testers to find what is left.

What a good test covers

  • Access control between users and between customer accounts.
  • Authentication: sign-in, password reset, sessions, tokens.
  • Injection and input handling.
  • Exposed secrets, misconfiguration and outdated dependencies.
  • Business logic: can someone get something without paying for it?

The report is also a sales document. Enterprise buyers often ask for a recent one, and for evidence that the findings were fixed.

Common questions

What is the difference between a penetration test and a vulnerability scan?

A scan is automated and lists known weaknesses. A penetration test is done by people, who try to exploit weaknesses and chain them together to show real impact.

How often should we have one?

Commonly once a year and after major changes, or whenever a customer or auditor requires it.

More on this: Production architecture & security · All glossary terms

Built something in Lovable you want people to rely on?

We are the engineers who take it the rest of the way — secured, tested, released and supported.