What is a penetration test?
The test enterprise customers ask to see a report from. Here is what it proves, and what it does not.
In short
A penetration test is an authorised, simulated attack on an application or system by security testers, who try to exploit weaknesses the way a real attacker would and report what they could reach. Unlike an automated vulnerability scan, which lists known issues, a penetration test proves which weaknesses can actually be used, and how far.
Also called: Pen test, Pentest, Ethical hacking
Why it matters when your prototype goes to production
A penetration test is most useful once the obvious gaps are closed. Run against an AI-built app nobody has reviewed, it mostly finds what a code audit would have found more cheaply: tables without row-level security, keys in the browser, endpoints that trust the client. Fix those first, then pay testers to find what is left.
What a good test covers
- Access control between users and between customer accounts.
- Authentication: sign-in, password reset, sessions, tokens.
- Injection and input handling.
- Exposed secrets, misconfiguration and outdated dependencies.
- Business logic: can someone get something without paying for it?
The report is also a sales document. Enterprise buyers often ask for a recent one, and for evidence that the findings were fixed.
Common questions
What is the difference between a penetration test and a vulnerability scan?
A scan is automated and lists known weaknesses. A penetration test is done by people, who try to exploit weaknesses and chain them together to show real impact.
How often should we have one?
Commonly once a year and after major changes, or whenever a customer or auditor requires it.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.