GLBA Safeguards Rule. Annual testing, started today

The Safeguards Rule wants annual pentesting. Start it today.

The FTC's GLBA Safeguards Rule requires financial institutions to test and monitor the effectiveness of their safeguards, including annual penetration testing for most covered entities. We run that test manually against your external systems, and hand you a report and attestation letter you can file as evidence. No sales call, no quote — start from the pricing table.

GLBA Safeguards Rule evidence Manual testing Published pricing Attestation letter included
Why GLBA teams end up here

Non-bank financial institutions are squarely in scope, and the Safeguards Rule is specific about testing.

If you're a mortgage broker, fintech, auto dealer offering financing, or another non-bank financial institution, the GLBA Safeguards Rule applies to you — and its testing requirement is more explicit than most: annual penetration testing plus twice-yearly vulnerability scanning for institutions without continuous monitoring. This page gets the penetration-testing half moving without a drawn-out sales process.

What audit-grade means

Four commitments that separate a real pentest from a quick-find scan.

"Audit-grade" is a category, not a slogan — it's what we commit to on every engagement, not just a claim.

Manual validation

Every finding is manually verified. Scanner output alone doesn't satisfy an annual pentest requirement, and we don't report it as if it does.

Full in-scope coverage

Every host and service you list gets tested end to end, not spot-checked.

Published pricing

Rates are listed by asset count on this page. No quote, no negotiation.

Free 14-day retest

Retest everything from scratch, free, within 14 days of your report.

Honest pricing

Published rates. No quotes. No sales calls.

Covered financial institutions range from single-location brokers to multi-branch lenders. Pricing scales with the number of hosts, IPs, or cloud endpoints tested.

How pricing works: The first asset covers the essential work every engagement requires — scoping, setup, validation, and reporting. Pricing scales with your environment from there. Count each public-facing host, IP, or cloud endpoint you want tested — they don't have to be contiguous or in the same network. If you have more than 256 assets, contact us.
Hosts, IPs, or cloud endpoints to test Price Price per asset
1$4,995$4,995
2–4$7,995$1,999 – $3,997
5–8$10,995$1,374 – $2,199
9–16$15,995$1,000 – $1,777
17–32$25,995$812 – $1,529
33–64$36,995$578 – $1,121
65–128$52,995$414 – $815
129–256$72,995$285 – $566

Manual validation included on every engagement. No false-positive reports. Fixed pricing designed for fast procurement.

GLBA FAQ

What GLBA-covered institutions ask before they buy.

Does this satisfy the GLBA Safeguards Rule's annual pentest requirement?
This provides the annual penetration test the Safeguards Rule calls for, covering your external network and systems. Whether it fully satisfies your specific compliance program is ultimately your assessor's call, not ours — we don't promise regulator acceptance.
Do I still need vulnerability scanning too?
Yes, if you don't have continuous monitoring — the Safeguards Rule calls for that separately, twice yearly. This engagement is the penetration test, not a substitute for scanning.
What's in scope?
External-facing systems tied to your financial services operations: customer portals, loan-origination systems, APIs, VPNs, and public infrastructure. List it and we test it.
How do we start?
Pick your scope from the pricing table and check out online — no sales call needed. Email hello@pentestexpress.com for scoping questions first.
Get started

Ready to start your GLBA Safeguards Rule pentest?

Self-serve checkout, published pricing. No call, no quote, no waiting.