Platform Offering Table | Synack
The Synack Platform: A Guide to Key Features and Benefits
The Synack Platform: Penetration Testing Product Offerings
| Offering | Assessment Window | Test Methodology | Testers | Asset Types | COMPLIANCE |
|---|---|---|---|---|---|
| Sara Pentest | 4-5 days | Open Vulnerability Discovery | AI agent driven | External Web or Host | Detailed Pentest Report: Yes* |
| Sara Pentest+ | ST: 5 days | Guided checklist-based assessment | Assigned researcher | Web or Host | Industry Standards Testing: Optional Add-on checklists (OWASP, NIST 800-53) |
| SynackST/ST+ | ST+: 5-10 days | Open Vulnerability Discovery | Pool of researchers | Web, Host, Mobile, or LLM/AI | Proof of coverage report included |
| Penetration Test SYNACK14 | 14 days | Open Vulnerability Discovery | Rotating pools of researchers | Web, Host, Mobile, or LLM/AI | Yes |
| Penetration Test SYNACK90 | 90 days | Open Vulnerability Discovery | Rotating pools of researchers | Web, Host, Mobile, or LLM/AI | Yes |
| Continuous Penetration Testing SYNACK365 | 365 days | Headless API endpoint testing and reporting | Pool of researchers | Headless API | Yes |
The Synack Platform: Key Features and Benefits
Synack Basic Platform
- ATTACK SURFACE DISCOVERY, POINT-IN-TIME (Not available in FedRAMP)
- Self-Service Discovery of New Assets for 30 Days
- Seed Groups to Help Organize Assets and Control Access
- Limited Discovery of Assets to Surface Testing Candidates
- Discovered Asset Reporting Dashboard
REPORTING AND ANALYTICS
Tracking for Researcher Testing Hours
Real-Time Reporting on Exploitable and Suspected Vulnerabilities
Attacker Resistance Score
Track holistic security performance overtime with a risk score
Coverage Analytics
Testing Data History & Retention
Asset List That Catalogs All Tested Assets
Fingerprinting of External Assets to Inform Further Testing
Asset Details Highlighting Previous Testing Results
API AND INTEGRATIONS
- Synack API
- Synack Basic Integrations (Jira, ServiceNow, Microsoft, Splunk, etc.)
MANAGED COMMUNITY ACCESS
- Researcher Vetting
- Proactive Researcher Rotation
- Access to Researchers and Vulnerabilities
- Fully Managed Researcher Payouts
AUTHENTICATION & AUTHORIZATION
- Single Sign-On (SSO) Integration (SAML 2.0)
- Role-Based Access Control (RBAC)
PLATFORM TEST CONTROLS
- Self-Service Pentest Creation
- Al Scoping Bot
- Pause Testing at the Click of a Button
- Synack-Owned Virtual Security Researcher Workspaces
- Enhanced Security with Testing Data Stored in Synack-Owned Endpoints
- Data Cleansing Available on Customer’s Request
- Exploits Requiring Callbacks
- Synack Command and Control Infrastructure to Contain Traffic Stemming from Exploits Requiring Callbacks
VULNERABILITY MANAGEMENT & INTEGRATIONS
- Active Communication with Researchers (SRT Chat)
- Patch Verification (PV)
- Synack On-Demand Security Testing Catalog Access
- Internal and External Testing
- Number of VPN Connections: 3, Add-ons available
CUSTOMER SUCCESS
- Proactive Identification of Test Issues
- Customer Success Personnel
- Self-Service
- Pooled CSS
The Synack Platform: Add-Ons
MANAGED VULNERABILITY DISCLOSURE PROGRAM
Vulnerability Disclosure Program Webform
Triage for 200 Vulnerability Submissions Per a Year (Each Additional Submission Is 1 Credit)
Synack will triage vulnerabilities the public submits through your program
External Researcher Management
Synack will manage relationships with members of the public that submit vulnerabilities
Real-Time Reporting
Synack provides a client portal for customers to view vulnerability data and generate PDF reports
ATTACK SURFACE DISCOVERY, CONTINUOUS
- Not available in FedRAMP
- Self-Service Discovery of New Assets for 365 Days
- Seed Groups to Help Organize Assets and Control Access
- Weekly Discovery of Assets to Surface Testing Candidates
- Discovered Asset Reporting Dashboard
SARA TRIAGE
- Not available in FedRAMP
- Includes 100 AI-Powered Vulnerability Exploit Validations (Each additional set of 10 triaged vulnerabilities requires 1 credit)
- Threat Intelligence Integration
- Human Validation of Exploitable Risks
- On-Demand SRT Capacity
Additional Details
ST/ST+ & Sara Pentesting Reports: “*” indicates AI-generated summaries of reported findings.
Asset Types and Scope: The following asset types and scoping parameters apply to each test type below. Customer may select the Customer Product for testing, and each Customer Product selected is subject to approval by Synack:
- Sara PT*: One low complexity authenticated or unauthenticated web application, or up to 100 host IPs.
- Sara PT+*: One large web authenticated or unauthenticated application, or up to 250 host IPs.
- ST*: One low complexity or authenticated web application, 25 unauthenticated URLs, or 100 host IPs.
- ST*, Synack14, Synack90, and Synack365: One of the following asset types: One large web authenticated application, up to 50 unauthenticated URLs, one mobile app (iOS and Android), or up to 250 host IPs.
- API: One API with up to 25 endpoints (add-ons available for more).
- Web application complexity will be determined by Synack based on factors including tenancy, user roles, and other factors.
Subscription Period: Except as otherwise stated above, all services will be provided during the subscription period set forth in the customer’s order form.
Open Vulnerability Discovery: Incentive-based open vulnerability discovery testing performed by the Synack Red Team (SRT) on in-scope test assets pursuant to agreed upon rules of engagement and testing timeline.
Guided Vulnerability Discovery: Structured vulnerability discovery is performed by a single vetted SRT member following a methodology based on industry-recognized standards on in-scope test assets pursuant to agreed upon rules of engagement and testing timeline.
Synack Catalog: With the purchase of Synack Credits, customers can launch additional tests and checklists within the Synack Platform. Synack Credits must be purchased separately.
Attack Surface Discovery, Point-in-time: For 30 days, new assets are discovered weekly and fingerprinted daily. Discovered assets are limited to 25,000 assets. Additional assets can be added for an additional fee.
Attack Surface Discovery, Continuous: For 365 days, new assets are discovered weekly and fingerprinted daily. Discovered assets are limited to 25,000 assets. Additional assets can be added for an additional fee.
Additional Offerings
- Managed Vulnerability Disclosure Program: Synack receives, investigates and validates vulnerability reports submitted by public security researchers (“Finders”) through a public managed vulnerability program. Finders are not Synack Personnel. Synack disclaims all liability arising from or related to the activities of Finders.
- Synack Credits: Synack Credits are redeemable for the services listed in the Synack Catalog available in the Synack Platform. Catalog offerings and credit prices are subject to periodic change. Synack Credits are redeemable only for Catalog offerings. Synack Credits have no cash value, are non-transferable and non-refundable. Synack Credits are only valid during the customer’s subscription period, and any unused credits will expire at the end of the subscription period.