Penetration testing
The internal and external, application-layer testing 11.4 requires — run continuously rather than once a year against a methodology you can show.
Requirement 11.4 requires a penetration test — at least annually and after every significant change. Autonomous agents run it continuously, prove what is exploitable where card data is handled, and produce the report your QSA reviews.
Signed in as one merchant, the payment API returned another account's transactions.
The internal and external, application-layer testing 11.4 requires — run continuously rather than once a year against a methodology you can show.
Agents check whether the systems that handle card data can be reached from systems that should be out of scope — the segmentation test 11.4 calls for.
Fixes land through your own coding agent over MCP; 11.4 requires re-testing after significant change, and agents run on every release.
Findings, exploitation, remediation status and dated retests, retained in the form an assessor expects to review.
PCI DSS turns on which systems handle card data and what connects to them. Superhack discovers your estate from the outside and maps every host to the provider and service provider behind it, so what is in scope and what touches it stays a live map rather than a spreadsheet updated once a year.
Point agents at the systems that handle card data and see the report your QSA wants — findings that arrive proven, segmentation checked, fixes verified, and testing that keeps running after every significant change.
Common questions about PCI DSS security evidence with Superhack.