Compliance — PCI DSS

Continuous pentests
for PCI DSS 11.4.

Requirement 11.4 requires a penetration test — at least annually and after every significant change. Autonomous agents run it continuously, prove what is exploitable where card data is handled, and produce the report your QSA reviews.

  • Requirement 11.4, covered
  • After every change
  • A report your QSA reviews
Integrate everything from your surface
  • AWS
  • Google Cloud
  • Azure
  • Cloudflare
  • GitHub
  • GitLab
  • Bitbucket
How it maps

The testing Requirement 11.4 wants,
and the proof it leaves.

Req. 11.4

Penetration testing

The internal and external, application-layer testing 11.4 requires — run continuously rather than once a year against a methodology you can show.

Req. 11.4.5

Segmentation testing

Agents check whether the systems that handle card data can be reached from systems that should be out of scope — the segmentation test 11.4 calls for.

Remediation

Closed and retested

Fixes land through your own coding agent over MCP; 11.4 requires re-testing after significant change, and agents run on every release.

Evidence

A report for your QSA

Findings, exploitation, remediation status and dated retests, retained in the form an assessor expects to review.

Beyond the pentest

The pentest is one requirement. Knowing what touches card data is another.

PCI DSS turns on which systems handle card data and what connects to them. Superhack discovers your estate from the outside and maps every host to the provider and service provider behind it, so what is in scope and what touches it stays a live map rather than a spreadsheet updated once a year.

Attack surface map

Your company, from the outside
AWS eu-west-1168 assets
Vercel96 assets
Cloudflare41 assets
Auth06 assets
Stripe9 assets
Datadog14 assets
Sentry4 assets
Heroku35 assets
Customer API42 assets
2api.acme.com
4api-eu.acme.com
gw.acme.com
events.acme.com
webhooks.acme.com
sandbox.acme.com
docs-api.acme.com
status.acme.com
Acquired estate26 assets
3sso.oldco.net
1vpn.oldco.net
2jira.oldco.net
wiki.oldco.net
mail.oldco.net
ftp.oldco.net
git.oldco.net
old-cdn.oldco.net
1
Payments18 assets
9
Internal tooling51 assets
3
Web application87 assets
Edge and DNS41 assets
1
Identity tenant6 assets
Billing9 assets
2
Observability14 assets
1
Error tracking4 assets
2
Legacy DNS9 assets
Critical findingsHigh findingsObserved relationshipReachable, not provenProven crossing
Why continuous

A once-a-year pentest ages fast.
The evidence has to stay true.

Capability
Pentest
annual engagement
Scanner
Burp · Nessus
Superhack
this thing
Continuous coverage
Once a year
Always-on
Continuous + on-demand
Full-scope, agent-deep
A sample of your stack
Surface only
Every endpoint, every path
Real exploitation
Bounded by human time
Pattern matching
End-to-end chains
Runnable proof of exploit
“Likely exploitable”
CVE / signature match
curl + Playwright pack
Zero false positives
Low (manual review)
High noise
Replayed before delivery
Same-day results
3+ months
Real-time, noisy
First critical inside hours
No per-engagement billing
$50–100k per engagement
Flat annual subscription
Free during early access
The evidence pack

Everything your auditor asks for. Assembled as the testing happens.

  • Every finding, with the requests and the exploit path that proved it
  • Severity, affected asset, and the boundary that was crossed
  • Remediation status, linked to the change that closed it
  • A dated retest verdict showing the exploit no longer reproduces
  • A timeline of agent activity across the testing window
  • Scope, rate limits and the identities testing ran as
For your next PCI assessment

Get the Requirement 11.4
penetration test.

Point agents at the systems that handle card data and see the report your QSA wants — findings that arrive proven, segmentation checked, fixes verified, and testing that keeps running after every significant change.

Evidence
Audit-ready
Testing
Continuous
Findings
Proven
Retests
Dated
FAQ

Frequently asked questions

Common questions about PCI DSS security evidence with Superhack.