Our Mission

We believe every organisation deserves enterprise-grade security assessment capabilities, regardless of size. Our mission is to democratise penetration testing by providing powerful, automated security tools that were previously only available to large enterprises with dedicated security teams.

PentestOps encodes established penetration testing methodology into automation, so the same phases run every time, on schedule, against every asset in scope. Read the seven phases on our methodology page.

The platform is built on industry-proven scanning, vulnerability detection, and exploitation engines, and it validates what it finds through safe exploitation rather than handing you an unverified list.

Securing the Digital World

Australian-built and operated. PentestOps is a product of Extranet Systems Pty Ltd, hosted in Australia on infrastructure the company runs itself.

Security First

Security is at the core of everything we do. Our platform is built with defence-in-depth principles and undergoes regular security assessments.

Innovation

We continuously evolve our scanning capabilities to address emerging threats and new attack vectors in the ever-changing security landscape.

Trust

We earn trust through transparency, reliability, and delivering on our promises. Your security data is handled with the utmost care.

Who Builds PentestOps

PentestOps is built and operated by Extranet Systems Pty Ltd, an Australian technology company headquartered in Wollongong, NSW, with an office in Sydney. Extranet Systems is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and delivers managed infrastructure, cloud, and security services to Australian organisations.

The platform came out of that work. A penetration test commissioned once a year means waiting for a tester to become available, then living with a report that starts ageing the day it is delivered. In between, the scanners an organisation already owns produce long lists of findings nobody has validated, so the security team spends its time deciding what is real instead of fixing what is.

PentestOps was built to close that gap: continuous, repeatable offensive testing across external perimeter, internal networks, web applications, APIs, cloud, identity, and Kubernetes, with findings validated through safe exploitation so the queue you work through is evidence, not guesswork. It keeps the coverage running between the point-in-time engagements rather than replacing the people who do them.

It is Australian-built and Australian-operated. The platform runs on infrastructure Extranet Systems operates, and customer data is stored in Australia. The AI that analyses findings is self-hosted by default, so scan data is not sent to third-party model providers unless you enable an external provider for your tenant.

Company at a glance

Legal entity
Extranet Systems Pty Ltd, ABN 29 632 743 189
Headquarters
Wollongong, NSW, Australia
Australian offices
Wollongong (Asia-Pacific headquarters) and Sydney (sales and operations)
Certification
ISO/IEC 27001:2022, independently audited by Atom Assurances. A copy of the certificate is available to customers and prospects on request.
Platform
PentestOps, hosted in Australia. See the Trust Centre for the full security posture.

Our Leadership

Amro Elmasry
CEO

Master of Networking and Systems Administration
BSc (Hons) Internet Communications & Networks

Professional Memberships

  • MIET - Member of the Institution of Engineering and Technology
  • MBCS - Member of the British Computer Society

Certifications

  • VCP - VMware Certified Professional (Data Center Virtualization)
  • VCP - VMware Certified Professional (Network Virtualization)
  • CCNP Data Center
  • MCSE - Microsoft Certified Systems Engineer
  • Cisco Data Center Unified Fabric Design Specialist
  • Cisco Data Center Unified Computing Design Specialist
  • Cisco Unified Computing Technology Design Specialist
  • Cisco Data Center Unified Fabric Support Specialist
  • Cisco Data Center Support for UC Specialist
  • Cisco Unified Computing Technology Support Specialist

Global Presence

Extranet Systems operates across three continents, delivering world-class cybersecurity solutions.

Bahrain

Middle East Operations

Egypt

North Africa Hub

Wollongong, Australia

Asia-Pacific Headquarters

Sydney, Australia

Sales & Operations

Extranet Systems company credentials

These are the corporate accreditations, vendor partner tiers, and awards held by Extranet Systems Pty Ltd, the Australian company that builds and operates PentestOps. They describe the parent company and its managed-services practice. They are not certifications of the PentestOps platform, which is covered separately below.

ISO/IEC 27001 logo
ISO/IEC 27001
Information Security Management
Cisco logo
Cisco
Premier Partner
Acronis logo
Acronis
Platinum Service Provider
IBM logo
IBM
Gold Partner
Omnissa logo
Omnissa
Platinum Partner
Google Cloud logo
Google Cloud
Partner
Webex logo
Webex
Contact Center Expert
Sparked logo
Sparked
Founding Member

Extranet Systems awards & recognition

Recognition earned by Extranet Systems Pty Ltd as a company, across its technology and services work and as a workplace.

Local Business Awards - Specialised Business (Finalist) 2026
Acronis #CyberFit Award 2025
Exceptional Marketing Award 2025
Excellence in Innovation - Illawarra Business Awards 2024
Technology, Consumers Award - Future of Ageing 2024

PentestOps platform credentials

A vendor partner tier held by Extranet Systems is not a PentestOps product certification, and the compliance frameworks below are what findings map to in reports, not a claim that PentestOps or your organisation is certified against them. The two lists are kept apart on purpose.

Reporting coverage

  • Findings auto-map to 8 compliance reporting frameworks, plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes
  • Reports carry control-level evidence, an executive summary, and prioritised remediation
  • Multiple report formats including PDF, CSV, and JSON over the API

Platform security

  • Built to SOC 2-aligned controls. SOC 2 attestation is on our roadmap
  • Data encrypted at rest, TLS in transit, secrets injected at runtime from a dedicated vault
  • Every tenant in an isolated Kubernetes namespace with its own dedicated database
  • Role-based access control, with multi-factor authentication required for administrators

Residency & retention

  • Hosted in Australia on infrastructure Extranet Systems operates. Customer data is stored in Australia
  • Tamper-evident audit logs retained for 365 days
  • Assessment findings retained 1 year on Starter, 3 years on Professional, and up to 7 years on Enterprise and MSP
  • Full detail in the Trust Centre

Compliance Reporting Frameworks

The platform maps vulnerability findings to these 8 industry-standard compliance reporting frameworks, generating detailed reports with control-level evidence.

These are the frameworks our findings map to in reports. Separately, Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified (independently audited by Atom Assurances); SOC 2 attestation is on our roadmap.

OWASP Top 10
PCI-DSS v4.0
NIST 800-53
ISO 27001
SOC 2
HIPAA
GDPR
SMB1001

Cloud and Kubernetes scanning also delivers CIS Benchmarks for AWS, Azure, GCP and Kubernetes. These are the frameworks our findings map to in reports. Extranet Systems Pty Ltd itself holds ISO/IEC 27001:2022 certification, independently audited by Atom Assurances.

Frequently Asked Questions

Who builds PentestOps?

PentestOps is a product of Extranet Systems Pty Ltd, an award-winning, ISO/IEC 27001:2022 certified Australian technology partner led by CEO Amro Elmasry. The same accreditations, vendor partnerships and engineering discipline behind our managed services stand behind the platform. The product is built by security professionals for security teams, as continuous offensive security across cloud, web, network and internal infrastructure.

Where is the company based?

Extranet Systems operates across three continents from four offices: Wollongong, NSW (77 Market Street, Wollongong NSW 2500) is the Asia-Pacific headquarters; Sydney (Level 39, Suite 4, 264 George Street, Sydney NSW 2000) covers Sales and Operations; Bahrain (Seef Area, Building 869, Road 3618) runs Middle East Operations; and Cairo, Egypt (120 One Kattameya Compound) is the North Africa hub. The platform itself is delivered as SaaS, so customers do not need to be near an office.

Is PentestOps Australian-built, and where is the platform hosted?

Yes. PentestOps is Australian-built and operated, with the company headquartered in Wollongong, NSW. The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request. The full posture is set out in our Trust Centre.

What awards has Extranet Systems received?

Recognitions our team and technology work have earned include the Local Business Awards - Specialised Business (Finalist) in 2026, the Acronis #CyberFit Award and the Exceptional Marketing Award in 2025, and Excellence in Innovation - Illawarra Business Awards plus the Technology, Consumers Award - Future of Ageing in 2024.

What partner accreditations does Extranet Systems hold?

The company holds ISO/IEC 27001 for Information Security Management and is a Cisco Premier Partner, an Acronis Platinum Service Provider, an IBM Gold Partner, an Omnissa Platinum Partner, a Google Cloud Partner, a Webex Contact Center Expert, and a Sparked Founding Member. These accreditations sit with Extranet Systems as a technology partner and are separate from the compliance frameworks that PentestOps findings map to in reports.

Does PentestOps replace human penetration testers?

No. We are the always-on coverage layer between human engagements, not a replacement for red teaming. Automation runs the repeatable, high-volume testing continuously so specialists can focus on the creative work that automation handles poorly. The platform is built to sit alongside a periodic human engagement, providing coverage in between, which is the model described on continuous penetration testing.

How do I get support, and what hours do you cover?

Support is 24/7 for Enterprise customers and Monday to Friday, 9am to 6pm AEST for other plans. Enterprise engagements also include a dedicated account manager and a dedicated security review. For anything else, including procurement questions and security documentation requests, use contact us.

Can I resell or white-label PentestOps?

Yes. The Partner and MSP programme lets you white-label or resell asset-wise testing to your own clients, with a fully isolated environment per client, custom domains with auto-managed SSL, fleet-wide agent management and three MSP tiers. It is sales-led rather than self-serve. See the MSP security platform or apply through the partner programme.

Ready to Work With Us?

Start your security assessment with PentestOps today.

Start Scanning Contact Us