Frequently Asked Questions

Where does PentestOps operate?

PentestOps is built and operated in Australia by Extranet Systems Pty Ltd, with its Asia-Pacific headquarters at 77 Market Street, Wollongong NSW 2500 and a Sydney office at Level 39, Suite 4, 264 George Street, Sydney NSW 2000. The platform is delivered as SaaS to organisations across every Australian state and territory and in New Zealand. Extranet Systems operates across three continents, with further offices in the Seef Area of Bahrain and in Cairo.

Do you have an office in Melbourne, Brisbane or New Zealand?

No, and we will not pretend otherwise. Our only offices are Wollongong (headquarters), Sydney, Bahrain and Cairo. Customers in Melbourne, Brisbane and New Zealand are served remotely: the platform is SaaS, the on-premise agent installs itself inside your own network, and support is led from Australia. Nobody needs to fly to your site to test it.

Where is our data stored and processed?

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. That applies to New Zealand customers as well, so trans-Tasman data flows should be covered in your own privacy assessment. Specific data-residency arrangements are available to Enterprise customers on request, and the Trust Centre sets out encryption, retention and access control in full.

Does remote delivery limit internal network testing?

No. Internal testing runs from an on-premise agent that you install yourself, usually in about 5 minutes. It connects outbound-only over TLS 443, needs zero inbound firewall rules, and runs scans natively on your LAN instead of tunnelling every packet in from outside. One host can cover multiple subnets, and the same agent supports 24/7 continuous monitoring.

What are your support hours and time zones?

Support is led from Australia, with our Bahrain and Cairo teams covering hours outside the Australian working day. Enterprise customers have 24/7 support; other plans are supported Monday to Friday, 9am to 6pm AEST, which overlaps most New Zealand business hours. Scans run on your schedule rather than ours, so change windows and after-hours testing are straightforward to arrange.

Can you test assets hosted outside Australia and New Zealand?

Our commercial focus is Australia and New Zealand, but your assets do not have to be. External, web application, API and cloud testing reach whatever you are authorised to test, and cloud accounts in overseas regions are audited the same way. What matters is authorisation: every scan runs under signed Rules of Engagement, and scope enforcement stops activity outside your authorised assets. For a complex multi-country footprint, talk to us before you scope.

Do local regulations change how you test?

They change the framing more than the technique. Australian buyers typically reference the Essential Eight, the ISM and the Privacy Act; New Zealand buyers work to the Privacy Act 2020 and often follow CERT NZ guidance; regulated financial entities add APRA CPS 234 and PCI DSS v4.0. Findings map to the same 8 compliance reporting frameworks in reports either way, and that mapping is evidence for your assessors rather than a certification of your organisation.

Why does an Australian-built platform matter?

It decides where your findings are stored and who operates the infrastructure holding them. Scan results, captured evidence and reports describe your most sensitive systems, and on PentestOps they stay on Australian-hosted infrastructure run by an ISO/IEC 27001:2022 certified company. For public sector, health and financial services buyers that is often the deciding factor. See penetration testing in Australia for the full picture.

Ready to See PentestOps in Action?

Start a 7-day trial, run a free demo scan against a domain you own, or book a walkthrough with our security team.