Delivered remotely as software

No local office and no travel required. External testing needs no agent, and internal testing runs through an agent your own team installs.

Data is held in Australia

The platform runs on Australian infrastructure operated by Extranet Systems. Customer data is stored in Australia, not in New Zealand.

Proof, not guesswork

Confirmed findings are validated by safe automated exploitation, governed by signed Rules of Engagement and a full evidence trail.

Independently certified vendor

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A copy is available on request.

How PentestOps works in New Zealand

Start with the part most vendor pages bury. PentestOps does not have an office in New Zealand and does not employ staff there. The platform is built and operated by Extranet Systems Pty Ltd, an Australian company headquartered in Wollongong NSW, and New Zealand customers are served remotely as software. Nobody flies over, and nobody needs to.

That works because testing happens over the network rather than in a meeting room. External testing runs with no agent at all. Internal testing uses an on-premise agent your own team installs as a Docker container, RPM or DEB package in about 5 minutes, connecting outbound-only over TLS 443 with 0 inbound firewall rules and no VPN. One host can cover multiple subnets, which suits sites across both islands.

What you lose by not having a local vendor is someone who can sit in your building. What you gain is a platform you can start using the same day, without a procurement cycle, and a testing cadence that keeps running between assessments rather than arriving once a year. Decide which of those matters more to your programme before you shortlist.

Where your data goes, stated plainly

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. For a New Zealand organisation that means scan results, asset inventory, findings, evidence and reports relating to your estate are held outside New Zealand.

We flag this rather than leaving it in a schedule at the back of a contract, because it is a decision your privacy officer and your procurement team should make deliberately. The New Zealand Privacy Act 2020 governs how your organisation handles personal information, including when that information is held or handled overseas. We cannot give you legal advice about your own obligations, and we will not tell you the arrangement is automatically fine. Take your own advice, using the facts on this page and in our Trust Centre.

The supporting detail: Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. The platform is built to SOC 2-aligned controls, and a SOC 2 attestation is on our roadmap. Every customer runs in an isolated environment with its own dedicated database, data is encrypted at rest, traffic is protected with TLS in transit, and audit logs are retained for 365 days. You are the data controller and Extranet Systems is the data processor; a signable DPA is available to customers on request. Enterprise customers can request specific data-residency arrangements, or the on-premise deployment option that keeps scan data inside your own boundary.

What gets tested

Every engagement runs the same seven phases, grounded in PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement authorise each scan and each exploitation attempt, and scope enforcement stops anything that reaches outside the assets you listed.

  • Perimeter. 24+ external recon modules map the internet-facing surface, including services stood up years ago and never retired. See external network testing.
  • Internal network. With the on-premise agent in place, 18+ internal modules execute on the LAN itself rather than tunnelling every packet across the Tasman and back. See internal network testing.
  • Applications and APIs. REST and GraphQL coverage against OWASP Top 10 and API Top 10 risks, with findings streaming live during the scan.
  • Cloud. 800+ automated checks across AWS, Azure, GCP and M365 against CIS Benchmarks, plus an agentless Kubernetes audit run from a read-only kubeconfig.
  • Identity. Active Directory enumeration, credential testing and password-policy auditing establish what one ordinary account can reach once somebody else is using it.
  • Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV flags, which matters most when the entire security function is one or two people.

What drives testing for New Zealand organisations

New Zealand estates are often smaller than their Australian equivalents and just as exposed, run by a security team of one or two people wearing several other hats. The pressure to test usually arrives from outside: an insurer, a customer questionnaire, an Australian parent company, or an incident. Teams following CERT NZ advisories already know which exposures matter; what they lack is evidence of whether those exposures exist in their own estate today.

Testing does not make an organisation compliant with anything, and we will never say it does. What it supplies is technical evidence: what is reachable, what is exploitable, how far an attacker gets, and what to fix first.

New Zealand contextWhere testing usually starts
Organisations handling personal information under the Privacy Act 2020Which paths reach systems holding personal information, and how far an attacker gets before detection
Teams acting on CERT NZ advisories about exposed servicesPerimeter discovery with continuous re-checks, so an advisory can be answered with evidence rather than assumption
Merchants and payment platforms in scope for PCI DSS v4.0Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release
New Zealand subsidiaries of Australian groupsOne platform covering both sides of the Tasman, with consistent methodology and comparable reporting
Vendors answering enterprise security questionnairesFull-scope assessment with reports mapped to the frameworks the questionnaire asks about

Local compliance landscape

New Zealand's landscape is its own, and it is worth naming precisely. The New Zealand Information Security Manual (NZISM) sets the technical baseline for government agencies and the suppliers that serve them. The Privacy Act 2020 governs how any organisation handles personal information. CERT NZ publishes the advisories most local teams actually work from. None of the three is a certification, and none is satisfied by running a scan.

The material fact for a New Zealand buyer belongs at the front, not in a schedule: customer data is stored in Australia, not in New Zealand. For an NZISM-scoped agency or a privacy officer applying the Privacy Act 2020, that is the first thing to weigh. It is also worth knowing that NZISM, the Privacy Act 2020 and CERT NZ guidance are not among the 8 frameworks PentestOps maps findings to in reports. We supply technical evidence; the compliance judgement stays with you and your advisers.

New Zealand instrumentWho it reachesWhat testing can evidence
New Zealand Information Security Manual (NZISM)Government agencies and the suppliers that build, host or operate their systemsExposed services, weak configuration and hardening gaps on in-scope systems, with evidence attached. Note that customer data is stored in Australia
Privacy Act 2020Any organisation handling personal information about New ZealandersWhich reachable paths lead to systems holding personal information, and how far an attacker gets before detection
CERT NZ advisoriesAny team acting on published guidance about exposed or actively exploited servicesWhether an advisory applies to your estate today, answered with perimeter evidence instead of assumption
Cross-border hosting reviewPrivacy officers and procurement teams assessing an Australian platformThe documented facts to assess: data stored in Australia, an ISO/IEC 27001:2022 certified processor, encryption at rest, TLS in transit, 365-day audit logs and a signable DPA

Getting started from New Zealand

There is no onshore onboarding process to wait for. You can authorise scope, add assets and run a real scan the same day you sign up, then expand scope from there. See continuous penetration testing for how the ongoing cadence works once the first assessment is done.

  • Authorise the scope. Sign the Rules of Engagement covering assets you own or are authorised to test. Scope enforcement stops activity outside them automatically.
  • Add assets. A public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster each count as one asset. Bulk CSV or XLSX import is available for larger estates.
  • Run the perimeter first. External testing needs no agent, so you see the internet-facing surface before touching the internal network.
  • Deploy the agent for internal scope. Docker, RPM or DEB, about 5 minutes, outbound-only over TLS 443. See the agent.
  • Set a cadence. Scheduled scans, continuous perimeter re-checks and drift detection keep coverage current between assessments.

Being honest about the trade-off

If your organisation has a firm requirement that security data stay onshore in New Zealand, our standard offering does not meet it, and we would rather tell you now than three meetings in. Enterprise customers can discuss specific data-residency arrangements or the on-premise deployment option with us; anything else is a conversation, not a checkbox.

If cross-Tasman hosting works for your risk position, the trade generally favours you: an ISO/IEC 27001:2022 certified vendor, asset-wise pricing with scans unlimited within fair use, exploit-validated findings rather than a severity list, AI analysis that is self-hosted by default so scan data is not sent to third-party model providers, and reports mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes.

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. New Zealand time runs ahead of that clock, so the earliest part of your morning sits outside standard hours. Scans, alerts and reporting run regardless.

Company and contact details

For the procurement file: PentestOps is a product of Extranet Systems Pty Ltd, an Australian company with ABN 29 632 743 189, headquartered at 77 Market Street, Wollongong NSW 2500. There is no New Zealand office and no New Zealand-based staff, so the contact number is the Australian one, +61 1300 290 196, or reach us through contact.

Frequently Asked Questions

Do you have an office in New Zealand?

No. PentestOps is built and operated by Extranet Systems Pty Ltd in Australia, and we have no New Zealand office and no New Zealand-based staff. New Zealand customers are served remotely as software. We list every office we have and never claim ones we do not.

Where is our data stored?

In Australia. The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. For a New Zealand organisation that means your scan data, findings, evidence and reports are held outside New Zealand. We state that plainly so your privacy and procurement teams can assess it properly rather than discovering it in a contract schedule.

Can we get data residency in New Zealand?

Not as a standard offering. The platform runs on Australian infrastructure. Enterprise customers can request specific data-residency arrangements, and Enterprise also includes an on-premise deployment option that keeps scan data inside your own boundary. If onshore hosting is a hard requirement, raise it in the first conversation via contact so we can tell you quickly whether we can meet it.

Does the New Zealand Privacy Act 2020 allow us to use an Australian platform?

That is a question for your privacy officer and your own legal advisers, not for a vendor page, and we will not tell you the answer is automatically yes. What we can give you is the factual basis for the assessment: data stored in Australia, an ISO/IEC 27001:2022 certified processor, encryption at rest and TLS in transit, isolated per-customer environments, 365-day audit logs, and a signable DPA under which you are the data controller and Extranet Systems is the data processor.

Does anyone need to travel to New Zealand to run a test?

No. Testing runs over the network. External assessment needs no agent at all, and internal assessment uses an on-premise agent that your own team installs in about 5 minutes. Scoping, briefings and report walkthroughs happen remotely.

Can you test our internal network without firewall changes?

Yes. The agent connects outbound-only over TLS 443 through a reverse tunnel, so 0 inbound firewall rules are required. It has no inbound listeners, supports HTTP CONNECT through restrictive corporate proxies and reconnects automatically after a link drop. Discovered credentials are redacted before findings ship, so they never leave your network in plaintext.

Does this replace an independent penetration test?

No. For a small New Zealand security team the honest split is that the platform carries the repetitive, high-volume work continuously, while a skilled tester carries the judgement work: business logic flaws, process abuse and the creative attacks automation handles poorly. Keep the periodic independent assessment and let PentestOps hold the line between them.

What support hours apply to New Zealand customers?

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. New Zealand time is ahead of AEST, so the earliest part of your morning falls outside standard hours, while the rest of the working day overlaps. Scheduled scans, alerts and reporting run continuously regardless of support hours.

How is it priced in New Zealand, and can we try it first?

Pricing is asset-wise: one asset is one item the platform can scan or monitor, such as a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Scans against an asset are unlimited within fair use. Run a free demo scan at demo scan, then start a trial when you are ready. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first. Live plan detail is on pricing.

Test your New Zealand estate from day one

Begin at the perimeter, bring the internal network in once the agent is installed, then hold the cadence between assessments. If cross-Tasman hosting needs discussing first, call +61 1300 290 196. All paid plans start with a 7-day free trial, and a card is required to start your trial and is only charged after the trial ends, unless you cancel first.