Last Updated: June 24, 2026
The Synack Platform: A Guide to Key Features and Benefits
The Synack Platform: Penetration Testing Product Offerings
Sara Pentest/
Sara Pentest+
SynackST/ST+
Penetration Test
SYNACK14
Penetration Test
SYNACK90
Continuous Penetration Testing
SYNACK365
Continuous Penetration Testing
API
Assessment Window
2-3 days
ST: 5 days
ST+: 5-10 days
14 days
90 days
365 days
Varies based on quantity in-scope endpoints
Test Methodology
Open Vulnerability Discovery
Guided checklist-based assessment
Open Vulnerability Discovery
Open Vulnerability Discovery
Open Vulnerability Discovery
Headless API endpoint testing and reporting
Smartscan
Yes
No
Yes
Yes
Yes
N/A
Testers
AI agent driven
Assigned researcher
Pool of researchers
Rotating pools of researchers
Rotating pools of researchers
Pool of researchers
Asset Types
External Web or Host
Web or Host
Web, Host, Mobile, or LLM/AI
Web, Host, Mobile, or LLM/AI
Web, Host, Mobile, or LLM/AI
Headless API
Detailed Pentest Report
Yes*
Yes*
Yes
Yes
Yes
Yes
Industry Standards Testing
Optional Add-on checklists (OWASP, NIST 800-53)
OWASP checklist
Optional Add-on checklists (OWASP, NIST 800-53)
Optional Add-on checklists (OWASP, NIST 800-53)
Includes 2 Premium Checklists (OWASP, NIST 800-53)
Proof of coverage report included
The Synack Platform: Key Features and Benefits
Synack Basic Platform
Synack Security Testing Platform
Self-Service Discovery of New Assets for 30 Days
Seed Groups to Help Organize Assets and Control Access
Limited Discovery of Assets to Surface Testing Candidates
Discovered Asset Reporting Dashboard
Tracking for Researcher Testing Hours
Real-Time Reporting on Exploitable and Suspected Vulnerabilities
Attacker Resistance Score
Track holistic security performance overtime with a risk scoreCoverage Analytics
Testing Data History & Retention
Asset List That Catalogs All Tested Assets
Fingerprinting of External Assets to Inform Further Testing
Asset Details Highlighting Previous Testing Results
Synack API
Synack Basic Integrations (Jira, ServiceNow, Microsoft, Splunk, etc.)
Researcher Vetting
Proactive Researcher Rotation
Access to Researchers and Vulnerabilities
Fully Managed Researcher Payouts
Single Sign-On (SSO) Integration (SAML 2.0)
Role-Based Access Control (RBAC)
Self-Service Pentest Creation
Al Scoping Bot
Pause Testing at the Click of a Button
Synack-Owned Virtual Security Researcher Workspaces
Enhanced Security with Testing Data Stored in Synack-Owned Endpoints
Data Cleansing Available on Customer’s Request
Exploits Requiring Callbacks
Synack Command and Control Infrastructure to Contain Traffic Stemming from Exploits Requiring Callbacks
Active Communication with Researchers (SRT Chat)
Patch Verification (PV)
Synack On-Demand Security Testing Catalog Access
Internal and External Testing
Number of VPN Connections
3, Add-ons available
Proactive Identification of Test Issues
Customer Success Personnel
Self-Service
Pooled CSS
The Synack Platform: Add-Ons
Vulnerability Disclosure Program Webform
Triage for 200 Vulnerability Submissions Per a Year (Each Additional Submission Is 1 Credit)
Synack will triage vulnerabilities the public submits through your programExternal Researcher Management
Synack will manage relationships with members of the public that submit vulnerabilitiesReal-Time Reporting
Synack provides a client portal for customers to view vulnerability data and generate PDF reportsNot available in FedRAMP
Self-Service Discovery of New Assets for 365 Days
Seed Groups to Help Organize Assets and Control Access
Weekly Discovery of Assets to Surface Testing Candidates
Discovered Asset Reporting Dashboard
Not available in FedRAMP
Includes 100 AI-Powered Vulnerability Exploit Validations (Each additional set of 10 triaged vulnerabilities requires 1 credit)
Threat Intelligence Integration
Human Validation of Exploitable Risks
On-Demand SRT Capacity


