PLDrop

Penetration Testing Through a Box You Post, Not a Person You Fly

PLDrop is a sealed appliance posted to the customer and plugged into their own network, where it becomes the single audited channel for penetration testing — internal, web, external, API and Wi-Fi. Every session opens only on the customer’s approval, lasts exactly as long as they allow, can be cut mid-session, and leaves a per-command, tamper-evident record in storage they own. The travel line leaves the invoice; the evidence line arrives in the audit file.

Penetration TestingSecurity ApplianceZero RetentionAudit Trail

Key Features

Powerful features designed to solve your security and development challenges.

Consent Gate on Every Session

Nothing opens without the customer’s approval, for a lifetime they set, and a live session can be revoked mid-command. There is no standing access.

Dial-Out Only

The unit never exposes a port to the internet. It reaches out through an encrypted tunnel, so there is no inbound path for anyone else to find.

The Tester Works Inside a Sealed Workspace

The consultant gets one Linux workspace and the tools — and that is the whole of what they can reach. The uplink, the keys and the audit record sit outside it.

On-Device Supervision

A purpose-trained model on the device watches that workspace for an attempt to leave it, for work outside the agreed scope, and for data moving by volume or by class. Findings leave the unit; the traffic does not.

Tamper-Evident Record to Your Own Storage

Every command and transfer is hash-linked into a record written to the customer’s own S3 bucket. Remove a line and the record stops verifying.

Wireless Testing On Board

The hardware unit carries its own radio for Wi-Fi work — the one thing a software-only deployment cannot do. A virtual build covers everything that does not need a radio.

Key Benefits

Why organizations choose this solution

No flights, hotels or travel days on the testing invoice

The customer approves each session, sets its lifetime, and can cut it while it runs

A dated, per-command, tamper-evident record in the customer’s own storage

The tester is boxed in by design, and the box keeps watching after the engagement ends

Internal, web, external, API and Wi-Fi testing through one audited channel

Use Cases

Common scenarios where this solution excels

Recurring internal testing without hosting a consultant on site

Multi-site estates where travel is the real cost of the programme

Regulated teams that must evidence who was approved, by whom, and for how long

Organisations that will not let engagement data leave their own storage

Technologies We Use

Sealed field applianceDial-out encrypted tunnelSession approval and revocationOn-device anomaly detectionHash-linked audit recordCustomer-owned S3 storage

Ready to Get Started?

Contact us today to discuss your project needs and receive a custom proposal with security expertise built in.