PLDrop
Penetration Testing Through a Box You Post, Not a Person You Fly
PLDrop is a sealed appliance posted to the customer and plugged into their own network, where it becomes the single audited channel for penetration testing — internal, web, external, API and Wi-Fi. Every session opens only on the customer’s approval, lasts exactly as long as they allow, can be cut mid-session, and leaves a per-command, tamper-evident record in storage they own. The travel line leaves the invoice; the evidence line arrives in the audit file.
Key Features
Powerful features designed to solve your security and development challenges.
Consent Gate on Every Session
Nothing opens without the customer’s approval, for a lifetime they set, and a live session can be revoked mid-command. There is no standing access.
Dial-Out Only
The unit never exposes a port to the internet. It reaches out through an encrypted tunnel, so there is no inbound path for anyone else to find.
The Tester Works Inside a Sealed Workspace
The consultant gets one Linux workspace and the tools — and that is the whole of what they can reach. The uplink, the keys and the audit record sit outside it.
On-Device Supervision
A purpose-trained model on the device watches that workspace for an attempt to leave it, for work outside the agreed scope, and for data moving by volume or by class. Findings leave the unit; the traffic does not.
Tamper-Evident Record to Your Own Storage
Every command and transfer is hash-linked into a record written to the customer’s own S3 bucket. Remove a line and the record stops verifying.
Wireless Testing On Board
The hardware unit carries its own radio for Wi-Fi work — the one thing a software-only deployment cannot do. A virtual build covers everything that does not need a radio.
Key Benefits
Why organizations choose this solution
No flights, hotels or travel days on the testing invoice
The customer approves each session, sets its lifetime, and can cut it while it runs
A dated, per-command, tamper-evident record in the customer’s own storage
The tester is boxed in by design, and the box keeps watching after the engagement ends
Internal, web, external, API and Wi-Fi testing through one audited channel
Use Cases
Common scenarios where this solution excels
Recurring internal testing without hosting a consultant on site
Multi-site estates where travel is the real cost of the programme
Regulated teams that must evidence who was approved, by whom, and for how long
Organisations that will not let engagement data leave their own storage