Being clear about what this service is not is part of doing it responsibly. Penetration testing at Appsierra is security assessment work delivered by our engineering pods, alongside our QA and security testing practice. It is technical testing, reporting and remediation support. It is not a formal compliance audit, and it does not produce a certificate.
Where a scheme, regulator or customer requires an accredited third-party assessor — a formal certification audit, or an assessment that only a qualified assessor may sign — that assessor must be the accredited party. In those programmes we work alongside them: supplying test evidence, closing the technical findings and retesting the fixes, rather than replacing the assessor's role. Appsierra does not issue compliance certificates and does not attest a client's compliance status.
The same boundary runs the other way. Our cloud infrastructure testing is reliability and correctness validation: a configuration policy check can confirm encryption is enabled, but it is not a security assessment. Penetration testing is the assessment that actively attempts to exploit what is there.