tencent cloud

PTS

Download
Focus Mode
Font Size
Last updated: 2026-08-13 16:43:54
AI-Translated
This document describes the billing methods for PTS (Penetration Test Service).

Service Description

PTS includes Web penetration testing, WeChat mini-program penetration testing, App penetration testing, and binary penetration testing. The features of these services are compared in the following table.
Service Category
Feature Details
Service Type
Website Type Determination
Web Penetration Testing
Provides PTS for users' critical business systems. Simulates attack and vulnerability discovery techniques that hackers might use to conduct penetration testing and security validation on target information systems.
Class I
A showcase website: primarily displays a company's image, brand, and other information. For example, a company's official website.
Marketing websites: they are commonly found among most small and medium-sized enterprises or individuals. For example, cosmetic surgery websites that are solely for promotional purposes.
Class II
Functional websites: for example, novel websites, movie websites, online education features, live streaming features, logistics information queries, and train ticket booking.
Service-oriented websites: they provide service queries and feature login/registration and interactive capabilities.
Forum websites: they provide a membership system and features such as posting, uploading/downloading, and sharing materials.
Portal websites: they primarily provide informational content, including comprehensive portals.
Backend management systems, operation platforms, monitoring systems, and others.
Class III
Transactional websites: they primarily provide online transactions, are mostly e-commerce websites, and offer recharge and transaction features.
Self-built employee OA systems and settlement systems.
WeChat Mini Program Penetration Testing
Performs security testing on WeChat Mini Programs, identifies potential security vulnerabilities and defects, and provides remediation recommendations.
Class I
Functional: such as interactive features, corporate showcases, and daily needs that do not involve recharge transactions or point redemption, for example, health code mini programs.
Class II
Transactional: primarily provides the feature of online transactions, such as e-commerce, hotel booking, online ordering, and service reservation.
App Penetration Testing
Performs security testing on mobile App programs, identifies potential security defects, and provides security test reports and improvement recommendations. Currently testable mobile App programs include: Android, iOS.
Class I Client
Functional: such as apps for interactive features, corporate showcases, and daily needs that do not involve recharge transactions or point redemption.
Class II Client
Financial Transaction: apps that involve recharge transactions or financial and economic activities.
Class I Server
Functional: such as apps for interactive features, corporate showcases, and daily needs that do not involve recharge transactions or point redemption.
Class II Server
Financial Transaction: apps that involve recharge transactions or financial and economic activities.
Binary Penetration Testing
Performs security testing on PC client binary applications (EXE, and so on), identifies potential security defects, and provides security test reports and improvement recommendations.
Class I Client
Functional: such as binary programs for interactive features, corporate showcases, and daily needs that do not involve recharge transactions or point redemption.
Class II Client
Financial Transaction: binary programs that involve recharge transactions or financial and economic activities.
Class I Server
Functional: such as binary programs for interactive features, corporate showcases, and daily needs that do not involve recharge transactions or point redemption.
Class II Server
Financial Transaction: binary programs that involve recharge transactions or financial and economic activities.

Billing Overview

PTS is primarily calculated based on the number of applications or modules tested.
Currently, Tencent Cloud can provide testing for Web applications, mini programs, apps, and binary systems. The specific pricing rules are shown in the table below:
Service Category
Service Type
Restriction
Billing Unit
Price Excluding Tax (USD/Time)
Web Penetration Testing
Class I
Static pages lack registration/login features and post-login personal center features.
Number of APIs ≤ 50
A regular business for one second-level domain
6,814
Class II
It features relatively complex logic but does not involve operations such as recharge or transactions.
Number of APIs ≤ 60
One second-level domain with complex logic.
11,357
Class III
Transactional websites, OA systems, settlement systems, and others. (If test accounts are not provided and only peripheral testing is conducted, orders can be placed under Category II.)
Number of APIs ≤ 80
One second-level domain that is a large-scale website.
18,171
WeChat Mini Program Penetration Testing
Class I
No features such as recharge, transactions, or point redemption.
If you need to test the management backend, purchase the business system PTS separately.
One regular mini program
6,814
Class II
If you need to test the management backend, purchase the business system PTS separately.
For multiple roles such as Merchant Edition and Courier Edition, a simple package must be added per role.
One mini program with transaction business/multiple roles/a management console
11,357
App Penetration Testing
Class I Client
No features such as recharge, transactions, or point redemption.
Only for the App client.
≤ 200 MB
Class I Regular App Client - 200M
6,814
Class II Client
Involving features such as recharge, transactions, and point redemption.
Only for the App client.
≤ 200 MB
Class II Financial Transaction App Client - 200M
9,086
Class I Server
No features such as recharge, transactions, or point redemption.
Number of APIs ≤ 50
Class I Regular App Server - 50 APIs
4,543
Class II Server
Involving features such as recharge, transactions, and point redemption.
Number of APIs ≤ 50
Class II Financial Transaction App Server - 50 APIs
6,814
Binary Penetration Testing
Class I Client
No features such as recharge, transactions, or point redemption.
Only for the binary program client.
≤ 200 MB
Class I Regular Binary Client - 200M 
6,814
Class II Client
Involving features such as recharge, transactions, and point redemption.
Only for the binary program client.
≤ 200 MB
Class II Financial Transaction Binary Client - 200M
9,086
Class I Server
No features such as recharge, transactions, or point redemption.
Number of APIs ≤ 50
Class I Regular Binary Server - 50 APIs
4,543
Class II Server
Involving features such as recharge, transactions, and point redemption.
Number of APIs ≤ 50
Class II Financial Transaction Binary Server - 50 APIs
6,814
Attention:
If the system types and restrictions listed above do not meet your actual requirements, you can contact us. After a reasonable assessment, we will provide you with a quotation.

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback