We are a small US-based B2B SaaS startup. We have a core engineering team of four and run a single primary web application hosted in the cloud. To date, our security measures haven't gone much beyond basic code reviews and standard server configurations.
Last week we entered contract negotiations with a prospective enterprise client, and they're asking for an independent penetration testing report. Initial quotes from professional pen-testing firms came back between $5,000 and $8,000. Our budget is pretty tight, so the dev team is suggesting we spin up open-source or cheaper automated vulnerability scanners and run the tests ourselves first, arguing these tools are industry standard anyway.
How reliable are the results if we run our own tests using open-source or commercial automated scanners? How much time will we lose chasing false positives, and will enterprise clients even take an internally generated scan report seriously?