A vulnerability scan of your website is not a penetration test of it.
Most "website pentests" sold cheaply are automated scans with a PDF wrapper. They find outdated libraries and missing headers. They don't find broken authentication, IDOR, privilege escalation, or business-logic flaws — the vulnerabilities that actually lead to a breach on a web application. This engagement is manual testing of your website or web app's actual functionality, not just its infrastructure.