You misunderstood. I'm not charging $600/hour, it's the other companies.
Pentest services basically involve ethical hackers attempting to hack your server/site and logging every step of the way. Whatever they find, they write down. Then you get a comprehensive report about your system security. You'd be surprised to know that EVERY single website has some kind of flaw, given enough time to look for one.
With the report, a client often gets a certificate which they can then show their clients to assure them of their data safety. Pentest services were mostly used by government sites, banks and big business sites but nowadays people are more and more interested in them, and for good reason - every little prick can hack a site using automated softwares.