Assessments
Find out before someone else does.
Five ways to have an application tested. Every one is quoted against a scope agreed with you first.
Start here
Which one of these is you?
You do not have to know what to ask for.
-
Nothing has ever been tested
Start with the Automated Assessment.
-
I am about to launch an MVP
Start with the Launch Check.
-
I have an application in production
That is the Application Pentest.
-
It handles money or sensitive records
Look at the Deep Dive.
-
None of these describe it
That is a Custom scope, and it starts with a conversation.
Still not sure?
The five
How much of the application gets taken apart.
The first tier is where a tool can reach. From the second up, the difference is how much of the application we exhaust rather than sample.
-
Automated Assessment
Nothing has ever been tested, and you want to know where you stand.
Automated coverage of the application and the API behind it, with every result verified by a tester before it reaches you.
What is covered
- Automated coverage of the application and the API behind it
- Known vulnerabilities in components and dependencies
- Missing or misconfigured security controls and headers
- Files, directories and endpoints exposed that should not be
- The input handling and injection classes tooling can reach
What a tool will not find is the logic: it does not know which endpoint was supposed to check the caller's role, or that one customer can read another's invoices. If that is the risk you are carrying, the manual tiers are the ones that answer it, and we will say so.
-
Launch Check
You built something, and you are about to put real users on it.
A short, focused test of a small application before it goes live.
What is covered
- Authentication, sessions, and account recovery
- Whether one account can reach another account's data
- The API behind the interface, called directly
- Input handling on the paths that carry the risk
- The client-side exposure that is worth the time
Scoped for an MVP: one product, a handful of roles. A day buys depth on the things most likely to be wrong, not coverage of everything. If your application needs more, we will say so before we start.
-
Application Pentest
Real users, real data, and a reason to be sure.
Your application and the APIs behind it, worked through by hand: role by role, feature by feature.
What is covered
- Authentication, authorisation and role separation
- Access control across accounts and across tenants
- The API surface, including the methods the front end never calls
- Business logic: your rules on limits, sequences, prices and ownership
- Input handling and injection
- Client-side security where the application puts trust there
What gets tested is agreed before anything starts. Not every category above applies to every application, and we would rather spend the days where the risk is than tick all of them.
-
Deep Dive
If this application is compromised, it is not an inconvenience.
For applications where money moves, records are sensitive, or something in there can act on a customer's behalf.
What is covered
- Multi-role and multi-tenant authorisation, worked through rather than spot-checked
- Payment, billing and anything else that moves money
- Privileged and administrative functionality
- The API estate, including what one service will do on behalf of another
- Business logic and state, driven the ways the design does not expect
- AI components: what the model can reach, and what it may do with it
Scope here is built for the application rather than taken off a list, so this one starts with a conversation. Ten days is where it begins; how far past that it goes depends on what we find.
-
Custom
It does not fit in a box.
Several applications at once, a very large API, an AI agent that can act on its own, or something that needs a plan rather than a package.
What this means
If it turns out one of the tiers above is the right answer, we will point at it instead of building something bigger.
A day means a day of one tester's time, not a day on the calendar. The counts above are where each tier starts. We look at the application first, then quote.
Deliverable
A report your engineers can work from.
Every finding: what we found, how to reproduce it, what it would cost you, and what to change. Ranked, so there is a queue to work through.
What you will not get, at any tier, is a scanner export with the false positives left in. Every result is confirmed by hand first.
Want to see what a finding looks like?
Why now
Build fast. Test before you ship.
A working product exists in weeks now. None of that tells you whether it holds up when someone attacks it. A model does not know which endpoint was supposed to check the caller's role, and the framework was never asked.
Need to make the case internally?
Retesting
Fix it. We'll check.
Your engineers close the findings, and we go back at them to confirm they are actually closed.
-
Within 15 days
Included. Fix the findings, tell us they are in, and we verify them.
-
Days 16 to 30
The same findings, at 50% of the original assessment price.
-
After 30 days
Usually a new assessment. By then the application has moved on.
Want the terms in full?
Not sure which one you need?
Describe the application and what it would cost you if the wrong person got in.