Primary package
Outside-in Web Assessment
Authorized assessment of one production app from the outside — validated findings with evidence, not an orientation memo.
Fixed package after short scope confirmation. Price is confirmed on the scoping call — not published here.
Recommended baseline scope
- 1 production application and up to 3 related public hostnames
- Unauthenticated public web; public APIs only if listed in scope
- 3–5 working days of assessment work after authorization and readiness
- Prioritized technical report and executive summary
- Remediation discussion and one bounded retest
You receive
- Evidence-backed findings with severity
- Business-readable priorities and fix guidance
- A short remediation discussion
- One bounded retest when agreed fixes land
Not included (upgrade or out of scope)
- Authenticated testing with client-provided accounts
- Multi-role or workflow abuse testing
- Source-code review or design walkthroughs
- Cloud-account or internal infrastructure assessment
- Social engineering
- Denial-of-service or destructive testing
- Extra applications beyond the agreed package
- Large or unlisted API estates
What happens
- Scoping call and written authorization (rules of engagement)
- Isolated assessment of the agreed public surface
- Evidence review and clear reporting
- Remediation discussion, then one bounded retest
One bounded retest is included when fixes land within 30 days of delivery. Extra retests or ongoing coverage are scoped separately.
