Web application penetration testing
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
An external security check of one website, free of charge, with a report that is paid only when vulnerabilities are found.
Application security
Most owners do not know whether their website can be broken into until it happens. A penetration test answers that question in depth, but it is a project with a budget. The free check is the first step: it shows whether an attacker who knows nothing about you finds a way in.
We look at the website from the outside, without accounts and without access to your server, and check what is visible and reachable from the internet. If we find nothing, you receive a report that says so, free of charge. If we find vulnerabilities, we tell you how many there are and how serious they are, and you decide whether to buy the report with the details and the fixes.
01Scope
02Approach
You name the website and confirm that you own it or act for its owner. Before the check starts, the owner, or a person the owner has authorised, signs an authorisation that lists the address and the dates of the check.
Tools map the website, and specialists verify every suspicion by hand and discard false alarms. There are no destructive actions, no load tests and no attempts to read the data of your visitors.
You receive the result in 1 to 5 business days after the authorisation is signed. No vulnerabilities: the report is free of charge. Vulnerabilities found: a notice with their number, their severity on the CVSS 4.0 scale and the price of the report.
You receive the report immediately after payment: every finding with evidence, steps to reproduce it and a fix. Once the fixes are in place, we retest every finding free of charge.
03
04
05Standards
Test cases for web applications and APIs.
OWASP Foundation
The most critical risks of web applications; a minimum, not a method.
OWASP Foundation
Severity score and vector of every finding.
FIRST
Class of weakness behind every finding.
The MITRE Corporation
06Questions
Because we are paid for a result. A website without vulnerabilities costs its owner nothing; a website with vulnerabilities gives us a report that is worth buying. It is the principle of bug bounty, applied to your website with your permission.
Then you owe nothing. What we found stays confidential: we pass it to no one and publish nothing.
By the number of the findings and their severity on the CVSS 4.0 scale. The price is stated in the notice, before you decide, and stays valid for 30 days.
No. The check is done from the outside, the way a visitor sees the website. Testing with accounts and roles is a separate service, web application penetration testing.
The check contains no destructive actions and no load tests. If the website becomes unstable, we stop and contact you.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.