{"title":"Web Application Pentests","description":"\u003cp\u003eFixed-price manual penetration tests for web applications and their APIs. Three tiers, scope written down, no sales call.\u003c\/p\u003e","products":[{"product_id":"entry-pentest","title":"Web Application Pentest - Baseline","description":"\u003cp\u003e\u003cstrong\u003eFixed price. Fixed scope. No sales call.\u003c\/strong\u003e A manual, authenticated penetration test of one web application: the right fit for a first SOC 2, ISO 27001 or customer-questionnaire pentest.\u003c\/p\u003e\n\u003ch3\u003eScope included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e1 web application (single primary domain) including its backend API\u003c\/li\u003e\n\u003cli\u003eUp to 2 user roles tested (e.g. regular user and admin)\u003c\/li\u003e\n\u003cli\u003eUp to 30 API endpoints \/ dynamic pages\u003c\/li\u003e\n\u003cli\u003eEstimated effort: 4 tester-days\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eWhat we test\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOWASP Top 10 and OWASP API Security Top 10\u003c\/li\u003e\n\u003cli\u003eAuthentication, session management and access control between the two roles\u003c\/li\u003e\n\u003cli\u003eBusiness-logic flaws specific to your application\u003c\/li\u003e\n\u003cli\u003eInput handling: injection, XSS, SSRF, file upload\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDeliverables\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)\u003c\/li\u003e\n\u003cli\u003eLetter of attestation you can share with auditors and customers\u003c\/li\u003e\n\u003cli\u003eCritical findings reported to you immediately, not at the end of the test\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eNot included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRetest of findings: add a \u003ca href=\"\/products\/retest-fix-verification\"\u003eSeparate Retest ($1,499)\u003c\/a\u003e, or choose Extended\/Comprehensive where a free retest is included\u003c\/li\u003e\n\u003cli\u003eSocial engineering \/ phishing, denial-of-service, physical testing\u003c\/li\u003e\n\u003cli\u003eMobile apps, infrastructure\/network testing, source-code review\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cem\u003eIf we discover during kick-off that your application is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.\u003c\/em\u003e\u003c\/p\u003e","brand":"fasttrack pentest","offers":[{"title":"Default Title","offer_id":64665643450745,"sku":"FT-WEB-T1","price":4899.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1039\/6100\/2361\/files\/ft2-web-1.svg?v=1790334619"},{"product_id":"web-application-pentest-extended","title":"Web Application Pentest - Extended","description":"\u003cp\u003e\u003cstrong\u003eFixed price. Fixed scope. No sales call.\u003c\/strong\u003e A manual, authenticated penetration test of one web application and its API, for teams with multiple user roles or a larger feature surface.\u003c\/p\u003e\n\u003ch3\u003eScope included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e1 web application (single primary domain) including its backend API\u003c\/li\u003e\n\u003cli\u003eUp to 4 user roles tested, including privilege-escalation between roles\u003c\/li\u003e\n\u003cli\u003eUp to 75 API endpoints \/ dynamic pages\u003c\/li\u003e\n\u003cli\u003eEstimated effort: 6 tester-days\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eWhat we test\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOWASP Top 10 and OWASP API Security Top 10\u003c\/li\u003e\n\u003cli\u003eAuthentication, session management and access control (IDOR, horizontal\/vertical escalation)\u003c\/li\u003e\n\u003cli\u003eBusiness-logic flaws specific to your application\u003c\/li\u003e\n\u003cli\u003eInput handling: injection, XSS, SSRF, file upload\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDeliverables\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e1 free retest within 45 days\u003c\/strong\u003e of the final report: we verify your fixes and issue an updated report\u003c\/li\u003e\n\u003cli\u003eLetter of attestation you can share with auditors and customers\u003c\/li\u003e\n\u003cli\u003eCritical findings reported to you immediately, not at the end of the test\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eNot included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSocial engineering \/ phishing, denial-of-service, physical testing\u003c\/li\u003e\n\u003cli\u003eMobile apps, infrastructure\/network testing, source-code review\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cem\u003eIf we discover during kick-off that your application is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.\u003c\/em\u003e\u003c\/p\u003e","brand":"fasttrack pentest","offers":[{"title":"Default Title","offer_id":64701194043769,"sku":"FT-WEB-T2","price":7199.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1039\/6100\/2361\/files\/ft2-web-2.svg?v=1790334620"},{"product_id":"web-application-pentest-comprehensive","title":"Web Application Pentest - Comprehensive","description":"\u003cp\u003e\u003cstrong\u003eFixed price. Fixed scope. No sales call.\u003c\/strong\u003e Our most thorough web application test, for multi-tenant SaaS platforms and applications with complex role models, payment flows or extensive APIs.\u003c\/p\u003e\n\u003ch3\u003eScope included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e1 web application (single primary domain) including its backend API\u003c\/li\u003e\n\u003cli\u003eUp to 6 user roles tested, including privilege-escalation between roles\u003c\/li\u003e\n\u003cli\u003eUp to 150 API endpoints \/ dynamic pages\u003c\/li\u003e\n\u003cli\u003eMulti-tenant isolation testing (tenant-to-tenant data access)\u003c\/li\u003e\n\u003cli\u003eEstimated effort: 7 tester-days\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eWhat we test\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOWASP Top 10 and OWASP API Security Top 10\u003c\/li\u003e\n\u003cli\u003eAuthentication, SSO\/OAuth flows, session management and access control\u003c\/li\u003e\n\u003cli\u003eBusiness-logic flaws, including payment and workflow abuse\u003c\/li\u003e\n\u003cli\u003eInput handling: injection, XSS, SSRF, file upload, deserialization\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDeliverables\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e1 free retest within 90 days\u003c\/strong\u003e of the final report: we verify your fixes and issue an updated report\u003c\/li\u003e\n\u003cli\u003eLetter of attestation you can share with auditors and customers\u003c\/li\u003e\n\u003cli\u003eCritical findings reported to you immediately, not at the end of the test\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eNot included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSocial engineering \/ phishing, denial-of-service, physical testing\u003c\/li\u003e\n\u003cli\u003eMobile apps, infrastructure\/network testing, source-code review\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cem\u003eLarger than this? Buy an additional tier for a second application, or email us and we'll reply with a fixed price, not a sales call.\u003c\/em\u003e\u003c\/p\u003e","brand":"fasttrack pentest","offers":[{"title":"Default Title","offer_id":64701195321721,"sku":"FT-WEB-T3","price":8699.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1039\/6100\/2361\/files\/ft2-web-3.svg?v=1790334620"}],"url":"https:\/\/fasttrackpentest.com\/collections\/web-application-pentests.oembed","provider":"fasttrack pentest","version":"1.0","type":"link"}