Skip to product information
Web Application Pentest - Baseline
€4.295,00
Fixed price. Fixed scope. No sales call. A manual, authenticated penetration test of one web application: the right fit for a first SOC 2, ISO 27001 or customer-questionnaire pentest.
Scope included
- 1 web application (single primary domain) including its backend API
- Up to 2 user roles tested (e.g. regular user and admin)
- Up to 30 API endpoints / dynamic pages
- Estimated effort: 4 tester-days
What we test
- OWASP Top 10 and OWASP API Security Top 10
- Authentication, session management and access control between the two roles
- Business-logic flaws specific to your application
- Input handling: injection, XSS, SSRF, file upload
Deliverables
- PDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)
- Letter of attestation you can share with auditors and customers
- Critical findings reported to you immediately, not at the end of the test
Not included
- Retest of findings: add a Separate Retest ($1,499), or choose Extended/Comprehensive where a free retest is included
- Social engineering / phishing, denial-of-service, physical testing
- Mobile apps, infrastructure/network testing, source-code review
If we discover during kick-off that your application is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.