A scoped, time-boxed assessment against a defined surface. The most common engagement shape we run.
What’s in scope
- Web applications. Production-grade SPAs, APIs, and admin consoles.
- Mobile. Native iOS and Android binaries plus their backends (OWASP MASTG).
- REST & GraphQL APIs, covering auth-token replay, IDOR, and rate-limiting.
- Cloud configuration across AWS, GCP, and Azure (read-only review).
We do not test customer-leased on-premises hardware, third-party SaaS we don’t host, or anything you don’t have written authorization to test.
How it runs
Gray-box by default: you give us credentials and a staging environment, and we spend the first day in your repo orienting. Black-box engagements are available on request. They add roughly 30% to the timeline and may not reach the same depth, since we spend time rediscovering what gray-box access would have shown us up front.
Two-week minimum. Four-week typical. We file findings live in your tracker as we discover them, so your team can start fixing on day three instead of waiting for a final PDF.
What you walk away with
- A final report with an executive summary, technical detail, and remediation steps
- An attestation letter you can share with customers and auditors
- A re-test included, scheduled within 90 days
- The ability to reference us in your SOC 2 / ISO 27001 evidence
- A shared Slack channel with the lead tester during the engagement and while your team works through the fixes