Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.
Typical scope
- Web applications and single-page front ends
- REST, GraphQL and gRPC APIs
- Internal and external network infrastructure
- Cloud configuration and identity boundaries
- Mobile applications (Android, iOS)
- Authentication, session and multi-tenancy logic
You receive
- Findings report with severity, business impact and CVSS v4 vector per issue
- Reproduction steps and a working proof of concept for every finding
- Remediation guidance written for the engineers who own the code
- Executive summary suitable for board or customer distribution
- Retest and a reissued report once fixes ship — included in the original price

