Application security assessment: the usable version
An application security assessment should rank what a signed-in user can abuse. Here is the scoped version product teams can finish in a week.
Procurement likes the phrase application security assessment. Engineering likes a PDF they can ticket.
Those are not the same purchase unless you force them to be.
Short answer: I sell a timeboxed web application security review that is an application security assessment of one live app: $2,400, $1,200 to start, written in 48 hours after access, one free retest.
What an assessment should produce
A snapshot of the surface, findings ranked by severity, evidence without payloads, remediations a developer can ship, and restored test state. That format is in the sample report.
It should not produce a 90-page appendix of unused CVE banners.
What I assess
Frontend and session. Auth and identity. The APIs the UI already calls, plus the obvious neighbors — missing auth, object access that ignores ownership, upload and export paths.
Source review is a second quote. Two apps are two prices.
See the offer on the security page and pricing.
FAQ
What is an application security assessment? +
A structured look at how an application behaves under authorized testing. On a web product that means UI, session, and API — written findings, not a scanner dump.
How is it different from a pentest? +
Buyers use the words for the same job. Firms that sell a two-week CREST engagement are selling a different calendar and stamp.
What does one cost? +
A focused single-app assessment can be $2,400. Boutique letters often start at $5,000–$15,000.