Authorized web app review: why the permission email matters
An authorized web app review starts with written permission and a URL you own. That is what separates a professional review from reckless scanning.
An authorized web app review is not a vibe. It is a sentence in writing: you own this URL, you want it tested, these roles are in, these systems are out.
I will not start without that. Neither should anyone you hire.
Short answer: Pay $1,200 to start a security review only after you can authorize the work. The remaining $1,200 is due on the report. Clock starts when access works.
What I need in the note
Target URL. Environment (prod or staging). Roles. Out-of-scope neighbors. A window. A name that can actually authorize.
Stripe checkout on the offer page asks for the URL and a confirmation you can authorize. That still does not start the clock.
What I will not do
Surprise-scan a linked vendor. Guess a sister tenant. Keep exploit recipes in the PDF. A sample shows the tone.
FAQ
What makes a review authorized? +
Written permission from someone who owns or controls the target, plus a defined URL, roles, and out-of-scope notes.
When does the 48-hour clock start? +
When login works — not when you pay the $1,200 start and not when the first email arrives.
Can I authorize staging only? +
Yes. Staging is often cleaner. Say so in writing. Production needs extra care around real customers.