Frontend and session
Pages, forms, uploads, tokens, cookies, and what a signed-in user can reach that they should not. I work as a real user, then as a slightly more privileged one if you grant a second role.
Buyers search “penetration test.” What most product teams actually need is an authorized review of the live app: login, roles, the pages a user can see, and the APIs behind them. I test those surfaces, rank what I find, and send a report you can hand to engineering the same week.
$2,400 per application. Half to start, half when the report lands. Clock starts when written scope and working credentials are in. One free retest of the same URL within 14 days.
Stripe takes the first half here. Add the target URL and confirm you can authorize the work. I email you for credentials. The 48-hour clock starts when login works — not when the card charges. The remaining $1,200 is due when the report lands.
Prefer a conversation first? Ask for the redacted sample, then pay.
Pages, forms, uploads, tokens, cookies, and what a signed-in user can reach that they should not. I work as a real user, then as a slightly more privileged one if you grant a second role.
Login, SSO, password reset, invite flows, role checks, and tenant boundaries. If the app sits behind Entra, Google, or a custom session, that is in scope when you say so.
The calls the UI already makes, plus the obvious neighbors: missing auth on an endpoint, IDOR-style object access, upload paths, and export/download controls. Source-code audit is a separate quote.
Target URL, roles, out-of-scope notes, and a test window. I do not start without authorization from the owner of the system.
You send credentials or an SSO invite. I confirm login. That is when the 48-hour clock starts — not when the first email arrives.
I exercise the live app under the agreed rules, keep notes by severity, and put any test state back the way I found it.
You get a written report. Fix what you want. I retest the same URL once, free, within 14 days.
Firms that sell a two-week CREST pentest for $8,000–$25,000 are selling a different product. I sell a timeboxed application security review with a report you can use. The market still calls that a web app pentest. I will too in conversation. I will not pretend I hold offensive-security certifications I do not hold, and I will not put exploit recipes in a PDF.
If strangers bounce before they ever log in, start with the website. If they call and nobody answers, start with the receptionist. This page is for teams who already have an app and need a grown-up look at how it behaves.