Skip to content
Web application security review

A written security review
in 48 hours — not a six-week theater.

Buyers search “penetration test.” What most product teams actually need is an authorized review of the live app: login, roles, the pages a user can see, and the APIs behind them. I test those surfaces, rank what I find, and send a report you can hand to engineering the same week.

$2,400 per application. Half to start, half when the report lands. Clock starts when written scope and working credentials are in. One free retest of the same URL within 14 days.

Night desk with a printed severity report, a laptop showing an abstract application dashboard, brass lamp, and moonlight
What you get Access → review → ranked report → one free retest
The offer

One application. Frontend, auth, and API.

$2,400
$1,200 to start · $1,200 on delivery
  • 48-hour delivery after access works (24–72 hours on a small or unusually large surface)
  • Authenticated review of the UI, session/auth, and backend APIs in scope
  • Severity-ranked written report with practical remediations — no exploit payloads, no credentials in the PDF
  • One free retest of the same application / target URL within 14 days
  • Redacted sample report available before you pay
Pay the start

$1,200 starts the review. The clock starts later.

Stripe takes the first half here. Add the target URL and confirm you can authorize the work. I email you for credentials. The 48-hour clock starts when login works — not when the card charges. The remaining $1,200 is due when the report lands.

Prefer a conversation first? Ask for the redacted sample, then pay.

Pay the start
Pay $1,200 to start
What is actually tested

More than a scanner dump. Not a red-team circus.

Frontend and session

Pages, forms, uploads, tokens, cookies, and what a signed-in user can reach that they should not. I work as a real user, then as a slightly more privileged one if you grant a second role.

Auth and identity

Login, SSO, password reset, invite flows, role checks, and tenant boundaries. If the app sits behind Entra, Google, or a custom session, that is in scope when you say so.

API and backend

The calls the UI already makes, plus the obvious neighbors: missing auth on an endpoint, IDOR-style object access, upload paths, and export/download controls. Source-code audit is a separate quote.

How it runs

Written permission. Then speed.

01

Scope in writing

Target URL, roles, out-of-scope notes, and a test window. I do not start without authorization from the owner of the system.

02

Access that works

You send credentials or an SSO invite. I confirm login. That is when the 48-hour clock starts — not when the first email arrives.

03

Review and restore

I exercise the live app under the agreed rules, keep notes by severity, and put any test state back the way I found it.

04

Report, then retest

You get a written report. Fix what you want. I retest the same URL once, free, within 14 days.

Start a review — $1,200 to begin
Plain language

What this is, and what it is not.

Firms that sell a two-week CREST pentest for $8,000–$25,000 are selling a different product. I sell a timeboxed application security review with a report you can use. The market still calls that a web app pentest. I will too in conversation. I will not pretend I hold offensive-security certifications I do not hold, and I will not put exploit recipes in a PDF.

FAQ

The questions people ask before they send access.

Is this a penetration test?
It is an authorized web application security review of the frontend, authentication, and API/backend in scope. Buyers and job posts often call that a web app pentest. It is not a multi-week infrastructure red team, a social-engineering exercise, or a certified CREST engagement.
How much does it cost?
$2,400 per application. $1,200 to start, $1,200 when the report is delivered. A tightly scoped app can still finish in 24–48 hours; a larger surface may take up to 72. Extra apps are quoted.
What do I need to start?
Written authorization, the production or staging URL, working test credentials or an SSO invite, any out-of-scope rules, and whether you want a second role for comparison.
Can I see a sample report?
Yes. Ask and I will send a redacted sample that shows format, severity ranking, and how remediations are written — with no client names and no exploit payloads.
What about a retest?
One free retest of the same application and target URL is included if you book the review, within 14 days of the first report.
Can I pay the $1,200 start from the page?
Yes. Stripe checkout on this page takes the start payment. You will add the target URL and confirm you are authorized. The 48-hour clock still starts only after working access, not at the charge.
If the leak is elsewhere

A weak site or a dead phone line is a different job.

If strangers bounce before they ever log in, start with the website. If they call and nobody answers, start with the receptionist. This page is for teams who already have an app and need a grown-up look at how it behaves.