SVC—01 · ASSESSMENT

Web application penetration testing

A scope-led assessment of exploitable application risk. This is not a repackaged scanner export.

Start scoping
OWASP WSTG 4.2OWASP ASVS 5.0.0 subsetNIST SP 800-115PTES

TEST BOUNDARY

What sits inside the boundary

Unique workflows, routes, roles, tenants, authentication and administration
Business logic, uploads, payments, integrations and sensitive data paths
Production-safe constraints, test accounts and environment assumptions

ACCESS MODES

Knowledge level is scoped

Black box
Grey box
White box

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Executive summary for decisions and an attack-path narrative

Reproducible findings with CVSS v4.0 vector and contextual priority

Engineering fixes, root causes, coverage map, and bounded retest

EFFORT—DRIVER

Workflows and dynamic routes

Roles, tenants and authorization complexity

Access model, integrations and deadline

EXPLICIT—LIMIT

Denial of service and destructive actions are excluded unless separately authorized

A point-in-time assessment cannot prove the absence of vulnerabilities

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft