Pentest // INTAKE
Pentest intake
A pentest you can buy in one sitting.
Four steps on one page: scan the target, check the scope against the caps, confirm the fixed price, book the Day-0 call and pay. If the scope is bigger than the caps, the same page routes you to a quote instead of a number that would not hold. The full service is on the penetration test page; the report format is the sample report.
Scan, scope, price, book
One web app plus its API, up to three hostnames and two user roles, one price, held. Authenticated authorization testing (BOLA and BFLA) is performed by the engineer. Everything below reads from that line; nothing is decided on the call that is not already on this page.
Paste your URL
The free Ghost Scan reads what your site exposes publicly, nine categories in about a minute. It is the surface read the engineer starts from; it does not log in and it stores nothing.
No card. No signup. Nothing stored.
Check the scope
One web app plus its API, up to three hostnames and two user roles, one price, held. Authenticated authorization testing (BOLA and BFLA) is performed by the engineer. List what the engineer should reach.
Hostnames
User roles
0 / 3 hostnames · 0 / 2 roles · inside the caps: fixed price
Mobile apps, internal networks, social engineering and denial-of-service are outside this engagement by default. If you need one of those, tick a box above and the quote covers it.
Confirm the price
One number, held. USD by card for international clients; companies registered in Sri Lanka are invoiced in LKR at the local rate card, a separate price, not a conversion.
$2,999Fixed · USD5–7Days · kickoff to deliveryFreeRe-test after you patchWhat is included
Executive PDF reportPlain-English findings written for a CEO, not just a CTO. Includes risk score, severity breakdown, AI-generated executive summary.Developer JSON + SARIFMachine-readable findings for SonarQube, GitHub Advanced Security, your CI pipeline.Reproducible proofEach high-severity finding includes a step-by-step PoC your engineers can replicate.Free re-testOnce you patch, we re-run the scan and issue an updated clean report, no extra charge.30-day Q&AEmail your assigned engineer with follow-up questions for 30 days after delivery.Attestation letterSigned PDF letter you can hand to auditors, customers, or VCs as proof of testing.See the format first: the example report (PDF, 15 pages). A synthetic engagement, same structure as yours.
Book the Day-0 call, then pay
Fifteen minutes on Day 0: we confirm the scope, sign the engagement letter, you send target details. Pay by card now, or request an invoice and pay by transfer.
From the call to the clean report
Standard delivery is 5 to 7 days from kickoff. The 72-hour rush is the same engagement started immediately.
