Skip to content

SaaS security assessments, part by part

One assessment can cover every part of your product an attacker could use. We follow the paths to your data and your customers’.

Request a scoping call

Free 30-minute scoping call. Not sure a pentest is enough? Read the comparison.

A typical SaaS product, part by part.

Every part, one assessment

Each part has its own assessment. Pick the ones you need, or cover them all at once.

Already have a pentest report? We’ll help you work out which findings matter and what to fix first. Then we check the fixes before the retest.VAPT report remediation support

How it works

From a free call to checked fixes.

  1. We agree what to look at

    On a free scoping call we work out which parts of your platform carry the most risk. You decide what’s in.

  2. We review and test

    We read the design, code and settings with your engineers. Where you’ve agreed it, we test hands-on with the access you set up.

  3. You get a clear report

    Every finding comes with its evidence and why it matters. They’re listed in the order we’d fix them.

  4. We retest your fixes

    Every fix comes with a way to confirm it worked. Once your team has made the fixes, we retest them. One round is included.

What it costs

One assessment can cover several parts, at one price.

Fixed fee for the agreed scope, quoted before work starts.

We quote it after the scoping call, once we know what’s in. If the scope grows later, we price the extra before we start it.

Included

  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes

Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Further retests after the first and extra scope added once work has started.

How we handle your systems and data

The same ground rules for every review.

Nothing starts without your written OK
You name the systems, the accounts and the time window. We start when you’ve signed that off.
What you share stays private
We can sign your NDA before you share any system details. Reports go only to the people you name.
We keep as little as we can
Only the evidence a finding needs, and as little personal data as possible. We don’t touch production without asking.
You get your access and data back
When we’re done we delete or return our working data and hand back every login you gave us.
What the report won’t cover
Every report lists what we didn’t test. It isn’t a compliance certificate.

Not sure which parts apply?

Tell us what you’re building and what’s changing, and we’ll suggest where to start. We reply within one working day.