Surface Vulnerability Scan: Identify common vulnerabilities such as outdated software and misconfigurations
OWASP Top 10 Testing: Check for the most critical web application security risks
Single Application/Website: Focus on a single target application
Manual & Automated Testing: Combination of automated scanning tools and basic manual verification
Basic Report: Summary of vulnerabilities with general recommendations for fixing
Secure Plus
Full Web Application Scan: Comprehensive scan across multiple pages and functionalities
OWASP Top 10 + Additional Threats: Testing for the OWASP Top 10 risks plus additional vectors such as session management flaws
Multiple Applications/Websites: Testing for up to 3 web applications or subdomains
Manual Testing for Key Areas: Deep manual testing for critical areas like authentication and data storage
Post-Test Consultation: One-hour call to discuss findings and recommendations
Detailed Report: Comprehensive report with vulnerability descriptions, risk levels, and specific remediation step
Secure Pro
Full Penetration Test: Includes advanced testing techniques such as social engineering, file upload exploitation, and business logic testing
Advanced Vulnerability Testing: Tests for zero-day vulnerabilities and complex attack scenarios
Unlimited Applications/Subdomains: No limit on the number of applications or subdomains included in the test
Source Code Review (Optional): Deep dive into your codebase to identify security issues within the code itself
Continuous Testing Option: Quarterly or monthly re-testing to ensure security over time
Priority Support: Direct access to the security team during and after the assessment
Executive Summary + Detailed Report: A report designed for both technical teams and C-level executives, with risk assessments, detailed remediation steps, and recommendations for long-term security