Skip to the content
04Security

Cybersecurity

We test websites, applications and bots the way an attacker would—only with your permission, and with a report instead of a breach. Every finding comes with reproduction steps and an assessment of what it means for the business.

What is included

Scope of work
point by point.

  • Reconnaissance: subdomains, forgotten environments, open ports
  • OWASP Top 10 checked by hand as well as by scanner
  • Authentication, sessions, password recovery
  • Access rights: horizontal and vertical privilege bypasses
  • Injection: SQL, NoSQL, commands, templates
  • File upload, XSS, SSRF, unsafe redirects
  • Secrets in the repository, the bundle and the headers
  • Vulnerable dependencies and outdated libraries
  • Testing of Telegram bots and mobile APIs
  • Report with priorities, proof of concept and a remediation plan
  • Free retest after you have made the fixes
Who it fits

Situations
where this pays for itself.

Before launch

Testing before users ever see the product. Fixing it on a staging environment is cheaper than explaining an incident afterwards.

Report in 5–7 working days

A partner or bank requires it

A formal test report of the kind accepted in procurement and when applying for card acquiring.

Report in a compliance-ready format

After a breach

We look for the way in, close it and check that nothing has been left behind.

First findings within 24 hours

Audit of inherited code

The project came from a previous contractor with no documentation. We work out what is in there and where it is dangerous.

Risk map by component

How we do it

Four steps
from brief to handover.

  1. 01

    Scope and permission

    We put in writing what is being tested and what must not be touched, then sign an NDA and a testing authorisation.

  2. 02

    Reconnaissance

    We build the map: subdomains, entry points, the stack, forgotten test environments.

  3. 03

    Exploitation

    We test the hypotheses. Critical findings are sent to you straight away, without waiting for the work to end.

  4. 04

    Report and retest

    You get the report with priorities. Once you have made the fixes, we check free of charge that the hole really is closed.

Technology

What we
build it with.

OWASP Top-10Burp SuitenmapsqlmapZAPSemgrepTrivyCWECVSS
Timeline and cost

Three tiers.
The exact estimate follows the brief.

Start

from ₽120,000

5–7 working days

  • One site or bot
  • OWASP Top 10
  • Dependency and secret checks
  • Report with priorities and proof of concept
  • One free retest
Business

from ₽350,000

10–20 working days

  • Web, API and mobile clients
  • Access rights checked role by role
  • Source code review of the critical modules
  • Infrastructure and CI/CD checks
  • Walkthrough of the report with your team
Enterprise

on request

20–45 working days

  • Several systems and the internal perimeter
  • Social engineering scenarios, subject to agreement
  • Threat model and risk map
  • Secure development requirements
  • Repeat audit six months later

Prices are the lower bound. What pushes an estimate up is set out on the pricing page

Questions

About this
service.

01How is this different from an automated scanner?

A scanner finds known patterns and reliably misses logic flaws: reaching someone else’s order through a direct link, a discount that can be applied twice, a payment cancelled after the goods have gone out. We run scanners as the first step and spend the bulk of the time checking the logic by hand.

02Can you break something?

On a production environment we work only by agreement and without destructive tests. The best option is to give us a copy on a separate environment—then we can test properly and risk nothing. The boundaries are agreed in writing before we start.

03What do we get at the end?

A report: a list of findings with a CVSS severity rating, reproduction steps, screenshots and a specific recommendation—which piece of code or which setting to change. Plus a one-page summary for management, with no jargon.

04Can you fix everything yourselves?

We can, but that is separate work. We deliberately keep the audit and the fixing apart: an auditor who patches their own findings stops being independent. If you do the fixing, we will help with the priorities and check the result free of charge.

Get an estimate:
Cybersecurity

The brief takes 5–7 minutes. In working hours we reply within two hours, and the estimate is free.