CREST Accredited
Manual and automated testing delivered under CREST accreditation.
Retest included
Fixed scope from $2,499
Self-serve checkout
Expert-led web application penetration testing that combines manual security testing with automated discovery to uncover exploitable vulnerabilities, authorization weaknesses, API security issues and business-logic flaws. Choose a fixed-price plan, complete your scope online and start your assessment without a lengthy sales process.
The definition
Unlike a vulnerability scan that primarily identifies potential weaknesses using automated tools, a penetration test combines automated discovery with manual investigation, validation and controlled exploitation. Our testers assess how weaknesses can be combined, whether security controls can be bypassed and what the actual business impact could be. Testing can uncover issues such as broken access controls, injection vulnerabilities, authentication weaknesses, insecure session handling, API authorization problems and application-specific business-logic flaws.
Manual and automated testing delivered under CREST accreditation.
Security professionals lead discovery, exploitation analysis, and reporting.
Coverage aligned with OWASP Top 10 and WSTG-style methodology.
Technical and executive reporting with a defined retest window on fixed tiers.
Know your application size? Choose a plan and get started. Not sure? Use the scope criteria below or complete our short scoping questionnaire.
For smaller web applications, startup products and straightforward customer or internal portals.
$2,499per application
Typical completion: 5–7 business days
For SaaS products and business applications with multiple users, APIs and more complex workflows.
$4,999per application
Typical completion: 7–10 business days
For large, complex or business-critical applications that require tailored scoping.
Custom pricing
Timeline and testing effort are agreed after scoping.
| Feature | Essential | Professional | Custom |
|---|---|---|---|
| Price | $2,499 | $4,999 | Custom |
| Web applications | 1 | 1 | Custom |
| User roles | Up to 2 | Up to 5 | Custom |
| Core workflows | Up to 10 | Up to 25 | Custom |
| API endpoints | Up to 25 | Up to 75 | Custom |
| Business-logic testing | Standard | Enhanced | Extensive |
| OAuth / SSO | — | ||
| API security testing | Up to 25 endpoints | Up to 75 endpoints | Custom |
| Retest | 1 | 1 | Defined in scope |
| Retest window | 30 days | 60 days | Defined in scope |
| Typical completion | 5–7 business days | 7–10 business days | Agreed |
| Manual penetration testing | |||
| Automated discovery | |||
| OWASP Top 10 testing | |||
| OWASP WSTG-aligned methodology | |||
| Authentication testing | |||
| Authorization testing | |||
| Session security | |||
| Technical report | |||
| Executive summary |
Pricing confirmed at checkout.
Plan selection
We'll recommend Essential, Professional, or Custom based on real application complexity—not marketing page count.
Automated scanners are useful for discovering certain classes of security weaknesses.They cannot reliably understand how your application is supposed to behave—finding these issues requires testing it as an attacker would, not simply running a scanner.
Coverage
Testing is risk-based and tailored to the functionality exposed by your application.
We examine the accessible application surface, technologies, endpoints and functionality relevant to the agreed scope.
We assess whether attackers could compromise or bypass mechanisms that establish user identity.
We test whether authenticated and unauthenticated users can access functionality or data beyond their intended permissions.
We assess how sessions are created, maintained and terminated.
We test application inputs and processing logic for exploitable conditions.
We test application-specific processes that automated scanners cannot adequately understand.
Where APIs are included in the selected package, we test their security controls and how they interact with the application.
We assess relevant browser-side functionality and trust boundaries.
Where applicable, testing may assess:
Methodology
Our approach combines structured security testing with expert-led investigation. Testing is aligned with recognised web application security testing practices, including the OWASP Web Security Testing Guide.
Step 1
You provide the application details, test environment, user roles, credentials, APIs and testing restrictions through Secusy. We validate that the selected plan matches the application scope before testing begins.
Your assessment produces practical outputs for both management and technical teams.
A management-level view of the assessment covering assessment scope, key security observations, significant findings, risk distribution, business impact and remediation priorities.
Each relevant finding can include vulnerability name, severity, affected component, description, security impact, evidence, reproduction information, remediation guidance and relevant technical references.
Where appropriate, findings include sufficient evidence to help your technical team understand and reproduce the issue without unnecessary exposure of sensitive information.
Clear recommendations help developers understand how each identified weakness can be addressed.
Once remediation is completed, included findings can be retested and their status updated.
Scoping
A core workflow is a distinct application function or user journey that requires security testing.
Examples include
Static content pages are not normally treated as individual workflows. The workflow limit is designed to estimate application complexity—not to prevent testers from examining functionality relevant to an identified security issue.
Plan boundaries
Unless specifically agreed, Essential and Professional do not include:
Remediation
Finding vulnerabilities is only part of the process. Once your developers have remediated identified issues, request your included retest through Secusy.
One retest requested within 30 days of the original report.
One retest requested within 60 days of the original report.
The included retest verifies remediation of vulnerabilities identified during the original assessment. New application functionality, additional systems or vulnerabilities outside the original scope may require additional testing.
Intake
Penetration testing requires explicit authorization and a clearly defined scope. After purchase, Secusy guides you through the information required to begin testing.
You will normally provide
Choose a predefined scope and purchase Essential or Professional directly.
Clear limits for applications, roles, workflows, APIs, retesting and deliverables reduce ambiguity before testing begins.
Penetration testing is performed by cybersecurity professionals—not delivered as an automated vulnerability scan.
Use Secusy to progress from purchase and onboarding through assessment, reporting and retesting.
Reports are designed to help both management understand the risk and developers fix the underlying vulnerabilities.
Secusy is the digital cybersecurity services platform powered by ValueMentor. Penetration testing purchased through Secusy is delivered using ValueMentor's cybersecurity testing capabilities.
Web application penetration testing can be appropriate for:
Test customer-facing SaaS platforms, administration interfaces, tenant isolation and APIs.
Obtain independent security testing before enterprise customer onboarding, fundraising, launch or security reviews.
Assess authentication, customer accounts, transactions, checkout flows and application APIs.
Test access controls, transactional workflows, APIs and sensitive application functionality.
Assess web applications handling sensitive workflows, accounts and integrations.
Independently test internally developed or externally exposed business applications.
Add independent security testing before major releases or as part of the secure development lifecycle.
Timing
Common triggers include:
A penetration test is a point-in-time assessment. Applications that change frequently may require more frequent or continuous security testing.
Questions