A larger or more sensitive application should not be forced into a fixed-scope security review. A custom penetration test is scoped around the actual system, user roles, APIs, environments and risks you need to verify.
We first define the objective, permissions and boundaries of the test. This makes it clear what will be tested, what the deliverable will include and what remains outside the agreed scope.
When a custom penetration test makes sense
- the application does not fit within the fixed Website Security Review scope;
- it has multiple user roles, environments, workflows or integration points;
- it handles more sensitive data, administrative access or important business processes;
- it includes a larger API or more complex permission logic;
- you need to verify a specific risk scenario rather than complete a generic checklist;
- the application needs to be assessed together with selected parts of its server, deployment or access controls.
What the test may include
The exact scope is defined around the objective of the engagement. The following areas are therefore not automatically included in every test.
- the web application and its public and authenticated areas;
- APIs and integration points;
- authenticationIdentity verification. A service checks whether you really are who you claim to be. More, sessionThe period after login when a service remembers you as a logged-in user. More management and account recoveryThe process of getting account access back after losing a password, phone, or second factor. More;
- authorisation, user roles and separation of data;
- administrative interfaces and application logic;
- forms, inputs, file uploads and file handling;
- the server, deployment process and selected infrastructure components;
- accounts, access controls and internal security practices where they affect the tested system.
How the scope is defined
Before testing begins, we define:
- what the test needs to verify and what decision the result should support;
- which systems, domainsA human-readable name for an internet service, such as a website address. More and environments are included;
- which accounts, roles and permissions will be available;
- which workflows and risk scenarios have priority;
- which data and operational constraints must be respected;
- how detailed the deliverable needs to be;
- the timeframe and price.
Testing outside the confirmed scope is not automatically included.
What you receive
- a concise summary of the main risks and their practical impact;
- a prioritised list of findings;
- the technical detail and evidence needed to understand each issue;
- clear remediation recommendations;
- a distinction between serious issues and lower-priority improvements;
- a technical appendix where required by the agreed scope.
The goal is not to deliver a long automated output. The report should make it clear what matters and what your developer or administrator should address first.
How the engagement works
- Send a brief description of the system. Basic information about the application, roles, environments and what you need to verify is enough to start.
- We define the scope. We clarify the objective, permissions, tested components, boundaries and required deliverable.
- You receive a concrete proposal. It includes the agreed scope, price and schedule.
- Testing takes place. The test follows the confirmed boundaries and permissions.
- You receive the deliverable. Findings are prioritised by severity, impact and recommended next steps.
What is not automatically included
- remediation of the identified issues;
- a retest after remediation;
- testing of systems or features outside the confirmed scope;
- ongoing responsibility for the security of the application;
- a compliance or certification audit;
- a guarantee that the application contains no other vulnerabilities;
- work without clear authorisation from the system owner.
Remediation, hardening or a retest can be agreed as separate follow-up work.
When the Website Security Review is enough
For one smaller web application, one domainA human-readable name for an internet service, such as a website address. More or environment, up to three user roles and up to five main application workflows, the fixed-scope Website Security Review may be a better fit.
It has a fixed scope, a price of CZK 35,000 and typical delivery within seven business days after the scope and required access have been confirmed. If the application exceeds those boundaries, a Custom Penetration Test is the appropriate next step.
Penetration test pricing
The price is determined after a short scoping process.
It depends mainly on the size and complexity of the system, the number of roles and environments, API scope, required testing depth, operational constraints and the required deliverable.
Once the scope has been confirmed, you receive a concrete proposal rather than an open-ended hourly estimate.
Discuss the test scope
Send a brief description of the application, user roles, environments and what you need the test to verify. If the fixed Website Security Review is a better fit, I will tell you.
