Test exploitable weaknesses across your agreed coverage.
For multiple apps, cloud accounts, complex access roles, or internal networks.
CORE DELIVERABLES, PLUS
Multiple environments and asset groups
Additional access roles and trust boundaries
Penetration testing within agreed boundaries
Fee and delivery window agreed upfront
What counts as a finding? A verified, actionable vulnerability within the agreed coverage. The fixed fee does not increase with the number of findings.
COVERAGE, NOT HEADCOUNT
Price the attack surface. Not the org chart.
A small team can run complex infrastructure. A larger company can have a simple environment. We price the work around what needs testing.
01
What’s exposed
Applications, APIs, domains, and services that need testing.
ASSETS
02
How it connects
Cloud accounts, networks, and integrations between systems.
ENVIRONMENTS
03
How deep we go
Access roles, internal testing, and the complexity of your setup.
You choose the assets and access included in the audit. An external assessment can begin with approved public-facing assets. Cloud, internal, or authenticated testing requires separately agreed permissions. The report identifies any limits caused by unavailable access.
How is our data handled during the audit?+
Before granting access, agree in writing on the data the assessment may use, any AI providers involved, retention and deletion terms, and how findings will be delivered. These terms belong in the engagement scope before testing begins.
Do I pay anything if you find nothing?+
No. If the agreed assessment finds no verified, actionable vulnerability, the audit fee is $0. You still receive a summary of the scope and assessment outcome.
Is $1,500 the price for every company?+
It is the starting price for a focused audit. Larger asset counts, additional environments, and more complex testing receive a custom fixed quote before work begins.
How is severity determined?+
Findings are rated Critical, High, Medium, or Low based on evidence, exploitability, potential impact, and the context of your environment. The report explains the reasoning and what to prioritize.
Does a clean audit mean we are completely secure?+
An audit is a point-in-time assessment within agreed boundaries. No findings means none were identified in that assessment; it does not guarantee that every vulnerability has been discovered.
Does the audit include fixing the issues?+
The audit includes remediation guidance. Implementation and any follow-up testing are separate work unless explicitly included in your agreed scope.
Will testing disrupt our business?+
Testing boundaries, permissions, and timing are agreed before work begins. Disruptive testing requires explicit authorization. Your engagement defines the permitted methods and stop conditions.
LET’S PLAN YOUR AUDIT
Start with a conversation.
Book 30 minutes with Mario to discuss your infrastructure, access preferences, and audit goals. We’ll confirm the coverage and fee before any testing begins.