Cybersecurity audits with proven risks and clear fixes
We test applications and infrastructure within an agreed scope, validate vulnerabilities without disrupting production and deliver a plan ordered by impact.
- €1,500
- Starting audit price
- OWASP
- Application methodology
- CVSS
- Documented severity
- 1x
- Retest included
An automated scanner does not replace a security audit
Useful findings come from pairing tools with manual validation and business context:
- Automated alerts include false positives and do not show a real attack path.
- Permissions, roles and application logic cannot be checked from the outside alone.
- Exposed servers and cloud configuration remain outside a simple web scan.
- A report without remediation order consumes time without reducing the primary risk.
How we conduct the audit
We work with written authorization, a clear test scope and agreed windows for sensitive operations.
Scope and rules
We define systems, accounts, limits, contacts and the emergency stop.
Testing
We combine automated analysis, manual checks and authenticated scenarios.
Validation
We confirm impact safely and remove false positives.
Report and retest
We deliver evidence, remediation steps, a technical session and one retest.
Web applications and APIs
Authentication, authorization, sessions, input, files and business logic.
Servers and networks
Exposed services, patches, configuration, segmentation and administrative access.
Cloud and containers
Permissions, secrets, storage, images and infrastructure configuration.
Prioritized risk
Technical severity placed in the context of company data and processes.
Usable report
Evidence, reproduction steps and recommendations for the remediation team.
Retest included
We verify reported vulnerability fixes once.
Methods and tools
- OWASP ASVS
- Burp Suite
- Nmap
- OpenVAS
Docker
AWS / Vercel
Medium-premium Romanian market rates based on application count, roles, APIs and infrastructure segments.
Essential
Audit for one web application or a limited perimeter.
- One web application
- Unauthenticated testing and one role
- OWASP Top 10 checks
- Technical report
- One retest
Advanced
Application, API and related infrastructure.
- Web and API
- Up to 4 roles
- Business logic testing
- External infrastructure scan
- Remediation workshop
Enterprise
Multiple applications or a complex cloud environment.
- Extended perimeter
- Cloud and containers
- IAM configuration review
- Executive and technical reports
- Priority retest
Prices exclude VAT and assume authorized access, an agreed scope and one retest round. An active incident response is not included.
FAQ
We agree limits and testing windows before work. High-risk tests run only with explicit approval or in a separate environment.
Yes. The report includes the affected system, severity, evidence, reproduction steps and remediation recommendation.
Yes, one retest round for reported vulnerabilities is included in every package.
Yes. We define confidentiality, evidence handling and authorized contacts before access.
Define the perimeter before somebody else tests it
Send the number of applications, roles, APIs and available environments. We will reply with scope, schedule and audit cost.
Let's talk