Deep Pentest

Your app keeps shipping.
Your pentest tests yesterday's app.

Named researcher plus autonomous agent fleet. PoC behind every finding, signed NIS2 / ISO report, one retest. Fixed price.

3-5 days

one app + API, from scoping to signed report

€3,500 fixed

starting point, locked in writing after 20 minutes

100% PoC

every finding has a working PoC

Proof, at our own risk.

This pipeline hunts live bug-bounty programs every day. Real scope, real triage, paid findings. Your test runs on the same pipeline.

Vercel
Zooplus
Exness

Findings and full report list on request.

How an engagement runs

01

20-minute scoping

Exact scope in writing: hosts, app, API, auth roles, what is explicitly not included.

02

Fixed quote within 24 hours

Written, in English or German, with a scope you can hand to your lawyer or auditor.

03

3-5 days of deep testing

Our agent fleet maps the whole surface and probes the logic; a named researcher reviews, verifies, and chains every finding.

04

Signed report + one retest

CVSS plus NIS2 / ISO 27001 mapping and prioritized remediation. You fix, we retest once, included.

What every test includes

  • Deep recon: every domain, subdomain, API, endpoint
  • Business logic: IDOR, authz, race conditions, payment & checkout flows
  • Proof-of-concept per finding, reproducible, in the report
  • Signed report with CVSS and NIS2 + ISO 27001 evidence mapping
  • One retest of all findings, included
  • Report and walkthrough in English or German

How pricing works

from €3,500, fixed

one web app + its API, unauthenticated + one role, 3-5 days, report + one retest.

Most projects: €4,000-€7,000.

What moves the price

additional app or API+ €1,500
additional auth role+ €500
mobile or cloud scopefixed, quoted upfront
NIS2 / ISO 27001 evidence mappingincluded
urgent start (next week)+ 20%

One fixed fee, in writing, signed by both sides. It moves only if the scope does.

Who actually does the test?+

Samir Abis. Named in the contract, reachable during the test and at the readout. He runs the pipeline, verifies every PoC himself, and signs the report.

How is this different from a bug bounty?+

Fixed scope, fixed price, 3-5 days, report guaranteed. A bounty gives you no coverage and no timeline, and you pay only if someone finds something. You still need the report for SOC 2.

What happens if you find a critical?+

We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive ever happens without written sign-off.

Is this legally sound in Germany?+

Yes. A signed authorization and rules of engagement come before the first probe: exact scope, permitted techniques, rate limits, emergency-stop contact. In writing, before we start.

Do you need credentials?+

Optional. Most of the external surface is reachable without credentials. Test accounts deepen the logic coverage, one of the price drivers.

What about the rest of my systems?+

This offer covers the external web + API surface. Internal network, mobile, and cloud are separate fixed-priced modules, quoted after scoping if you want them.

20 minutes. Then a fixed price, in writing.

Send what you want tested, or book the scoping call. Within 24 hours you have a fixed-price quote with a scope you can sign.