Your web application is the part of your business an attacker reaches first. Here is what they find.
Three tiers of web application penetration testing โ from a non-intrusive Bronze configuration review (from $990, delivered in 5โ7 days) to a full ASVS Level 1 Gold assessment for compliance-driven requirements. OSCP-certified testers. Developer-readable reports.
The right tier depends on what's driving the engagement. Most businesses start with Bronze.
Bronze
- Exposed service and port mapping
- SSL/TLS configuration review
- HTTP security headers
- Passive information leakage
- Authentication mechanism review
Silver
- Everything in Bronze
- Active OWASP Top 10 testing
- Authenticated testing
- Business logic testing
- Re-test within 90 days included
Gold
- Everything in Silver
- ASVS Level 1 verification
- Architecture and design review
- Limited source code review
- Compliance statement included
Every CyberCraft web app penetration test is conducted by an OSCP-certified tester. The report is written for developers โ not for auditors. Each finding includes the specific code-level or configuration change required to remediate it. A finding without a fix is an observation, not a useful output.
Bronze is non-intrusive. Bronze uses passive and semi-passive techniques โ it does not send attack payloads or attempt to exploit the application. It can be run against a production system without risk of disruption. Silver and Gold involve active exploitation attempts โ a test environment is strongly recommended for those tiers.
Kickoff call โ 30 minutes
Scope agreement, application overview, test credentials (Silver/Gold only), and agreed test window. Bronze can often proceed without a kickoff call.
Active testing within the agreed window
Bronze: non-intrusive. Silver and Gold: active exploitation attempts in a test window or test environment. If we find anything critical, you hear from us immediately โ not in the final report.
Draft report delivered for review
You see the draft before finalisation. If any finding needs clarification or context, this is when we address it.
Debrief call (Silver and Gold)
One-hour walkthrough of findings with your development or technical lead. Optional for Bronze. Silver and Gold include a re-test within 90 days of final report delivery.
Not sure which tier? Bronze is the right starting point for most businesses.
Book Bronze โ from $990, 5โ7 daysSilver โ OWASP Top 10 โ from $2,490 ยท Gold โ ASVS Level 1 โ from $4,990