If we find no confirmed high or critical vulnerabilities.
Web & API penetration testing
The price depends only on the high or critical vulnerabilities we find and validate within the agreed scope.
If we identify 1 confirmed high or critical vulnerability.
Maximum, however many high or critical vulnerabilities we find.
The assessment runs in full regardless of the number of findings.
The best moment to find a vulnerability is before it becomes an incident.
We run offensive assessments of web apps and APIs to find exploitable flaws, validate their real impact and prioritize what to fix first. We don't just hand over scanner output.
What the assessment includes
A real security assessment of web apps and APIs, with manual validation of the relevant findings.
- Web & API pentestManual plus automated testing to find what scanners miss.
- Executive & technical reportEvidence, impact, priority and remediation guidance.
- 1 retest included in paid assessmentsOnce fixes land, we verify again.
- Retest holds regardless of who fixesValid whether your team, another vendor or Slash ships the fix.
No high vulnerability found? You still get the report.
At no cost: medium, low and informational findings, with evidence and remediation guidance.
We can also help you fix it.
On request, Slash prepares an independent proposal to implement the recommended fixes.
And the human factor?
Controlled phishing and social-engineering tests from COP $5 million.
Which platform would you like to assess?
Tell us the domain, application or platform to review. We'll make a first read and confirm the scope.
Offer subject to scope definition and contract. High or critical findings must be confirmed and reproducible within the authorized scope.