Book a call

Quality Engineering / Security

Website & Application Security Assessments

Understand public exposure, test important access decisions, or establish demonstrated attack impact. Give your engineering team evidence and a practical path to fixes.

Choose the right depth

Three assessments. One clear scope.

Surface suits a brochure website. Deep is our main offer for suitable authenticated applications. Choose Adversarial when controlled exploitation and combined impact answer your team's question.

Assessment

Surface Security Review

€400 + VAT

What does my website expose publicly?

A practical starting point for brochure websites.

  • One website, up to two exact public hostnames and one optional email domain.
  • Low-impact checks of public exposure, hostname-specific TLS, redirects, relevant browser, cookie and email controls, and exposed content. No login or exploitation.
  • Evidence-backed findings and explicitly public-only coverage.
Discuss this assessment

Main offer

Deep Security Assessment

From €800 + VAT

Do login, permissions and important workflows hold up?

Our main offer for suitable applications with user accounts.

  • One deployment, up to two hosts, three named workflows and two roles. Requires controlled accounts, test data and supplied configuration evidence.
  • Public baseline plus bounded active tests of sessions, object and role boundaries, input handling and business rules. Agreed application authorization and test-tenant boundaries are included.
  • Missing access or evidence is recorded as incomplete coverage. A public-only run does not complete a Deep assessment.
  • Observed access decisions, workflow results and configuration evidence gaps.
Discuss this assessment

Assessment

Adversarial Security Assessment

From €1,600 + VAT

How far could an attacker actually get?

For teams that need demonstrated exploitation and combined impact.

  • A quoted attack plan for one deployment, normally up to five authorized hosts/services, five workflows and three roles. The quote defines exact assets, cases, effort and permitted impact. The full ceiling is not included at the starting price.
  • Scoped penetration testing through controlled exploitation, privilege-boundary tests and tested attack chains. When applicable and expressly authorized, proofs may include SQL injection, SSRF, temporary command execution and privilege escalation.
  • Demonstrated impact and limits, tested versus hypothetical attack paths, detection observations and cleanup evidence.
Discuss this assessment

A workflow is an agreed sequence such as signing in, opening a customer project or changing a user's permissions. We name its operations, roles and expected outcomes; it does not mean every function of your application. We confirm exact scope, access, price and dates before booking. Starting prices do not promise every case within the scope ceiling.

Deliverables

Evidence your team can act on

  • A private, self-contained interactive HTML assessment and a readable A4 PDF, with the same deliverable quality at every tier.
  • Dedicated Overview, Findings, Developers, Coverage and Attack paths sections. Developers includes a remediation backlog, implementation briefs and acceptance tests.
  • Prioritized findings with reviewed reproducible evidence, impact, confidence and concrete fix guidance. Negative checks and legitimate user actions verify fixes; ticket, CSV and report-data exports support your team.
  • Visible tested, incomplete, excluded and not-tested coverage. Vulnerabilities, hardening opportunities, positive controls and inconclusive checks remain distinct. A clean result applies only to recorded scope; finding count is not a security score.

A results discussion and one free focused retest of original findings requested within 30 days of report delivery. We schedule the retest separately. New assets, features and repeated testing need a separate scope.

Fictional sample report

Explore an Embeddedware example for a fictional application. It illustrates report structure and evidence, not a customer assessment or a promise of findings. The sample is in English.

Optional remediation

Fix guidance is included. Implementation is scoped separately.

Targeted remediation: €70/hour or €400 per booked day, excluding VAT. Agree the work and a spending limit first. A four-hour total allowance is €280, including the investigation, implementation, code review, rollback preparation and regression checks that fit within it. We do not promise to fix every finding.

Booked blocks use the day rate; smaller or ad hoc work uses the hourly rate. The quote defines the working-day duration and charging basis. We never bill the same work twice. Larger changes need an agreed estimate before work begins.

How we work

Authorization, evidence and clear limits

Agree the plan before testing

Testing is limited to owned or owner-authorized assets, an agreed window, permitted effects, stop conditions and cleanup. We confirm access and controlled test data first, then agree delivery dates. Missing access, evidence and untested cases are visible in the report. We make no fixed initial turnaround promise.

What needs separate scoping

Destructive availability tests, persistence, real-data extraction, social engineering and unrelated third-party systems are outside the default offer. Broad network or Active Directory assessments, entire complex multi-tenant platforms, payment-provider systems and embedded or firmware work need specialist scoping. Agreed test tenants and application permission boundaries remain within Deep and Adversarial scope.

Assessment, with honest limits

Surface is public-only. Deep adds bounded authenticated testing. Adversarial includes explicitly scoped penetration testing and controlled exploitation. No tier is a security certification, exhaustive OWASP coverage, a guarantee of compromise discovery or proof that no vulnerabilities remain.

Part of Quality Engineering

These website and application services do not automatically cover embedded devices, firmware or your entire product infrastructure. Ordinary defects in our own delivery are not charged again as optional security work. We disclose when assessing our own build; that review is not independent assurance.

Explore Quality Engineering

Start with your website and your question

Share ordinary contact details, the public website URL, package interest and what prompted your enquiry. An enquiry does not authorize testing, confirm eligibility, reserve promotional availability or book an engagement.

Request a scoped quote

Do not send passwords, API keys, vulnerability evidence or sensitive system details through the public form or email. We agree secure access and evidence handling separately.