Comprehensive Web App Security Testing
Budget: ₹1,500 – ₹12,500 INR
I need a qualified, third-party security testing agency to run a full grey-box assessment of our production web application. The engagement must combine manual techniques with automated scans powered exclusively by licensed commercial tools—no open-source-only stacks. A CERT-In-empanelled team is strongly preferred.
Key areas to probe are user authentication and authorization flows, data storage and encryption mechanisms, and every third-party integration we rely on. I will also share full API documentation so you can include endpoint-level checks in the same cycle.
Please plan for two distinct test windows: an initial assessment and a follow-up once we have patched the findings. All identified risks must be verified as closed before final sign-off.
Deliverables (submitted in PDF with supporting evidence):
• Initial AppSec / DAST + API Security Testing Report
• Risk summary with reproducible vulnerability details and severity ratings
• Re-test / Revalidation Report confirming fixes and residual risk status
Feel free to outline your proposed methodology, licensed toolset, sample report format, and estimated timeline when you respond.
Key areas to probe are user authentication and authorization flows, data storage and encryption mechanisms, and every third-party integration we rely on. I will also share full API documentation so you can include endpoint-level checks in the same cycle.
Please plan for two distinct test windows: an initial assessment and a follow-up once we have patched the findings. All identified risks must be verified as closed before final sign-off.
Deliverables (submitted in PDF with supporting evidence):
• Initial AppSec / DAST + API Security Testing Report
• Risk summary with reproducible vulnerability details and severity ratings
• Re-test / Revalidation Report confirming fixes and residual risk status
Feel free to outline your proposed methodology, licensed toolset, sample report format, and estimated timeline when you respond.