Comprehensive Web App Security Testing

Job ID: 39993246

Budget: ₹1,500 – ₹12,500 INR

I need a qualified, third-party security testing agency to run a full grey-box assessment of our production web application. The engagement must combine manual techniques with automated scans powered exclusively by licensed commercial tools—no open-source-only stacks. A CERT-In-empanelled team is strongly preferred.

Key areas to probe are user authentication and authorization flows, data storage and encryption mechanisms, and every third-party integration we rely on. I will also share full API documentation so you can include endpoint-level checks in the same cycle.

Please plan for two distinct test windows: an initial assessment and a follow-up once we have patched the findings. All identified risks must be verified as closed before final sign-off.

Deliverables (submitted in PDF with supporting evidence):
• Initial AppSec / DAST + API Security Testing Report
• Risk summary with reproducible vulnerability details and severity ratings
• Re-test / Revalidation Report confirming fixes and residual risk status

Feel free to outline your proposed methodology, licensed toolset, sample report format, and estimated timeline when you respond.