FR
Payment successful! We’ll send your report shortly.
Payment cancelled. You can try again anytime.

Get a professional security report for your website.

200
one-time · full report

What you get

  • Executive summary with risk ratings
  • Detailed technical findings
  • Prioritized remediation steps
  • Re-test verification included

How it works

1 Order & provide your URL
2 We audit your site (48h)
3 Receive your report
30-day money-back guarantee
OWASP Top 10 & API Top 10 Secure payment via Stripe

Frequently asked questions

How much does a website security audit cost?

200 €, one payment, for one website — no hourly billing and no add-ons. That covers the audit, the written report, and one re-test after you deploy your fixes. A full penetration test is quoted per day and runs over weeks; this is a different product, with a fixed scope limited to one web application.

What exactly is tested, and what is not?

The audit covers the exposed surface of one web application and its API: authentication and session handling, access control, injection, exposed endpoints, server and header configuration, and dependency exposure — mapped to the OWASP Top 10, the OWASP API Security Top 10, the CWE Top 25 and the OWASP ASVS. Out of scope: internal network, source code review, phishing and social engineering, load or denial-of-service testing, and mobile applications. No destructive testing is performed intentionally: no data deletion, no denial of service, no mass account creation. Active testing on a live application is never entirely risk-free — a recent backup is recommended, and a staging environment can be audited instead on request.

Is this a real penetration test or just an automated scan?

A scanner is used on the first pass, to cover ground quickly. Every result is then reproduced by hand before it enters the report: false positives are dropped, and each item comes with the exact steps to reproduce it. Business logic flaws — one account reading another account’s data, a price or a role that can be changed client-side, a checkout step that can be skipped — are found manually; no scanner reports them. What you receive is a written report, not a tool export.

What do you need from me, and am I allowed to have the site tested?

Two things at checkout: your email and the URL to audit — plus a test account if you want the areas behind the login covered. You must own the site or hold a written authorization from its owner, which you confirm before paying: testing a site without the owner’s consent is a criminal offence (article 323-1 of the French Code pénal, and equivalents elsewhere). Scope questions are settled by email before testing starts. If the site runs on shared hosting or a SaaS platform, check their terms as well: some require advance notice.

What if you find no vulnerabilities?

You get the full report either way: what was tested, how, and what came back with nothing — that is the document you hand to a client or to a prospect asking about your security. A site that returns strictly nothing is rare: configuration defects and missing headers show up on well-maintained applications too. And if the report is not useful to you, the 30-day money-back guarantee applies: just ask by email within 30 days of delivery.