Grey-box
Testing with working accounts across each role, but no access to your source code. Nothing leaves your environment, and it is the form of test that due-diligence reviewers and certification bodies expect to see.
Web application and API testing, scoped properly and quoted as a fixed price. You get a report your auditor and your enterprise customers will accept.
Testing with working accounts across each role, but no access to your source code. Nothing leaves your environment, and it is the form of test that due-diligence reviewers and certification bodies expect to see.
The same coverage with read access to the repositories. Less effort to reach the same depth, so it costs less — worth it if you are comfortable granting that access.
On pricing. We quote a fixed price for a defined scope, not a day rate. A day rate makes the cost of your test a function of how long it takes us, which is the wrong incentive and the wrong conversation. You should know the number before you commit.
A short form and usually one call: the routes, the roles, the integrations, and what you actually need the report to prove.
A non-production environment, accounts for each role, an API export, and any WAF allow-listing. None of it onerous, but worth starting early.
A defined window. Critical findings are raised with you as they are found, not held back for the report.
Report about a week after testing, then a walkthrough. Retest of high and critical findings once you have remediated.
Testing is carried out by CREST-certified testers working to Summit's engagement terms.
A short conversation is usually enough to work out whether we can help, and what it would cost.