SecureBlockLog inStart a pentest
Kickoff in 48 hours

From "we need a pentest" to signed report in ~2 weeks.

No RFP. No three-week sales cycle. No scoping spreadsheet. A transparent 5-step flow you can complete in one sitting — and a fixed price your auditor can bank on.

Manual testing, not just scanners Mutual NDA before you share scope Free retest included
The 5 steps

Every engagement, every time.

No custom sales process, no bespoke SOW dance. The same clean flow whether you're testing one web app or twenty.

Step 01

Scope it yourself

~2 minutes

Answer four questions in a form — no discovery call required.

What you do
  • Pick the assets you want tested (web app, API, mobile, cloud...)
  • Say how many of each and roughly how big they are
  • Choose a start window and accept a mutual NDA
What we do
  • Nothing manual — pricing is instant, based on our published rubric
  • Your scope is encrypted at rest the moment you submit it
You walk away with — A live-updating quote and a locked-in start window.
Step 02

Get a fixed price

Instant

One number, line-itemed, no scope-creep clauses.

What you do
  • Review the quote — line items, deposit, testing window
What we do
  • Show the exact math: base price per asset x size x auth x volume discount
  • Include the retest and the evidence-ready report in the price
You walk away with — A quote your finance team can approve without a call.
Step 03

Lock in your dates

Same day

Pay 25% to confirm, or hop on a 30-min call first.

What you do
  • Pay the deposit via Stripe to reserve the slot
  • Or book a call with a senior engineer to walk through the scope
What we do
  • Assign a lead tester (OSCP + CREST) within the hour
  • Send an engagement letter, kickoff calendar invite, and a shared Slack channel
You walk away with — A confirmed engagement, tester assigned, kickoff dated.
Step 04

Testing begins

5-10 business days

Manual, hands-on testing — not scanner spam parked in your inbox.

What you do
  • Grant scoped credentials via a secrets manager we share
  • Answer occasional clarifying questions in Slack (usually one or two)
What we do
  • Follow OWASP WSTG, PTES, and NIST SP 800-115
  • Publish confirmed findings in the platform as we validate them
  • Emergency-escalate anything critical the same hour we find it
You walk away with — Findings with CVSS, evidence, and remediation guidance — live.
Step 05

Report & retest

Report day 10 · retest free

One report your engineers and your auditor will both actually use.

What you do
  • Fix findings on your timeline
  • Ping us when you're ready for the retest
What we do
  • Deliver an executive summary + technical report + evidence packs
  • Retest verified fixes and reissue a clean report — no charge
You walk away with — Evidence-ready report that drops into SOC 2, ISO 27001, PCI DSS, HIPAA requests.
Typical timeline

Two weeks, kickoff to report.

Retests happen on your schedule — up to 90 days after the report drops.

Day 0
Kickoff

Scope confirmed · creds exchanged · Slack channel live

Day 1-10
Active testing

Manual, hands-on · confirmed findings published live

Day 12
Report delivered

Executive summary + technical report + evidence packs

Within 90d
Free retest

We verify your fixes and reissue a clean report

What you get

Everything shipped as part of the engagement.

No paid add-ons. No 'premium report' tier. One price, everything below.

Executive summary

One-page brief for the boardroom — findings, severity mix, risk posture.

Technical report

Every finding with CVSS, evidence, reproduction steps, and remediation.

Evidence packs

Audit-ready artifacts formatted for SOC 2, ISO 27001, PCI DSS, HIPAA.

Live findings platform

Watch findings appear in-platform as testers confirm them — no waiting.

Shared Slack channel

Ask the tester questions during the engagement. No ticket queues.

Free retest

Once you've fixed things, we verify and reissue the report — included.

Why teams choose us

A pentest that engineers respect, and auditors accept.

Boutique-firm depth. Product-company speed. Fixed-price predictability.

Real humans, not scanners

Every finding is exploited by hand and validated by a senior engineer before it lands in your report.

One fixed price

Priced up front, no mid-engagement re-scopes. The number you saw is the number you pay.

48-hour kickoff

Sign today, kick off Wednesday. No four-week sales cycle before someone actually looks at your code.

Retest included

Fix things, we re-verify. Not an upsell — part of the original price.

Audit-drop-in reports

Formatted for the framework your auditor is asking about, not a generic template.

Same team, kickoff to retest

The tester who found the bug also verifies your fix. No handoffs, no re-onboarding.

Ready when you are

Scope your test in the next two minutes.

No sales calls to book. No spreadsheets to fill. A fixed-price quote appears on the last step — pay to confirm or hop on a call first.