SecureBlock

Prenota un vero test di penetrazione come acquisteresti qualsiasi altro servizio.

Definisci lo scope in due minuti, ottieni un prezzo fisso sul momento e hai tester certificati OSCP e CREST sul tuo stack entro 48 ore. I report vengono direttamente inseriti nelle richieste di evidenza per SOC 2, ISO 27001, PCI DSS e HIPAA.

Vedi un report di esempio
Testing manuale, non una scansioneRetest gratuito inclusoRisultati in 10 giorni lavorativi
Evidenze accettate per
SOC 2ISO 27001PCI DSSHIPAA
Certificazioni dei tester
OSCPCRESTOSCE
La piattaforma

Il tuo team e i tuoi tester nello stesso spazio di lavoro.

I risultati arrivano in tempo reale durante il testing. Ogni problema ha un collegamento diretto con il tester che lo ha trovato — nessuna coda di ticket, nessun account manager intermediario.

app.secureblock.io/projects/acme-corp-web/overview
SecureBlock
Dashboard
Projects
Taskboard
Team
Reports
Settings
Projects/Acme Corp — Web Application
AC
Acme Corp — Web Application
Start: 12 Jan 2026 · Due: 12 Feb 2026 · Lead: M. Kovač (OSCP)
In progress · Day 6 of 10
Overview
Vulnerabilities
Scope
Tasks
Reports
Notes
Description

Full web application and REST API penetration test covering authentication, authorisation, business logic, and OWASP Top 10 across all in-scope endpoints. Includes multi-role testing for admin, user, and guest principals.

Testing progress60%
Day 6 of 10 · report est. Day 12
Open findings5
1 Crit2 High1 Med1 Low
Activity
MK
M. Kovačadded findingCritical · 9.1

Horizontal IDOR on /api/v2/invoices/{id}

2h ago
DO
Dana O.commented

Does the list endpoint also leak cross-tenant IDs? Pagination might expose them too.

2h ago
MK
M. Kovačreplied

Confirmed — /api/v2/invoices has the same missing ownership check. Updating this finding to include it.

3h ago
DO
Dana O.set "Mass assignment" status toFix verified
5h ago
SB
SystemProject started · NDA signed · credentials confirmed
Day 3
MK
Add a comment…Send
AI
AI Assistantonline

What's the best remediation for the Horizontal IDOR on /api/v2/invoices/{id}?

AI

Root cause is a missing ownership check server-side. The API returns data for any valid integer ID regardless of the caller's tenant.

  • ›Validate tenant_id ownership before returning any resource
  • ›Replace sequential integer IDs with UUIDs or opaque tokens
  • ›Add a server-side assertion: if invoice.tenant_id ≠ current_user.tenant_id → 403

Should we also add rate limiting to prevent enumeration?

AI

Yes — ownership checks are the fix, but rate limiting limits blast radius if a similar issue surfaces elsewhere. Also add audit logging for any 403s on resource endpoints.

Ask about this finding…Ask

We scoped on a Tuesday and testing started that Thursday. The report went straight into our SOC 2 evidence folder untouched — our auditor had zero follow-ups.

Dana Okonjo
CTO, Ledgerpath
SOC 2 Type II · 2026

“The findings read like they were written by someone who had actually used the product.”

Marcus Reid · Head of Security, Fernwood

“Retest was included and turned around in three days, so we closed the audit finding in the same quarter.”

Priya Nandakumar · VP Engineering, Certiv
Come funziona

Da "abbiamo bisogno di un pentest" a pianificato in una sola sessione.

Nessuna RFP, nessun ciclo di vendita di tre settimane, nessun foglio di calcolo per lo scoping.

STEP 01
Definisci lo scope tu stesso

Scegli i tipi di asset e rispondi a quattro domande. Due minuti, nessuna chiamata necessaria.

STEP 02
Ottieni un prezzo fisso

Un preventivo trasparente con il moltiplicatore di scope e il retest mostrati riga per riga.

STEP 03
Blocca le date

Paga subito oppure approva dopo una chiamata di scoping. In entrambi i casi la finestra temporale è riservata.

STEP 04
Inizio del testing

I tester certificati lavorano manualmente. I risultati appaiono nella piattaforma man mano che vengono confermati.

STEP 05
Report e retest

Report pronto per l'audit in 10 giorni lavorativi, seguito da un retest gratuito per la verifica delle correzioni.

Copertura

Ogni superficie che sviluppi, testata manualmente.

Scegli uno o tutti e sei i tipi di asset — lo scope determina il prezzo e non viene incluso nulla di cui non hai bisogno.

Piattaforma

Il tuo pentest non si conclude in un PDF.

Ogni incarico viene eseguito tramite la piattaforma SecureBlock — risultati, conversazioni con i tuoi tester, retest ed esportazioni di evidenze, tutto in un unico posto.

I report vivono nella piattaforma

I risultati arrivano man mano che vengono confermati — non come PDF tre settimane dopo. Esporta le evidenze nel momento in cui il tuo auditor le richiede.

Parla direttamente con i tester

Commenta qualsiasi risultato e il tester che lo ha scritto risponde. Nessuna coda di ticket, nessun account manager intermediario.

Gestisci l'intero incarico

Scope, pianificazioni, credenziali, richieste di retest e accesso del team — un unico posto, con una traccia di audit completa.

app.secureblock.io/projects/acme-corp-web/vulnerabilities
Projects/Acme Corp — Web Application
AC
Acme Corp — Web Application
Start: 12 Jan 2026 · Due: 12 Feb 2026 · Lead: M. Kovač (OSCP)
In progress · Day 6 of 10
Overview
Vulnerabilities
Scope
Tasks
Reports
Notes
Vulnerabilities4
Export evidence+ Add finding
#DateTitleSeverityStatus
0114 JanHorizontal IDOR on /api/v2/invoices/{id}criticalOpen
0214 JanMass assignment on POST /users/profilehighFix verified
0315 JanSession fixation on password reset flowmediumRetest requested
0415 JanMissing HSTS preload on marketing subdomainlowOpen
Metodologia

Profondità verificabile, non solo dichiarata.

Ogni incarico segue OWASP WSTG, PTES e NIST SP 800-115, eseguito da tester che detengono OSCP, CREST CRT o OSCE.

OWASP WSTGPTESNIST SP 800-115MITRE ATT&CK
Giorno 0
Chiamata di kickoff

Scope confermato, credenziali scambiate, NDA firmato.

Giorni 1-10
Testing attivo

Testing manuale. I risultati confermati vengono pubblicati man mano che emergono.

Giorno 12
Report consegnato

Report pronto per l'audit con la remediation per ogni risultato.

Entro 90 giorni
Retest gratuito

Verifichiamo le tue correzioni e remettiamo il report.

app.secureblock.io/projects/acme-corp-web/findings/sb-01
Projects/Acme Corp/Vulnerabilities/Horizontal IDOR — invoices
Horizontal IDOR on /api/v2/invoices/{id}
Description

An authenticated user can access invoice records belonging to other tenants by substituting their own resource identifier in the URL path. The ownership check is absent server-side — the API returns data for any valid integer ID regardless of the caller's tenant.

Steps to reproduce
  1. 1. Authenticate as Tenant A. Retrieve any invoice: GET /api/v2/invoices/1842
  2. 2. Replace the ID with a known Tenant B value: GET /api/v2/invoices/1843
  3. 3. Server returns 200 OK with Tenant B billing data.
Impact

Complete tenant isolation bypass. Any authenticated user can enumerate and exfiltrate invoice data, payment terms, and line items for every customer in the system.

Vulnerability context
Risk
critical9.1
Target
api.acme.com
Day 2 of 10
Status
Open
Created by
M. Kovač
OSCP · 14 Jan 2026
Affected asset
/api/v2/invoices/{id}
Compliance

Di quale report ho bisogno?

Scegli il tuo framework e ti mostreremo lo scope e la cadenza che gli auditor si aspettano.

Scope richiesto
Web app esterna + API nell'ambito dei criteri dei trust services
Frequenza
Annualmente
Retest
Richiesto dagli auditor
Gli auditor di tipo II richiedono evidenza che le vulnerabilità siano state remediate — il retest gratuito lo copre.
Prezzi

Prezzo fisso. Nessuna chiamata commerciale. Preventivo in due minuti.

Rispondi a quattro domande sul tuo scope e ottieni il numero esatto di cui il tuo team finanziario ha bisogno per approvare.

1Tipo di asset2Dimensione dello scope3Profondità di autenticazione4Framework di compliance
= il tuo prezzo fisso

Nessun SOW personalizzato, nessun "prezzi su richiesta." Il modulo richiede due minuti e si conclude con un numero su cui puoi agire immediatamente.

Tutti i tester OSCP o CRESTRetest gratuito entro 90 giorniAvvio entro 48 ore
FAQ

Le domande che fanno davvero i clienti.

Hai ancora dubbi? Chiedi a un ingegnere in chat, non a un commerciale.

Il tempo di avvio standard è da due a tre settimane dal checkout; gli incarichi urgenti iniziano entro 48 ore dalla chiamata di kickoff. Il testing attivo dura da 5 a 15 giorni lavorativi a seconda dello scope, e il report arriva due giorni dopo la fine del testing.

Sappi dove ti trovi prima che lo faccia il tuo auditor.