IReview · ₹50,000 · 5 working days
Five working days. ₹50,000. A straight answer.
fixed price · fixed scope · one app, one environment
For a web application that's about to launch, about to raise, or about to be shown to a customer who'll ask hard questions. You don't need a full penetration test yet — you need someone who does this for a living to look properly and tell you the truth.
What's covered
One web application, one environment, with source access.
In five working days I check all of this — and the class of bug I find most often, in apps of every size, is the second one.
- 01Authentication and session handlingSignup, login, reset, tokens, logout, what happens when they're wrong.
- 02Access controlWhether user A can read or change user B's data by changing an ID, a role or a request.
- 03Input handlingInjection, cross-site scripting, unsafe file handling.
- 04CORS and cross-origin configurationWhat another origin can read, send or trigger.
- 05Security headers, CSP, TLS and cookie flagsThis site is the reference; check it.
- 06SecretsIn the codebase and across the full git history, not just the current commit.
- 07Dependencies with known vulnerabilitiesAudited and listed with what to do about each.
- 08Deployment and configuration basicsExposed admin surfaces, debug modes, default credentials, storage buckets.
IIWhat you get
A written findings document, each with what it is, why it matters to your business, how to reproduce it, and how to fix it. A 30-minute walkthrough call.
If I find nothing that needs fixing, the document says so, and I won't invent findings to justify the fee or sell you a pentest you don't need.
Findings ranked by severity. If there are none, the document says so.
Price and timeline
Fixed price, fixed scope — if the application is much larger than a single app in one environment, I'll tell you before starting, not after.
- ₹50,000
- fixed · one app · one environment
- 5 working days
- from access to written findings
- 8
- areas checked, listed above
- 30 min
- walkthrough call with your developers
What it isn't
A review by one person in one week.
It isn't a full penetration test, and it won't find everything a two-week manual test finds. If your application is high-risk enough to need that, I'll tell you on day one — and if you book the test within 30 days, the ₹50,000 is credited against it.
It isn't a compliance certificate.
Questions founders ask
Before you book
Is the review a compliance certificate?
No. It is a written findings document from one experienced person in one week, ranked by severity with reproduction steps and fixes. It is not a certificate and I will never call it one.
How is a review different from a penetration test?
A review is five working days on one application in one environment with source access, checking the eight areas listed on this page. A penetration test is a longer manual engagement with a wider scope and a report in the public sample format. If your application needs the test, I say so on day one, and the review fee is credited against it if you book within 30 days.
What do you need from me to start?
Source access, one environment, test accounts at each role, and written authorisation. There is a free rules-of-engagement template at amansploit.com.
What if you find nothing?
Then the document says so. I do not invent findings to justify the fee, and I do not sell you a penetration test you do not need.
What does it cost and how long does it take?
₹50,000, fixed. Five working days from access to written findings, plus a 30-minute walkthrough call.
IIIBook a review
Ready to launch, or ready to find out?
Send the URL and a line about what it does. I reply within one working day.