Services / Dedicated pentest

Dedicated pentest

Define what may be tested and follow a security assessment conducted directly by a researcher through the portal.

Pentest engagements are currently available only in Brazil.

01How it works

A straightforward path from registration to report.

The portal organizes engagement and progress. Technical analysis combines investigation, automation, and validation according to the scope.

01

Pentest registration

You describe the product, authorized assets, restrictions, and rules of engagement.

02

Technical review

We review the material, clarify questions, and classify the pentest by size.

03

Quote

You receive the price, payment terms, and expected timeline. The estimated start uses the next business day after payment.

04

Scheduling

Initial payment confirms the stated window and places the pentest in the queue.

05

Execution and delivery

The portal tracks execution, early alerts, documents, and the final report.

02Definition and classification

First, we define what will be tested.

Registration captures the technical context and authorization boundaries. We use this information to assign the pentest to one of the three categories below.

Registration details

Registration should provide the information needed to understand the product, define the authorization boundaries, and prepare execution.

01Assessment objective and product description
02URLs, APIs, applications, IPs, repositories, and other assets
03Items authorized and excluded from testing
04Access, windows, restrictions, and prohibited actions
05Responsible contacts and supporting documentation

Pentest classification

The category summarizes the size and technical variety of the work and sets the estimated execution timeline. The timelines below are best-case estimates and may be extended by blockers or dependencies during the work, with the revised estimate recorded in the portal.

01

Type 1 · Small

Focused product with few flows, profiles, and business rules.

Execution timeline
Around 7 business days
02

Type 2 · Medium

Product with related flows, permissions, states, or integrations.

Execution timeline
Around 10 business days
03

Type 3 · Large

Broad platform with several modules, profiles, services, or codebases.

Execution timeline
Usually 15 business days or more

We manually define the classification and effort index after technical review. The Pricing page explains the calculation criterion for each category.

03Quote, schedule, and timelines

The quote records what was agreed.

It states the classification, price, payment structure, estimated start date, and execution timeline. Payment is available for up to 3 calendar days.

Payment

Type 1 is paid in full before work begins. For Types 2 and 3, the deposit is 40% of the total amount and the 60% balance is paid when the final report is ready for release. Before final delivery, you may also request cancellation and discuss a refund with us based on work progress.

Availability and reservation

The schedule has a limited number of shared slots across ongoing work. After review, we find a window compatible with the pentest. When the quote is issued, that window is held for 3 calendar days. Initial payment confirms the reservation and places the estimated start on the next business day; the assessment may begin earlier when capacity is available. Without payment by the deadline, the window returns to the schedule.

If capacity is occupied, the portal shows that the pentest is waiting for availability. The quote is issued as soon as a compatible date can be offered.

Each timeline begins at a specific point

01

Technical review

Within 2 business days of submission

The clock pauses while required information is pending.

02

Payment

3 calendar days after the quote

This is also the temporary hold period for the window.

03

Estimated start

Next business day after payment

The date updates when payment is confirmed. The assessment may begin earlier when capacity is available.

04

Execution

From the actual start

The clock begins when work is in progress and access is available.

04Execution and reports

The portal follows the work through delivery.

After initial payment, the pentest enters the queue with an estimate for the next business day. Execution may begin earlier; when work starts, the status changes to in progress and the timeline begins.

01

Queued

Reservation confirmed and estimated start date defined.

02

In progress

Assessment started and execution timeline running.

03

Paused

Timeline suspended while a dependency prevents progress.

Credentials, access releases, environment restoration, or other client dependencies may pause the timeline. The reason and revised estimate are recorded in the portal.

Alerts and preliminary reports

Vulnerabilities requiring immediate attention are communicated as soon as they are confirmed. Each preliminary report remains available in the portal with its submission date and time.

Final report

The report consolidates impact, evidence, reproduction, and remediation guidance. For payments made in full, the complete file is released at completion. For split payments, the final report is shown as ready and remains locked until payment of the remaining 60% of the quote's total amount; preliminary reports remain accessible throughout the process.

After delivery, we remain available to clarify findings and coordinate possible retests.

05Communication

The portal and direct conversation work together.

The account email and, when provided, WhatsApp are available from the beginning of the review. Message-based communication follows the engagement from start to finish.

01

Review

Context confirmation, access requests, and clarification of the authorized boundaries.

02

Execution

Operational coordination, dependencies, and communication of relevant vulnerabilities.

03

After delivery

Finding clarification, help interpreting evidence, and retest coordination.

Work-related messages are retained for a limited period to preserve continuity, traceability, and security.

06 / Start

Register the pentest for review.

Describe the product, what may be tested, and the required rules. You can review everything before submission.

Register pentest