Type 1 · Small
Focused product with few flows, profiles, and business rules.
- Execution timeline
- Around 7 business days
Define what may be tested and follow a security assessment conducted directly by a researcher through the portal.
Pentest engagements are currently available only in Brazil.
The portal organizes engagement and progress. Technical analysis combines investigation, automation, and validation according to the scope.
You describe the product, authorized assets, restrictions, and rules of engagement.
We review the material, clarify questions, and classify the pentest by size.
You receive the price, payment terms, and expected timeline. The estimated start uses the next business day after payment.
Initial payment confirms the stated window and places the pentest in the queue.
The portal tracks execution, early alerts, documents, and the final report.
Registration captures the technical context and authorization boundaries. We use this information to assign the pentest to one of the three categories below.
Registration should provide the information needed to understand the product, define the authorization boundaries, and prepare execution.
The category summarizes the size and technical variety of the work and sets the estimated execution timeline. The timelines below are best-case estimates and may be extended by blockers or dependencies during the work, with the revised estimate recorded in the portal.
Focused product with few flows, profiles, and business rules.
Product with related flows, permissions, states, or integrations.
Broad platform with several modules, profiles, services, or codebases.
We manually define the classification and effort index after technical review. The Pricing page explains the calculation criterion for each category.
It states the classification, price, payment structure, estimated start date, and execution timeline. Payment is available for up to 3 calendar days.
Type 1 is paid in full before work begins. For Types 2 and 3, the deposit is 40% of the total amount and the 60% balance is paid when the final report is ready for release. Before final delivery, you may also request cancellation and discuss a refund with us based on work progress.
The schedule has a limited number of shared slots across ongoing work. After review, we find a window compatible with the pentest. When the quote is issued, that window is held for 3 calendar days. Initial payment confirms the reservation and places the estimated start on the next business day; the assessment may begin earlier when capacity is available. Without payment by the deadline, the window returns to the schedule.
If capacity is occupied, the portal shows that the pentest is waiting for availability. The quote is issued as soon as a compatible date can be offered.
The clock pauses while required information is pending.
This is also the temporary hold period for the window.
The date updates when payment is confirmed. The assessment may begin earlier when capacity is available.
The clock begins when work is in progress and access is available.
After initial payment, the pentest enters the queue with an estimate for the next business day. Execution may begin earlier; when work starts, the status changes to in progress and the timeline begins.
Reservation confirmed and estimated start date defined.
Assessment started and execution timeline running.
Timeline suspended while a dependency prevents progress.
Credentials, access releases, environment restoration, or other client dependencies may pause the timeline. The reason and revised estimate are recorded in the portal.
Vulnerabilities requiring immediate attention are communicated as soon as they are confirmed. Each preliminary report remains available in the portal with its submission date and time.
The report consolidates impact, evidence, reproduction, and remediation guidance. For payments made in full, the complete file is released at completion. For split payments, the final report is shown as ready and remains locked until payment of the remaining 60% of the quote's total amount; preliminary reports remain accessible throughout the process.
After delivery, we remain available to clarify findings and coordinate possible retests.
The account email and, when provided, WhatsApp are available from the beginning of the review. Message-based communication follows the engagement from start to finish.
Context confirmation, access requests, and clarification of the authorized boundaries.
Operational coordination, dependencies, and communication of relevant vulnerabilities.
Finding clarification, help interpreting evidence, and retest coordination.
Work-related messages are retained for a limited period to preserve continuity, traceability, and security.
Describe the product, what may be tested, and the required rules. You can review everything before submission.
Register pentest