Services / Dedicated pentest

Dedicated pentest

Tell us what may be tested. We review the product, send the quote, and track the work through the portal.

Pentest engagements are currently available only in Brazil.

01How it works

A simple process, with every stage visible in the portal.

You send the product details. We review the material, send the quote, and begin the pentest on the agreed date after payment.

01

Pentest registration

You describe the product, authorized assets, restrictions, and rules of engagement.

02

Technical review

We review the material and contact you if anything is missing.

03

Quote

You receive the price, payment terms, and expected dates before hiring.

04

Confirmation

Payment confirms the stated window and places the pentest in the queue.

05

Execution and delivery

During the test, you can track progress and receive reports through the portal.

02Definition and classification

You define what we may test.

Registration captures the product context, authorized assets, and restrictions. We use that information to prepare the work and define the pentest size.

Registration details

Provide what we need to understand the product and the authorization boundaries.

01Assessment objective and product description
02URLs, APIs, applications, IPs, repositories, and other assets
03Items authorized and excluded from testing
04Access, windows, restrictions, and prohibited actions
05Responsible contacts and supporting documentation

Pentest classification

We classify the pentest as small, medium, or large. The category reflects the product size and the number of paths that need testing.

01

Type 1 · Small

Focused product with few flows, profiles, and business rules.

Execution timeline
Around 7 business days
02

Type 2 · Medium

Product with related flows, permissions, states, or integrations.

Execution timeline
Around 10 business days
03

Type 3 · Large

Broad platform with several modules, profiles, services, or codebases.

Execution timeline
Usually 15 business days or more

We classify the pentest manually after technical review. The exact price appears in the quote.

03Quote, schedule, and timelines

The quote shows what matters before payment.

You receive the pentest size, price, payment terms, and expected dates. The quote remains available for 3 calendar days.

Payment

Type 1 is paid in full before work begins. For Types 2 and 3, you pay 40% to confirm the pentest and the remaining 60% when the final report is ready. If you need to cancel before delivery, contact us so we can review the work completed and the refund.

Date reservation

The quote holds the stated window for 3 calendar days. Payment confirms the date and places the pentest in the queue. Without payment by the deadline, the window becomes available again.

If the schedule is full, the portal will tell you. We send the quote as soon as a suitable date becomes available.

Main timelines

01

Technical review

Within 2 business days of submission

If we need more information, we contact you through the registered channel.

02

Payment

Within 3 calendar days of the quote

The stated date remains reserved during this period.

03

Estimated start

Next business day after payment

The portal updates the date as soon as payment is confirmed.

04

Execution

Counted from the actual start

If a dependency pauses the work, the reason appears in the portal.

04Execution and reports

Progress and deliveries stay in one place.

After the initial payment, the pentest enters the queue. When work begins, the portal shows its progress and starts the execution timeline.

01

Queued

Reservation confirmed and estimated start date defined.

02

In progress

Assessment started and execution timeline running.

03

Paused

Timeline suspended while a dependency prevents progress.

If an access or another required detail is missing, the timeline may be paused. The reason and revised estimate appear in the portal.

Alerts and preliminary reports

Vulnerabilities requiring immediate attention are communicated as soon as they are confirmed. Each preliminary report remains available in the portal with its submission date and time.

Final report

The report consolidates impact, evidence, reproduction, and remediation guidance. For payments made in full, the complete file is released at completion. For split payments, the final report is shown as ready and remains locked until payment of the remaining 60% of the quote's total amount; preliminary reports remain accessible throughout the process.

After delivery, we remain available to clarify findings and coordinate possible retests.

05Communication

When a question comes up, the conversation stays direct.

We contact you through the account email and, when provided, WhatsApp. The same channel follows the pentest from review through delivery.

01

Review

Context confirmation, access requests, and clarification of the authorized boundaries.

02

Execution

Operational coordination, dependencies, and communication of relevant vulnerabilities.

03

After delivery

Finding clarification, help interpreting evidence, and retest coordination.

Work-related messages are retained for a limited period to preserve continuity, traceability, and security.

06 / Start

Register the pentest for review.

Describe the product, what may be tested, and the required rules. You can review everything before submission.

Register pentest