Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Testing models ]

Grey Box Penetration Testing

Standard user credentials, no source code. The best coverage per pound spent.
Typical duration
5-10 days
Starting price
Scoped
You provide
Low-privilege credentials, basic architecture notes

[ 01 / The engagement ]

Grey box is what we recommend to most teams, most of the time. We get the same credentials one of your ordinary users would have, nothing privileged, and spend the engagement on what sits behind the login rather than on getting through it. Broken access control, tenant isolation, privilege escalation and business-logic flaws all live in that space, and a black box test rarely reaches them.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

OWASP ASVS L2OWASP Top 10PTES
  1. 01Horizontal and vertical privilege escalation between roles
  2. 02Multi-tenant isolation and object-level authorisation (IDOR)
  3. 03Business-logic abuse: pricing, quotas, workflow and state machines
  4. 04Session handling, token lifetime and revocation
  5. 05Server-side injection reachable only by authenticated users
  6. 06File upload, export and reporting features as an execution path
  7. 07Internal API surfaces exposed to the browser

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ New ]

No high or critical findings?
We refund the invoice.

For qualifying manual assessments where we have full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee back on your invoice. Confirmed in writing before we touch a packet.

Applies to grey box and white box engagements. Excludes black box, scans, and retests. Terms set in the engagement letter.

[ 04 / Questions ]

Before you commit.

At least two accounts per role you want tested, so we can prove cross-account access rather than just describing it. Two roles is the practical minimum; more roles means more coverage and a slightly longer scope.

We prefer one that mirrors production. If you only have production we will work there, with agreed rate limits, an agreed window and a named contact reachable throughout.

Scope a grey box penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.