Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Testing models ]

White Box Penetration Testing

Source code, architecture and admin access. Maximum depth, nothing held back.
Typical duration
10-15 days
Starting price
Scoped
You provide
Source code, architecture, admin credentials

[ 01 / The engagement ]

White box removes the guessing entirely. With source, architecture and privileged access, we read the code where behaviour is ambiguous and test the paths a black box engagement would never reach, cryptographic implementation, race conditions, deserialisation, and the quiet assumptions between services. It is the model to choose before a launch, an audit, or a first enterprise customer.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

OWASP ASVS L3OWASP SCVSCWE Top 25
  1. 01Manual source review of authentication, authorisation and crypto paths
  2. 02Insecure deserialisation and unsafe reflection
  3. 03Race conditions and time-of-check/time-of-use flaws
  4. 04Secrets handling, key rotation and storage
  5. 05Dependency and supply-chain exposure with reachability analysis
  6. 06Server-side request forgery through internal service topology
  7. 07CI/CD pipeline and build-time trust boundaries

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ New ]

No high or critical findings?
We refund the invoice.

For qualifying manual assessments where we have full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee back on your invoice. Confirmed in writing before we touch a packet.

Applies to grey box and white box engagements. Excludes black box, scans, and retests. Terms set in the engagement letter.

[ 04 / Questions ]

Before you commit.

No. Read access to the services in scope is enough. Code stays in your systems wherever you prefer. We can work over your VDI or a time-boxed read-only account, and we sign an NDA before scoping.

Both, deliberately. We use the code to find candidate flaws, then exploit them in a running instance so every finding in the report comes with a working proof, not a static-analysis warning.

Scope a white box penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.