[ Testing models ]
White Box Penetration Testing
- Typical duration
- 10-15 days
- Starting price
- Scoped
- You provide
- Source code, architecture, admin credentials
[ 01 / The engagement ]
White box removes the guessing entirely. With source, architecture and privileged access, we read the code where behaviour is ambiguous and test the paths a black box engagement would never reach, cryptographic implementation, race conditions, deserialisation, and the quiet assumptions between services. It is the model to choose before a launch, an audit, or a first enterprise customer.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Manual source review of authentication, authorisation and crypto paths
- 02Insecure deserialisation and unsafe reflection
- 03Race conditions and time-of-check/time-of-use flaws
- 04Secrets handling, key rotation and storage
- 05Dependency and supply-chain exposure with reachability analysis
- 06Server-side request forgery through internal service topology
- 07CI/CD pipeline and build-time trust boundaries
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ New ]
No high or critical findings?
We refund the invoice.
For qualifying manual assessments where we have full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee back on your invoice. Confirmed in writing before we touch a packet.
Applies to grey box and white box engagements. Excludes black box, scans, and retests. Terms set in the engagement letter.
[ 04 / Questions ]
Before you commit.
No. Read access to the services in scope is enough. Code stays in your systems wherever you prefer. We can work over your VDI or a time-boxed read-only account, and we sign an NDA before scoping.
Both, deliberately. We use the code to find candidate flaws, then exploit them in a running instance so every finding in the report comes with a working proof, not a static-analysis warning.
Often scoped together
All services →Black Box Penetration Testing
We start with your domain name and nothing else, exactly like a real attacker.
Grey Box Penetration Testing
Standard user credentials, no source code. The best coverage per pound spent.
Web Application Penetration Testing
Manual testing of the application your customers actually log in to.
Scope a white box penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.