Usually a reply within one working day
Tell us what the system does
and what worries you.
The more you can say here, the more useful our first reply is. If a penetration test is not what you need yet, we will tell you that too.
- No obligationScoping costs you a conversation, not a commitment.
- Under NDA as standardHappy to sign yours rather than insist on ours.
- A person, not a queueYou speak to someone who will be on the engagement.
- Straight answer on fitWe turn down work that we are not the right people for.
What happens next
From this form to a fixed proposal
Four steps, and you can stop at any of them.
- 1
You send this form
One message, no obligation. It goes to a person, not a queue.
- 2
We reply within one working day
With scoping questions if we need them, or straight to a proposal if what you have written is already enough.
- 3
A scoping call
Half an hour, remote. We go through the application, the roles and what would hurt most if it went wrong.
- 4
A proposal with a fixed timeline
Scope, duration and price, with the retest included. If a penetration test is not what you need yet, this is where we tell you.
Other ways
Not a scoping request?
Email us directly at info@appsec-labs.com — or take one of these instead.
Careers
We are hiring application security specialists. Roles, and what it is like to work here.
GoBuy through Azure
Already procuring through Microsoft? You can commission the engagement on your existing agreement, as a private offer carrying the scope we agree.
GoRead the catalogue first
276 published test cases across 42 categories. Plenty of people scope their own engagement from it before getting in touch.
GoBefore you write
The questions we are asked most
What does a penetration test cost?
It is driven by scope: the size of the application, how many roles and workflows exist, whether APIs and mobile clients are included, and how deep you want us to go. We scope properly before quoting, so the number you get is the number.
What do you need from us to start?
A description of the application and what matters most about it, an environment to test against (staging that mirrors production is ideal), and credentials for each user role. Roles matter more than anything else.
How do you handle our data?
Confidentially, under NDA, as standard. Findings and reports are treated as sensitive material — they are effectively a map of how to attack you. We are happy to sign your agreement rather than insist on ours.
Will testing disrupt production?
We prefer to test against staging for that reason. Where production testing is necessary we agree the boundaries in advance — what is in scope, what techniques are excluded, and a contact who can reach us immediately.
The formal bit
Company details
AppSec Application Security Ltd. — trading as AppSec Labs
Registered in Israel, company number 514521335
Hataas 20, Kfar Saba, Israel
info@appsec-labs.com · +972-9-7485005