Web app / API penetration testing | Assurance

For regulated teams and complex applications that need deeper coverage. Manual testing, clear evidence and actionable remediation.

Suitable for applications with AI/LLM features.

01

Scope of this package

Assessment surface
One web application or API group
Maximum user roles
5
Fix validation
One round within 90 days

One surface. Exploratory exploit chaining is scope-limited and not guaranteed. Red teaming and social engineering are excluded.

02

What you receive

  • Manual pentest with OWASP Top 10 coverage
  • Report with severity, impact, reproduction steps and fixes
  • 30-day findings Q&A by email/Slack
  • Attestation letter
  • Executive summary in your report
  • One fix-validation round within 90 days
  • Optional attestation refresh after fix validation
  • Jira / CSV issue export
  • Advanced attacks and business logic abuse
03

Optional support

One fix-validation round within 90 days is included.

04

Scope and readiness, aligned

Your project manager coordinates access, contacts and delivery timing. Typical start is 2–3 weeks; testing effort and report delivery are separate milestones.

Need something beyond these limits?Multiple applications or environments and unusual requirements can be scoped with Blaze before you purchase.
Talk to an expert

Clear findings. A direct path to remediation.

See the delivery process and reporting experience behind your purchase.

Explore buyer assurance
Compliance support

Pentests for compliance and beyond.

Support audit, customer and procurement requirements with independent testing and clear reporting.

Testing is scoped around the requirements relevant to your organization.

GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2 — compliance frameworks supported by Blaze pentests