THREATNEST

Application security audits

A defined scope, manual testing, clear evidence, and a report your developer can use.

Standard assessment

Website Security Audit

Standard assessment: USD 2,000

For independent healthcare clinics, dental practices, and medical centers operating patient facing web applications.

OWASP-guided manual testing / PHI tracking exposure review / Security configuration review / Full PDF report / Plain-English executive summary / Prioritized remediation guidance / One included retest within 14 days.

How the audit works.

We agree on the scope first, test by hand, and send a remediation blueprint with proof, severity, affected assets, business impact, and fixes. No destructive actions. Reports and access details stay strictly confidential.

01

Recon

We map the public attack surface first: domains, frameworks, hidden endpoints, and anything already exposed.

02

Config review

We check headers, TLS, cookies, exposed files, admin paths, and the kind of setup problems that cause avoidable risk.

03

Auth testing

We test login, reset, session handling, enumeration, and takeover paths that affect real accounts.

04

Logic testing

We look for access issues, forced browsing, workflow mistakes, and business logic problems scanners usually miss.

05

Input validation

We review in-scope forms, APIs, and uploads for injection, cross-site scripting, request forgery, redirect, and file handling issues.

06

Manual verification

Every reported finding is reproduced by hand, false positives are removed, and the result is documented with evidence and remediation steps.

Report and retest.

You receive a full PDF report, a plain-English executive summary, detailed findings, and one included retest after fixes.

Full PDF report with every verified finding

Plain-English executive summary

Severity using CVSS 3.1 and practical business impact

Affected component, technical evidence, and reproduction detail

Prioritized remediation guidance for the developer

Optional written Q&A within seven days of report delivery

One included retest requested within 14 days of report delivery

Scope

Application, pages, and systems are defined before testing.

Payment

The standard USD 2,000 fee is split 50% upon signing and 50% when the final report is delivered.

Timing

Testing runs during the agreed seven-day window; the final report follows within 48 hours after testing is completed.

Authorization

A request, call, email, or payment does not authorize testing. A completed, signed Service Agreement containing the Authorization to Test is required.

USD 2,000 fixed

The standard scope has no hidden costs: 50% upon signing and 50% when the final report is delivered.

Seven-day testing window

Testing begins after the agreement, scope, required deposit, access, and testing window are confirmed.

Report within 48 hours

The full PDF report and plain-English executive summary are delivered within 48 hours after testing is completed.

Included retest

One retest of the original findings is included when requested within 14 calendar days after the final report is delivered.

Ready to start?

Send your website URL and a short description of your application. We will confirm scope, explain the assessment process, and provide the next steps.