THREATNEST

Website Security Audit

A fixed-scope application penetration test for independent healthcare clinics, dental practices, and medical centers operating patient-facing websites.

USD 2,000 fixed

No hidden costs: 50% upon signing and 50% when the final report is delivered.

Seven-day testing window

Testing begins after the signed agreement, scope, deposit, access, and testing window are confirmed.

Report within 48 hours

The full PDF report is delivered within 48 hours after testing is completed.

Included retest

One retest of the original findings when requested within 14 calendar days after report delivery.

In scope

The website domain and any subdomains authorized in writing.

Contact, appointment request, and new-patient forms.

Tracking pixels and third-party scripts on patient-facing pages.

Patient portal login, registration, password reset, and session handling when present.

File uploads and public website APIs when present.

Exposed admin panels, login pages, files, and configuration details.

Security headers, TLS configuration, and cookie flags.

CMS, site-builder, and plugin versions.

Error messages, information disclosure, access control, and input validation.

Out of scope

Denial of service, load, stress, destructive, or availability testing.

Phishing, impersonation, social engineering, physical security, or ransomware simulation.

Internal networks, wireless systems, employee personal accounts, or unrelated systems.

Third party services the client does not own or have written authority to include.

Intentional exfiltration or exploitation beyond the minimum proof needed to validate a finding.

How the audit runs.

The assessment follows the OWASP Web Security Testing Guide and OWASP Top 10. We agree scope, test by hand, and document proof, severity, affected assets, business impact, and clear fixes.

01

Reconnaissance

We map the authorized public surface, including subdomains, technology, hidden pages, scripts, and exposed files.

02

Configuration review

We review TLS, HTTP security headers, cookie flags, exposed configuration files, and verbose error pages.

03

Authentication and sessions

Where present, we assess login, registration, password reset, rate limiting, and session handling.

04

Access control and form logic

We manually review access controls on authorized patient-facing forms and private pages.

05

Input validation

We review in-scope forms, APIs, and uploads for injection, cross-site scripting, request forgery, redirect, and file handling issues.

06

Verification and reporting

Every reported finding is reproduced by hand, false positives are removed, and evidence is limited to what is needed.

Remediation blueprint and retest.

Full PDF report with a plain-English executive summary

Detailed findings with severity, affected component, evidence, and business impact

CVSS 3.1 risk rating combined with practical impact

Concrete, prioritized remediation guidance

Optional written Q&A within seven days after report delivery

One included retest requested within 14 days after report delivery

Final report delivered within 48 hours after the seven-day testing window is completed

Findings, screenshots, credentials, business data, and the report are treated as confidential.

A penetration test is limited in time and covers the agreed scope. It does not guarantee that every vulnerability will be found or certify legal or regulatory compliance.

01

Scope and sign

We define the included systems and complete the Service Agreement and Authorization to Test.

02

Prepare

The 50% deposit clears, required access is provided, and the testing window and emergency contact are confirmed.

03

Seven-day testing window

The authorized live application is assessed using OWASP WSTG and OWASP Top 10 guidance.

04

Report delivery

The full PDF report and executive summary are delivered within 48 hours after testing is completed.

05

Retest

One retest of remediated original findings is available when requested within 14 days after report delivery.

Production reveals real application behavior.

A live patient facing application shows the routes, headers, login flow, tracking scripts, and setup outsiders can actually reach.

What gets checked

Auth, sessions, and account abuse paths

Access control, input handling, and APIs

PHI tracking exposure and third party JavaScript

Headers, cookies, TLS, and exposed files

Report and retest

Full PDF report and plain-English executive summary

Findings with proof, severity, and business impact

Remediation guidance for your developer

One included retest requested within 14 days

Ready to send the target?

Send your website URL and a short description of your application. We will confirm scope, explain the assessment process, and provide the next steps. A request, introductory call, payment, or ordinary email does not authorize testing.