Our Assessment
Methodology
We follow industry best practices, blending automated scanning with deep manual testing to uncover complex vulnerabilities.
Black Box
Simulating an external hacker attack without prior information about your system. The tester only knows the target URL and attempts to penetrate the system like a real-world attacker.
- ✓Real-world attacker perspective
- ✓Uncover vulnerabilities exposed to the public
- ✓Test your perimeter defense
- ✓Suitable for compliance requirements (PCI DSS, Security Audits)
Grey Box
Testing with limited information such as standard user accounts. Simulating insider threat scenarios or an attacker who gained initial access to the system.
- ✓Balance between coverage and efficiency
- ✓Focus on privilege escalation
- ✓Find business logic flaws in business process
- ✓More time-efficient execution
White Box
Comprehensive testing with full access to source code, documentation, and infrastructure. Includes code review and architecture analysis.
- ✓Most thorough coverage (including code-level vulnerabilities)
- ✓Detect logic bombs and backdoors
- ✓Code review for secure coding practices
- ✓Detailed remediation guidance
Scope &
Complexity Tiers
SIMPLE
- • Static website or basic WordPress
- • 5-20 pages/endpoints
- • Minimal or no database interaction
- • Simple authentication (admin panel only)
- • No payment gateway
- • No API integration
- • Shared hosting or basic VPS
- ✓ OWASP Top 10 basic checks
- ✓ Authentication testing
- ✓ Input validation
- ✓ SSL/TLS configuration
- ✓ Basic information disclosure
MEDIUM
- • Dynamic web application with database
- • 20-50 endpoints/pages
- • User authentication & role-based access
- • Form processing & file upload
- • Payment gateway integration
- • CRUD operations
- • REST API (basic)
- ✓ Full OWASP Top 10
- ✓ Business logic testing
- ✓ Session management
- ✓ Authorization bypass attempts
- ✓ API security testing
- ✓ File upload vulnerabilities
- ✓ Payment flow security
COMPLEX
- • Multi-tier architecture
- • 50-100+ endpoints
- • Complex user roles & permissions
- • Multiple API integrations
- • Real-time features (WebSocket)
- • Mobile app backend
- • Cloud infrastructure (AWS/GCP/Azure)
- ✓ OWASP Top 10 + API Security
- ✓ Advanced business logic flaws
- ✓ Race conditions
- ✓ GraphQL/REST API deep testing
- ✓ Third-party integration security
- ✓ Mobile API security
- ✓ Cloud misconfigurations
Client
Requirements
Required Preparation
- Scope definition: Target URL/IP, In-scope subdomains, Allowed hours
- Legal docs: Signed agreement, Auth letter, NDA
- Emergency contact: Tech support (24/7), Escalation contact
- Preparation: System backup prior to testing, IT team info
X NOT Required
- User credentials
- Source code
- Documentation (Architecture, etc.)
- Infrastructure details
Testing Process
Pre-engagement
Kickoff meeting, scope finalization, legal agreement signing, access provisioning, and rules of engagement (2-3 days).
Reconnaissance
Information gathering, asset discovery, attack surface mapping, and threat modeling (1-2 days).
Active Testing
Vulnerability scanning, manual exploitation, business logic testing, privilege escalation attempts (3-15 days).
Reporting
Vulnerability documentation, risk assessment, proof of concept creation, executive summary (2-3 days).
Presentation
Findings presentation, Q&A session, remediation roadmap discussion, and priority setting (1 day).
Retest (Optional)
Verify fixes, regression testing, updated report, and security posture assessment (2-3 days).
Value Added
Services
Sample Pentest Report
View a live example of our professional security audit report complete with Executive Summary, CVSS Severity Score, POC, and Remediation Guide.
Retest Service
Verify remediation effectiveness. Retesting exclusively for identified issues.
Our Competitive
Edge
Proven Track
10+ successful assessments, 0 data breach during testing, 98% client satisfaction.
Manual Focus
Manual testing (not just scanner), business logic focus, real-world attack scenarios.
Local Support
Indonesian & English reporting, local business hours, on-site meeting available.