Authenticated Application TestSecurity audit
What this package is
Pro tests your site as someone who has already logged in, which is the one angle no automated scanner anywhere can cover for you.
Most of the weaknesses that genuinely cost a business money sit behind the login: an ordinary user reaching another customer's data, a payment flow that accepts an amount edited on the user's side, an upload field that will take anything at all. Those need a person trying it by hand.
I cover every page that matters rather than just the front one, and send a video walking through the findings in plain language, because a security report nobody can read is a security report nobody acts on.
See it working
| Path | What it is | Behind login | Found |
|---|---|---|---|
| / | Home | Public | 1 |
| /products | Product list | Public | 0 |
| /login | Sign in | Public | 1 |
| /account/orders | Customer order history | Behind login | 2 |
| /checkout | Payment path | Behind login | 1 |
| /account/upload | Slip upload | Behind login | 1 |
| /admin | Admin dashboard | Behind login | 1 |
7 pages tested · 4 of them behind a login · 7 findings in total
The four pages behind a login are the ones a basic scan never reaches, and three of the four worst findings are there.
A worked example for example-shop.test, built for the demonstration and not any client's data.
The scanner and the basic report are part of this package too
This package is not only the authenticated testing. The whole external assessment from the basic package is included.
The scanner is free and open to anyone. It works entirely from the outside and never touches the inside of your site. What this package adds is the full report in the second tab, ranked by severity with a fix for each finding and a summary written twice, once for people and once for engineers, instead of showing three findings and locking the rest.
Both pages are live on this site rather than mock-ups. You can use them from inside the frame.
Everything you get
This list is the entire scope of the package. Nothing is hidden in a contract.
- Everything in the external review
- Testing behind the login, including what each user role can reach
- Payment steps and file uploads tested
- Every page that matters, not only the home page
- Video walkthrough where I explain the findings in plain English
- Report written for two readers: you, and whoever does the fixing
- Replies inside stated working hours, written in your time zone
- Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
- A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
- Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
- Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
- Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.
Questions about this package
How different is this from Basic? Is the gap worth it?
Basic checks what is visible from outside. Deep checks what happens after logging in, which is where the expensive weaknesses live. If your site is a profile site with no accounts, Basic genuinely is enough. If there are logins, payments or customer data, Basic never sees the part that matters most.
Will real orders be created, or data damaged?
No. I use test accounts and the payment system's test mode. Where no test mode exists, I test only the steps that create nothing real and record in the report how far each area could be checked. I do not delete or alter your data while testing.
Why is there a video as well?
Because most security reports die from never being read to the end. A video shows you what I clicked and what happened, which conveys severity far better than prose, and you can forward it to your team without booking a meeting.
How long does it take?
The report lands within five working days, counted from when the authorisation and the test accounts are complete. If the site turns out much larger than described, I tell you how much longer it needs before starting rather than going quiet and delivering late.
If you find something serious mid-test, do you say so immediately?
Immediately, without waiting for the report. If I find a door being used right now, or customer data actively exposed, I call you that day with a way to close it temporarily, and write it up afterwards.