Skip to content
COLONFILM

CHOOSE YOUR PENTESTKnow what will be tested.

By David Colón & Flor · COLONFILM

Before you hire

Scope. Evidence. Action.

A practical buying guide for web applications and APIs.

Choose a penetration testing company by matching its written scope, manual testing methods, and report quality to your application's actual risks and the evidence your customer or team needs.

In short

  • Start with the decision: launch readiness, customer due diligence, or a specific security concern.
  • Compare the same application, roles, API coverage, deliverables, and retest terms across providers.
  • Ask for a redacted report and an explanation of how findings are manually verified.
  • COLONFILM offers a vulnerability assessment for $490, a web application pentest for $990, and a web app plus API pentest for $1,990.

Which penetration testing services do you actually need?

A useful brief starts with a business question. Can one customer see another customer's documents? Can a restricted user perform an administrator's action? Does a new integration expose information outside its intended audience? These questions help a provider allocate effort to the parts of your product where a failure would matter.

A vulnerability assessment identifies and prioritizes weaknesses, often using automated scanning followed by verification. A penetration test adds manual investigation of how the application behaves and how weaknesses affect real workflows. Both have a place. Buying the right one prevents a mismatch between the report you receive and the decision you wanted to make.

For example, a small public application with a login and a contact form needs a different scope from a subscription platform with organizations, invitations, document exports, and a partner API. The second product has more trust boundaries even if both websites have roughly the same number of screens.

NeedSuitable starting pointEvidence to request
Prioritize known and detectable weaknessesVerified vulnerability assessmentValidated findings, risk ratings, practical fixes
Examine authenticated web workflowsManual web application pentestRole coverage, reproducible evidence, technical report
Test application and integration permissionsWeb app and API pentestEndpoint inventory, authorization tests, business logic coverage
Assess a large enterprise environmentSpecialist engagement with custom scopeRelevant infrastructure coverage and required procurement evidence

Where to hire a penetration testing company

You can hire an independent tester, a focused service studio, a specialist security consultancy, or a provider offering recurring testing through a platform. Compare the engagement model before comparing logos. A fixed project suits a defined release or application. A recurring arrangement may suit a team that needs repeated testing throughout product development.

Freelance marketplaces can make prices and reviews easier to compare, but inspect the actual service description. A strong marketplace history speaks to delivery experience; it does not by itself establish expertise in your architecture. Ask who performs the work, who reviews the findings, and what happens when an issue needs clarification.

A specialist consultancy can be appropriate when procurement requires particular accreditations, named tester qualifications, industry experience, or a broad environment assessment. Verify those requirements directly with your customer before collecting quotes. A lower price is useful only if the resulting work meets the acceptance criteria.

For a bounded web application or API project, the COLONFILM penetration testing service gives you three published scopes. It is a practical option when you can provide test access, identify the application owner, and nominate a developer to receive the findings.

Write a pentest scope that providers can price accurately

Describe the application as a set of assets and workflows. Include hostnames, environments, login methods, user roles, integrations, and the actions that carry business risk. State whether the API is REST or GraphQL and whether documentation reflects the deployed version. An outdated inventory creates avoidable uncertainty before testing even starts.

Count roles by permissions, not job titles. An owner and an administrator might have identical access, while two ordinary customers in separate organizations introduce an important isolation boundary. Include representative accounts and explain what each should be able to read, change, approve, export, or delete.

  • Assets: the exact application, domains, API base URLs, and environment.
  • Identity: roles, tenant boundaries, login flows, and multifactor authentication arrangements.
  • Workflows: payments, invitations, uploads, account recovery, and administrative actions where relevant.
  • Access: test accounts, synthetic records, documentation, and any required network permissions.
  • Outputs: audience, report format, delivery date, remediation guidance, and retest expectations.

Put rules of engagement in writing. COLONFILM requires authorization signed by the owner of the system and environment, prefers staging, and excludes social engineering and denial of service. Agree testing windows, an emergency contact, stop conditions, and evidence handling before the first request reaches the application.

Staging should represent the relevant production behavior. Record differences in configuration, integrations, identity, and deployment version. If a payment gateway uses a sandbox, explain which steps remain representative. This lets the report say precisely what was observed and which assumptions need attention when changes reach production.

How to evaluate manual testing and OWASP coverage

The OWASP Web Security Testing Guide provides a structured reference for web security testing. The OWASP Application Security Verification Standard provides security verification requirements. Ask which versions and relevant checks the provider uses, and how those choices map to your agreed scope.

A proposal that says “OWASP testing” still needs detail. Ask the provider to describe a permission boundary in your product and how the engagement would assess it safely. The answer should refer to your roles, records, or business workflows rather than simply list scanner names.

Consider a hypothetical customer portal with document downloads. A useful test examines whether access follows the intended ownership rules across test accounts. A useful finding explains the affected workflow, the expected restriction, the observed behavior, and the practical consequence. You need enough evidence for a developer to investigate without exposing unnecessary customer data.

For an API, clarify how endpoints are counted. In REST, the path and method combination may matter. In GraphQL, one HTTP endpoint can expose many operations and resolver permissions. Agree an inventory that describes meaningful functionality; the number “one endpoint” can otherwise hide substantial complexity.

What a good penetration testing report should contain

Request a redacted sample before hiring. Read one finding as if you were the engineer assigned to fix it. Can you locate the affected component, understand the prerequisite access, reproduce the behavior in an authorized environment, and identify the proposed corrective action? A long report can still fail this simple test.

The executive summary should explain the main risks and priorities in business terms. The technical section should support those conclusions with evidence. Keep severity and business urgency distinct: an issue's technical characteristics matter, but so do exposed data, reachable users, and the function's importance to your product.

Report elementWhat makes it useful
Scope and datesIdentifies the tested version, environment, assets, and access available
Finding evidenceShows the observed behavior with sensitive information minimized
Risk explanationConnects the weakness to a plausible impact on this application
Remediation guidanceGives developers a concrete direction and verification target
Coverage and constraintsDistinguishes completed checks from blocked or excluded areas

Ask how duplicates are consolidated and uncertain results are handled. Ten observations with one underlying cause may be more useful as one well-explained finding. Conversely, a shared symptom across different permission boundaries may deserve separate treatment. The objective is a report your team can turn into a prioritized work queue.

Compare pentesting quotes using the same acceptance checklist

Give each shortlisted provider the same brief, then compare written answers. Review scope fit, manual testing, evidence quality, communication, data handling, and retest terms. Mark each item as clear, needs clarification, or outside scope. Resolve the important gaps before judging the final price.

Ask whether the quoted duration means delivery time or hands-on testing time. An eight-day delivery window does not automatically mean eight full days of manual testing. Also confirm when the clock starts, what happens if accounts stop working, and whether a deployment during testing changes the agreed scope.

Clarify report ownership, permitted sharing, confidentiality, retention, and deletion arrangements. If your organization has restrictions on AI tools or data locations, raise them before transferring material. A provider should explain the workflow plainly enough for you to make an informed procurement decision.

Keep remediation implementation separate from advice. A report can tell your developer what to change; implementing and deploying that change uses engineering time. A retest then checks agreed fixes. For a closer price comparison, use the 2026 penetration testing cost guide.

COLONFILM penetration testing packages and best fit

PackagePrice and deliveryIncluded scope
BASIC$490 · 3 daysExternal and authenticated scanning of one web app; every finding manually verified; risk-rated report with fixes
STANDARD$990 · 5 daysManual web application pentest against OWASP Top 10 and ASVS checks; up to 2 user roles; proof-of-concept evidence; executive summary and technical report
PREMIUM$1,990 · 8 daysEverything in Standard plus a REST or GraphQL API up to 40 endpoints; business logic and access control testing; developer remediation guidance; one retest within 30 days; letter of attestation

Choose Basic when your immediate goal is a verified vulnerability inventory. Choose Standard when you need manual testing of application behavior across up to two roles. Choose Premium when the API and its permissions are part of the buying decision and you want a defined opportunity to verify fixes.

The Premium attestation records the scope, dates, and results of the test. If a customer requests a particular document or provider qualification, send that requirement before booking so the deliverable can be checked for fit. Procurement language matters as much as the package name when another organization will review the result.

COLONFILM is David Colón and Flor's studio in Zaragoza, Spain, designing since 2010. Its Fiverr profile is Pro and Top Rated, with more than 1,000 reviews and a 4.8-star rating. Work is produced with AI agents and reviewed by a person. Evaluate that disclosed workflow alongside your confidentiality and procurement needs.

These are defined online projects with a clear handover. Before booking, prepare your application inventory, user roles, preferred environment, deadline, and report recipient. You can then choose the penetration testing package against an actual requirement rather than guess from a price alone.

Turn the pentest into a usable remediation plan

Reserve time with engineering before the report arrives. Assign an owner to each accepted finding, decide its priority, and record the intended fix. Where several issues share a root cause, plan the change at the appropriate layer rather than treating every affected screen independently.

For Premium, work backward from the retest window of 30 days. Allow time for implementation, internal checks, and a stable deployment for verification. Keep the tested build and the corrected build identifiable. If the application changes substantially, discuss whether the new functionality needs separate scope.

A strong handover ends with a short decision record: what was tested, what was found, what will be fixed first, and who owns the next action. That record makes the engagement useful to developers, management, and customer-facing teams without asking every reader to interpret raw technical evidence.

FAQ

Is a vulnerability assessment the same as a pentest?

A vulnerability assessment prioritizes identified weaknesses. A pentest adds manual investigation of application behavior and impact. Compare the contracted methods and evidence to your actual requirement.

Can testing happen on production?

Discuss production constraints during scoping. COLONFILM prefers a representative staging environment. The selected environment, testing window, contacts, and stop conditions belong in the written agreement.

Does a pentest prove that a website is completely secure?

A pentest is an authorized assessment of an agreed scope at a point in time. Its report and attestation describe that work and its results; they do not certify absolute security.

What if my API has more than 40 endpoints?

Provide the inventory before purchasing. Premium covers up to 40 endpoints; a larger or unusually complex API needs a scope discussion so coverage and pricing stay explicit.

Which COLONFILM package includes a retest?

Premium includes one retest within 30 days. Basic and Standard have different deliverables, so confirm any additional verification you need before booking.

READY TO MAKE IT REAL? That’s the day job.

See penetration testing services (web apps & APIs) packages →
Open chat