VioletX Request scope

Vx Test

A pentest should give you judgment, not another scanner export.

VioletX runs human led web application penetration tests for product and security teams that need credible results without a long procurement cycle.

Single web application engagements start at $4,500. Final price depends on scope and complexity.

Why human led

Automation helps with coverage. People find what tools miss.

Scanners are useful, but they do not understand your application the way a customer, employee, or attacker does. VioletX testers examine how authentication, permissions, sessions, workflows, and application logic behave together.

Every reported finding is reviewed by a security professional before it reaches your team. You receive evidence, impact, and practical remediation guidance instead of an unfiltered list of alerts.

What is included

A bounded test your team can buy and use.

01

Fast scoping

We confirm the application, test environment, authenticated roles, important workflows, exclusions, and timing before work starts.

02

Human testing

A security professional leads the engagement. Automated tools may support coverage, but they do not replace tester judgment.

03

Useful reporting

The report explains each validated finding, its impact, supporting evidence, severity, and recommended remediation.

04

Complimentary retest

After your team addresses findings, VioletX includes one retest of the reported issues and records their updated status.

Good fit

Built for a real deadline.

This fits when

  • A customer or partner needs a current pentest report
  • An audit, insurer, or board request created a deadline
  • Your team wants independent validation before release
  • You need a focused test of one web application

Separate scope required

  • Multiple applications or complex role structures
  • Mobile, network, cloud, API, or source code testing
  • Social engineering, red team, or physical testing
  • Unstable environments or material scope changes

Process

Scope. Test. Report. Retest.

  1. Confirm scopeWe document the target, roles, workflows, timing, rules of engagement, and final price.
  2. Run the testA human tester leads application testing and validates potential findings.
  3. Deliver the reportYour team receives prioritized findings with evidence and remediation guidance.
  4. Verify fixesOne complimentary retest confirms the status of addressed findings.

Common questions

Before you request a scope

Is the price always $4,500?

$4,500 is the starting price for a focused test of one web application. Authenticated roles, application complexity, APIs, multiple environments, and deadline requirements can change the final scope and price. VioletX confirms both in writing before testing begins.

Is this an automated scan?

No. A security professional leads the test and validates every reported finding. Tools can support coverage, but the delivered report is not an unreviewed scanner or AI export.

How quickly can testing start?

Availability changes. VioletX responds with current start options after reviewing the application and scope. The statement of work identifies the agreed start and delivery dates.

What does the complimentary retest cover?

It covers one verification pass for findings reported in the original engagement. New functionality, added systems, or a changed application boundary may require a separate scope.

Can the report support a customer or audit request?

The report documents scope, methods, validated findings, evidence, severity, and remediation guidance. Specific customer, auditor, or regulatory requirements should be shared during scoping so VioletX can confirm fit.

Request a scope

Tell us what needs to be tested and when.

VioletX will review the application boundary and respond with fit, available start dates, and the information needed for a written scope.

Prefer to talk? Schedule a call with William
Keep this high level.

Do not include passwords, credentials, API keys, customer data, vulnerability details, or production secrets. VioletX will provide a secure handoff process after scope is confirmed.

Does the request include anything beyond one web application?

Current availability

Send the application and target date. We will tell you what the test requires.

Direct scoping with a VioletX operator. No generic demo and no obligation.