Frequently asked questions

What is included in the penetration testing price?

The price includes agreed scope analysis, manual security assessment, finding validation, a technical report and remediation guidance. Final pricing depends on the number of applications, API endpoints, user roles, IP addresses and functionality.

What is the difference between penetration testing and vulnerability scanning?

Vulnerability scanning automatically finds known issues. Penetration testing includes manual validation, access control, business logic, API authorization and exploitable-risk analysis.

How long does a penetration test take?

A small review can take 1-3 days. A typical web/API penetration test often takes 5-10 business days, while larger network or source code reviews are scoped separately.

Can you test production systems?

Yes, if testing boundaries, timing, accounts and prohibited actions are agreed in advance. If a staging environment exists, it is often a good starting point.

Do you provide retesting?

Yes. Retesting can be included in the proposal or scheduled separately after remediation.

How is source code security review performed?

We analyze how data enters the system, how it is processed and where security risk can appear. We assess risk paths in the code, important business logic areas and provide clear recommendations on what to fix first.

How is network security assessment performed?

Externally, we assess what can be reached and observed from the internet. Internally, we check how access, network segments and the risk of movement from one compromised device are controlled.

Can the report be used for audits or vendor assessments?

The report includes scope, methodology, findings summary, risks, PoC, impact, remediation and retest status. If a specific format is required, mention it before the project.

Can we start with a small-scope review?

Yes. We can start with a limited scope, one application, one API segment or the free 1-day source code review if it fits your situation.

Who is the free 1-day source code review for?

It is for teams that want to quickly understand whether the code shows early security risk signals. It is a limited initial assessment, not a full audit.

How is continuous security review different from a one-off penetration test?

A one-off pentest assesses one moment in time. Continuous security review is aligned with your release cycle and helps find risks when they appear.

Do you work in English and Lithuanian?

Yes. Communication, reports and walkthroughs can be delivered in English or Lithuanian.