Tool-led scanning of one web application, with every finding checked by a person
Buy now
From$599USD one-off
One payment. Work starts once we have confirmed your requirements.
The four questions this page answers
1
What you buy
A one-off assessment of a single web application using recognised scanning tools, followed by manual checking of each result so the false positives are removed before you ever see them.
2
What you get
5 deliverables, listed in full below
A written assessment report listing every verified finding with severity and reproduction notes
A remediation list ordered by severity, with the suggested fix against each item
The signed authorisation and the agreed scope statement, kept on file for both sides
Carried out remotely by our team. Nothing is posted and no one visits.
REMOTE SERVICE
4
How long it takes
7–10 business days from receipt of signed authorisation and test credentials
Measured from the point everything under “what we need from you” is with us, not from the moment you pay.
An audit report: findings grouped into severity bands with an owner for each. Illustrative interface concept — not a screenshot of a client deployment.
What is this, in plain English?
A one-off assessment of a single web application using recognised scanning tools, followed by manual checking of each result so the false positives are removed before you ever see them.
Where the Website Security Audit reads configuration, this exercises the running application, including logged-in areas when you supply test credentials. It is scan-led with human verification. It is not a penetration test: we do not exploit what we find, we do not attempt to move deeper into your systems, and we are not a licensed security testing firm. Testing does not start until written authorisation is signed.
The problem it solves
You run a web application that takes logins, payments or customer records, and nobody has ever pointed a scanner at it or read what one would say.
If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.
What you get
The concrete things that exist at the end and that you own.
5 deliverables
A written assessment report listing every verified finding with severity and reproduction notes
A remediation list ordered by severity, with the suggested fix against each item
The signed authorisation and the agreed scope statement, kept on file for both sides
A written statement of coverage: what was scanned, what was not, and why
A retest report covering the findings you closed within 30 days
What's included
The work covered by the figure in the buy box, at no extra cost.
One web application, up to roughly 40 distinct pages or endpoints
Unauthenticated and authenticated scanning
Manual verification of all findings
Severity-rated written report with reproduction notes
A walkthrough call over video
One retest of up to ten fixed findings within 30 days
Everything listed here is delivered as part of this product. Nothing on this list is aspirational.
Unauthenticated scan of the publicly reachable application
Authenticated scan using test credentials at each user role you provide
Manual verification of every finding, so false positives never reach the report
Checks for common web weaknesses, informed by the OWASP Top Ten
Each issue rated for severity and explained in plain English as well as technically
Reproduction notes written so your developers can confirm the issue themselves
One retest of up to ten fixed findings, free, within 30 days of the report
How it works
The delivery sequence from order to handover.
1
Authorisation first
You sign a written authorisation naming the systems, the dates and the person authorising. Nothing is scanned before it is returned.
2
Agree scope and window
We fix which hosts and paths are in scope, what is out of bounds, and when the scan runs. Your host is notified where their terms require it.
3
Scan
Unauthenticated and authenticated passes run against the agreed target, at a rate tuned not to overwhelm it.
4
Verify by hand
Every raw result is checked manually. Anything we cannot reproduce is discarded rather than padded into the report.
5
Report and retest
You receive the report and a walkthrough call. When your fixes are in, we retest the closed findings once.
Delivery & fulfilment
Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.
REMOTE SERVICEHow this is delivered
1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.
Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 7–10 business days from receipt of signed authorisation and test credentials.
Delivery method
Remote Setup
Expected delivery time
7–10 business days from receipt of signed authorisation and test credentials
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.
Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.
What we need from you
Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.
Signed written authorisation from the owner of the system, before testing begins
Written confirmation from your hosting provider where their terms of service require notice of scanning
Test credentials for each user role that should be covered
A staging copy, or an agreed window during which the live application may be scanned
A named technical contact reachable during the testing window
Who this is for
Businesses running a custom-built web application
Companies whose client or insurer has asked for evidence of security testing
Development teams with no in-house security capability
Anyone about to launch an application that handles customer data
Just as plainly as the list above: the things this package is not.
Exploitation of findings, privilege escalation or any activity resembling a penetration test
Social engineering, phishing simulation and testing of staff or physical premises
Testing of third-party services you do not own, such as a payment provider or hosted CRM
Fixing anything we find; remediation is quoted separately, or handled by your own developers
Certification, accreditation or a security sign-off letter, which we are not able to issue
Any statement that the application is free of vulnerabilities; no assessment can establish that
Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.
FAQs
Why do you insist on written authorisation?
Scanning a system without the owner’s permission is illegal in most places, regardless of intent. We will not begin until we hold a signed authorisation naming the systems, the dates and the person authorising it. If the application sits on infrastructure you do not control, we need the controlling party’s agreement too.
Is this a penetration test?
No. A penetration test involves exploiting findings and chaining them together, usually by a licensed testing firm, and we are not one. This is automated scanning plus manual verification, which catches the common and well-documented issues at a fraction of the cost. If you need a formal penetration test, say so and we will tell you plainly that this is not it.
Could the scan break our application?
It is possible. Scanners submit forms and follow links, so they can create test records, trigger emails or put load on a fragile server. We prefer to run against a staging copy for that reason, and where we must use production we agree a window, tune the rate and ask you to take a backup first.
What if you find nothing serious?
Then the report says so, and that is a legitimate result rather than a failed engagement. The price covers the work of assessing, not a quota of findings. A clean report means the common issues were not present on the day we looked, which is not the same as the application being secure.
Refund & cancellation
What happens if you change your mind, and what happens to money already paid.
Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.