Cybersecurity & Digital Protection · Assessment

Web Vulnerability Assessment

Tool-led scanning of one web application, with every finding checked by a person

Buy now

From$599USD one-off

One payment. Work starts once we have confirmed your requirements.

The four questions this page answers

  1. 1

    What you buy

    A one-off assessment of a single web application using recognised scanning tools, followed by manual checking of each result so the false positives are removed before you ever see them.

  2. 2

    What you get

    5 deliverables, listed in full below

    • A written assessment report listing every verified finding with severity and reproduction notes
    • A remediation list ordered by severity, with the suggested fix against each item
    • The signed authorisation and the agreed scope statement, kept on file for both sides
    + 2 more
  3. 3

    How it is delivered

    Remote Setup

    Carried out remotely by our team. Nothing is posted and no one visits.

    REMOTE SERVICE

  4. 4

    How long it takes

    7–10 business days from receipt of signed authorisation and test credentials

    Measured from the point everything under “what we need from you” is with us, not from the moment you pay.

An audit report: findings grouped into severity bands with an owner for each — illustrative concept, not a screenshot of a client system
An audit report: findings grouped into severity bands with an owner for each. Illustrative interface concept — not a screenshot of a client deployment.

What is this, in plain English?

A one-off assessment of a single web application using recognised scanning tools, followed by manual checking of each result so the false positives are removed before you ever see them.

Where the Website Security Audit reads configuration, this exercises the running application, including logged-in areas when you supply test credentials. It is scan-led with human verification. It is not a penetration test: we do not exploit what we find, we do not attempt to move deeper into your systems, and we are not a licensed security testing firm. Testing does not start until written authorisation is signed.

The problem it solves

You run a web application that takes logins, payments or customer records, and nobody has ever pointed a scanner at it or read what one would say.

If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.

What you get

The concrete things that exist at the end and that you own.

5 deliverables

  • A written assessment report listing every verified finding with severity and reproduction notes
  • A remediation list ordered by severity, with the suggested fix against each item
  • The signed authorisation and the agreed scope statement, kept on file for both sides
  • A written statement of coverage: what was scanned, what was not, and why
  • A retest report covering the findings you closed within 30 days

What's included

The work covered by the figure in the buy box, at no extra cost.

  • One web application, up to roughly 40 distinct pages or endpoints
  • Unauthenticated and authenticated scanning
  • Manual verification of all findings
  • Severity-rated written report with reproduction notes
  • A walkthrough call over video
  • One retest of up to ten fixed findings within 30 days

Not seeing something you expected? Check what you are not buying before you order.

What does it do?

Everything listed here is delivered as part of this product. Nothing on this list is aspirational.

  • Unauthenticated scan of the publicly reachable application
  • Authenticated scan using test credentials at each user role you provide
  • Manual verification of every finding, so false positives never reach the report
  • Checks for common web weaknesses, informed by the OWASP Top Ten
  • Each issue rated for severity and explained in plain English as well as technically
  • Reproduction notes written so your developers can confirm the issue themselves
  • One retest of up to ten fixed findings, free, within 30 days of the report

How it works

The delivery sequence from order to handover.

  1. 1

    Authorisation first

    You sign a written authorisation naming the systems, the dates and the person authorising. Nothing is scanned before it is returned.

  2. 2

    Agree scope and window

    We fix which hosts and paths are in scope, what is out of bounds, and when the scan runs. Your host is notified where their terms require it.

  3. 3

    Scan

    Unauthenticated and authenticated passes run against the agreed target, at a rate tuned not to overwhelm it.

  4. 4

    Verify by hand

    Every raw result is checked manually. Anything we cannot reproduce is discarded rather than padded into the report.

  5. 5

    Report and retest

    You receive the report and a walkthrough call. When your fixes are in, we retest the closed findings once.

Delivery & fulfilment

Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.

REMOTE SERVICEHow this is delivered
  1. 1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
  2. 2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
  3. 3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.

Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 7–10 business days from receipt of signed authorisation and test credentials.

Delivery method
Remote Setup
Expected delivery time
7–10 business days from receipt of signed authorisation and test credentials
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.

Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.

What we need from you

Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.

  • Signed written authorisation from the owner of the system, before testing begins
  • Written confirmation from your hosting provider where their terms of service require notice of scanning
  • Test credentials for each user role that should be covered
  • A staging copy, or an agreed window during which the live application may be scanned
  • A named technical contact reachable during the testing window

Who this is for

  • Businesses running a custom-built web application
  • Companies whose client or insurer has asked for evidence of security testing
  • Development teams with no in-house security capability
  • Anyone about to launch an application that handles customer data

Business needs this addresses: Improve IT infrastructure

What's not included

Just as plainly as the list above: the things this package is not.

  • Exploitation of findings, privilege escalation or any activity resembling a penetration test
  • Social engineering, phishing simulation and testing of staff or physical premises
  • Testing of third-party services you do not own, such as a payment provider or hosted CRM
  • Fixing anything we find; remediation is quoted separately, or handled by your own developers
  • Certification, accreditation or a security sign-off letter, which we are not able to issue
  • Any statement that the application is free of vulnerabilities; no assessment can establish that

Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.

FAQs

Why do you insist on written authorisation?

Scanning a system without the owner’s permission is illegal in most places, regardless of intent. We will not begin until we hold a signed authorisation naming the systems, the dates and the person authorising it. If the application sits on infrastructure you do not control, we need the controlling party’s agreement too.

Is this a penetration test?

No. A penetration test involves exploiting findings and chaining them together, usually by a licensed testing firm, and we are not one. This is automated scanning plus manual verification, which catches the common and well-documented issues at a fraction of the cost. If you need a formal penetration test, say so and we will tell you plainly that this is not it.

Could the scan break our application?

It is possible. Scanners submit forms and follow links, so they can create test records, trigger emails or put load on a fragile server. We prefer to run against a staging copy for that reason, and where we must use production we agree a window, tune the rate and ask you to take a backup first.

What if you find nothing serious?

Then the report says so, and that is a legitimate result rather than a failed engagement. The price covers the work of assessing, not a quota of findings. A clean report means the common issues were not present on the day we looked, which is not the same as the application being secure.

Refund & cancellation

What happens if you change your mind, and what happens to money already paid.

Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.

The full terms, item type by item type, are in the Refund & Cancellation Policy. How the work reaches you is covered by the Delivery & Fulfilment Policy.

Not sure this is the right product?

We would rather point you at the right thing than sell you the nearest one. Ask us before you buy — no obligation.

Related products

Others that solve nearby problems, in case this is not quite the right fit.

Or see all 11 in Cybersecurity & Digital Protection.

Contact us