Manual investigation
Sign-in, authorisation and the business workflows in scope.
Human-led testing. Clear findings. Practical fixes.
From A$7,500 ex GST for one web app, its API and two user roles.
Other services have their own from price in the quote form.
Manually verified findings.
Sign-in, authorisation and the business workflows in scope.
Severity rationale, reproducible evidence and remediation priorities.
A decision-maker summary alongside technical detail for the people fixing the issues.
Coverage and terms stated in the written scope.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.
A buyer has asked for testing evidence? Our SaaS procurement penetration testing scope covers acceptance criteria, tenant boundaries and retest records before booking.
Preparing your asset list? Use the penetration test scope builder. API teams can also use the OWASP API security self-check. Neither replaces a penetration test. Planning a cloud move? The cloud migration readiness checklist records preparation gaps without inspecting your systems.
Read the scoping guide. What a penetration test report should contain.
Our testers hold OSCP, OSWE, OSCE and OSWP from OffSec. They also hold CREST Registered Tester, eCPPT v2 and Zero-Point Red Team Operator certifications.
These are certifications held by individuals, not company accreditations. Sorami is not a CREST member company.
Full certification list. The company accreditation position, in full
From A$7,500 ex GST for one web application with its API and two user roles. The base scope covers five testing days, the report and a retest of critical and high findings. Qualified web scopes with additional applications, endpoints or cloud accounts show an indicative range. Other systems need written scope review. Fixed price once scope is agreed.
Testing effort is not the same as elapsed delivery time. We agree dates after reviewing scope, access readiness and your deadline. Allow time for remediation and retesting. The estimate does not reserve dates.
Acceptance depends on the requester’s requirements. Share their exact wording before booking so we can check scope, credentials and retest terms. A penetration test is not SOC 2 or ISO 27001 certification.
Only with written authorisation, agreed techniques and test windows, safe data and a stop-test contact. Destructive testing and denial of service are excluded by default. This service is not emergency incident response.
No. Sorami Consulting Pty Ltd is not a CREST member company. Our testers hold individual CREST Registered Tester certification, and we will confirm that position in writing for your procurement file.
The sample report is illustrative, built from synthetic findings. It is not a client report.
Last reviewed: