Firepan Pentest · Authorized Web2 security testing
TEST WHAT AN ATTACKER
COULD REACH.
Request a scoped penetration test for your website, application, API, or infrastructure. Before testing begins, we agree the targets, exclusions, rules, and report with you in writing.
Testing is scoped with your team. A request or deposit alone never starts testing.
Sign in with GitHub or Google to describe the systems and timing. You can start with a tentative scope; our team will discuss it through your request. You do not need a source repository to request a Web2 Pentest. Do not include credentials; we arrange a separate secure handoff if access is needed.
Specific systems
Identify the application flows, APIs, authentication, integrations, cloud, or network assets that matter to your team.
Agreed scope
Set explicit targets, exclusions, testing windows, and authorization before active testing.
Reviewed findings
The reviewed report states what was tested, what was excluded, what was found, and what to fix.
First-release terms
- Web2 scope. Discuss websites, applications, APIs, authentication, integrations, cloud, and network assets. The final scope is agreed in writing.
- Quoted engagement. Price and any deposit are set for your agreed scope. There is no fixed online price or recurring Pentest subscription.
- Separate payment. After accepting a quote with a deposit, pay it by card. Firepan invoices the remaining balance separately.
- Reviewed delivery. The agreed report identifies tested assets, exclusions, findings, evidence, and follow-up.
How a Pentest works
START WITH THE SYSTEM AND THE SCOPE
- 01
DESCRIBE THE SYSTEM
Tell us which website, application, API, or infrastructure you want assessed, what concerns you, and when testing could happen.
- 02
AGREE THE SCOPE
Confirm targets, exclusions, environment, rules of engagement, and the written quote with Firepan before any testing begins.
- 03
PAY ANY AGREED DEPOSIT
If the agreed quote includes a deposit, pay that amount online by card. Firepan invoices the remaining balance separately.
- 04
FOLLOW THE TEST
See the engagement status in your Firepan account. Testing begins only after the agreed scope and written authorization are in place.
- 05
USE THE FINDINGS
Receive a reviewed report with evidence, scope limits, and remediation guidance for the agreed test.
Choose the right Firepan offer
MATCH THE ENGAGEMENT TO THE QUESTION
| Offer | Use it for | What you receive |
|---|---|---|
| Scan / Probe / Audit | Automated smart contract repository analysis: Scan discovers common signals, Probe investigates a selected commit, and Audit reviews it adversarially. | Source-linked observations, investigation results, or reviewed findings at the selected level. |
| Firepan Pentest | Authorized testing of an agreed Web2 application or infrastructure scope. | A reviewed report with evidence, scope limits, remediation guidance, and a retest if included in the agreed scope. |
| Contract Hunt | Exploit validation for EVM contracts at a pinned revision or deployment. | Reviewed exploit evidence and a bounded disposition. |
| Boutique Audit | A wider human-led security assessment. | A human-led audit deliverable and collaborative review of the agreed scope. |
Start with the question
REQUEST A FIREPAN PENTEST
Bring the systems, testing objectives, exclusions, and timing you want to discuss. Firepan will confirm what can be tested and put the scope in writing.
Open Pentest Request