Penetration Testing

Prove Your App Is Secure — and Detect the Next Attack

Scoped manual web & API penetration testing for small companies with no security team. Fixed scope, fixed fee, 2–3 weeks. You get a report you can hand straight to a customer's security reviewer — plus the detection rules to catch the attack if someone tries it later.

Book a Scoping Call

The Problem

Most Small Companies Are Exposed on the Things That Actually Get Breached

You have a web application and an API your customers depend on. You also have no in-house security team — and the questionnaires are piling up.

✗

The compliance pressure is real

A SOC 2 prospect, a PCI requirement, an enterprise customer's vendor-security review — they all expect an independent annual penetration test, not just a scan.

✗

The big firms price you out

NetSPI and Bishop Fox quote $40K+ and treat a 30-person company as an afterthought. So most small companies skip the test entirely.

✗

The cheap "scan" finds nothing real

A $2K automated scan prints a Nessus report and calls it a day — it misses the auth, access-control, and business-logic flaws that actually get exploited.

✗

You have nothing credible to hand a customer

When a prospect's security team asks "when was your last pentest and can we see the report?" — you need a real answer, not a shrug.

The Offer

A Real Manual Test — That Also Leaves You Able to Detect Attacks

A scoped manual web & API penetration test, delivered in 2–3 weeks by an operator who builds defensive security tooling for a living. Fixed scope, fixed fee, no surprises.

🔎

Manual testing of your web app + API

Authentication, authorization / access control (IDOR, BOLA), injection, business-logic flaws, session handling, and common misconfigurations — the classes that actually get breached, not just an automated scan.

📋

A report you can actually use

Each finding with severity, reproduction steps, business impact, and a concrete fix — written to hand straight to a developer, and to a customer's security reviewer.

🛡

The differentiator: detection-rule tuning

For the findings, I write the Sigma / Suricata / Falco detection rules so that if someone does try that attack later, you see it. Most pentests hand you a list of holes; this one also leaves you able to detect the attempts.

🔄

One free re-test within 30 days

After you fix the findings, I re-test to confirm they're closed — so you can show a clean result, not just a list of problems.

Who This Is For

Built for SaaS Companies Without a Security Team

SOC 2-Bound SaaS

You're pursuing or renewing SOC 2 Type II and the auditor expects an independent annual penetration test on the assets that matter.

Enterprise Sales Blockers

A big customer's vendor-security review is holding up the deal, and you need a credible test report to unblock it.

Web App + API Businesses

Your product is a web app and an API handling real customer or financial data — the exact surface that gets attacked.

2–3 wks
Test to report
50 / 50
On signature / on delivery
15%
Labor-overage cap protects you
On-shore
Pacific time — data stays in the U.S.

Investment

Fixed Scope, Fixed Fee

No hourly surprises. You know the number before we start.

Starter

$5K – $8K

One web app, light API, OWASP Top-10 coverage, single report.

Standard — most SMBs

$10K – $15K

Web app + API, manual depth, the detection-rule deliverable, and a 30-day re-test.

Extended

Quoted

Multi-app or internal-network add-ons, scoped separately.

How We Start

From Call to Clean Report

1

20-minute scoping call

What's your stack, how many endpoints, what's driving the need — a customer, or a compliance deadline? No pitch deck.

2

One-page SOW

Fixed scope, fixed fee, 50/50 terms, and clear authorization language. You sign, I start that week.

3

Test → report → walkthrough → re-test

You walk away with the findings fixed and detection in place — and something credible to hand the customer who asked.

Next Step

Book a 20-Minute Scoping Call

No deck, no pressure — just whether the timing and scope are a fit.

Johnathan Hamaker

Insect Zoo Security — FarmHub LLC
wafarmhub@gmail.com
LinkedIn · Insect Zoo
Washington State

All testing is performed only against assets you own or are explicitly authorized to test, under a signed scope. No findings, data, or proof-of-concept material is disclosed outside the engagement.