Penetration Testing
Scoped manual web & API penetration testing for small companies with no security team. Fixed scope, fixed fee, 2–3 weeks. You get a report you can hand straight to a customer's security reviewer — plus the detection rules to catch the attack if someone tries it later.
The Problem
You have a web application and an API your customers depend on. You also have no in-house security team — and the questionnaires are piling up.
A SOC 2 prospect, a PCI requirement, an enterprise customer's vendor-security review — they all expect an independent annual penetration test, not just a scan.
NetSPI and Bishop Fox quote $40K+ and treat a 30-person company as an afterthought. So most small companies skip the test entirely.
A $2K automated scan prints a Nessus report and calls it a day — it misses the auth, access-control, and business-logic flaws that actually get exploited.
When a prospect's security team asks "when was your last pentest and can we see the report?" — you need a real answer, not a shrug.
The Offer
A scoped manual web & API penetration test, delivered in 2–3 weeks by an operator who builds defensive security tooling for a living. Fixed scope, fixed fee, no surprises.
Authentication, authorization / access control (IDOR, BOLA), injection, business-logic flaws, session handling, and common misconfigurations — the classes that actually get breached, not just an automated scan.
Each finding with severity, reproduction steps, business impact, and a concrete fix — written to hand straight to a developer, and to a customer's security reviewer.
For the findings, I write the Sigma / Suricata / Falco detection rules so that if someone does try that attack later, you see it. Most pentests hand you a list of holes; this one also leaves you able to detect the attempts.
After you fix the findings, I re-test to confirm they're closed — so you can show a clean result, not just a list of problems.
Who This Is For
You're pursuing or renewing SOC 2 Type II and the auditor expects an independent annual penetration test on the assets that matter.
A big customer's vendor-security review is holding up the deal, and you need a credible test report to unblock it.
Your product is a web app and an API handling real customer or financial data — the exact surface that gets attacked.
Investment
No hourly surprises. You know the number before we start.
$5K – $8K
One web app, light API, OWASP Top-10 coverage, single report.
$10K – $15K
Web app + API, manual depth, the detection-rule deliverable, and a 30-day re-test.
Quoted
Multi-app or internal-network add-ons, scoped separately.
How We Start
What's your stack, how many endpoints, what's driving the need — a customer, or a compliance deadline? No pitch deck.
Fixed scope, fixed fee, 50/50 terms, and clear authorization language. You sign, I start that week.
You walk away with the findings fixed and detection in place — and something credible to hand the customer who asked.
Next Step
No deck, no pressure — just whether the timing and scope are a fit.
Johnathan Hamaker
Insect Zoo Security — FarmHub LLC
wafarmhub@gmail.com
LinkedIn · Insect Zoo
Washington State
All testing is performed only against assets you own or are explicitly authorized to test, under a signed scope. No findings, data, or proof-of-concept material is disclosed outside the engagement.