Skip to content

Penetration testing and security audits. We find the holes before attackers do.

We test your website, app or API using the same techniques attackers use. You get a clear report with findings ranked by severity and steps to fix them. After the fixes, we verify everything again.

We always sign an NDA and a DPA

Price estimate in 60 seconds · Proposal within 2 business days · No commitment

OWASPbased on Top 10 and ASVS
Retestincluded after fixes

Trusted by

Why custom

You usually find out your site is vulnerable from an attacker.

Automated scanners only find some of the problems. Flaws in permissions, login or application logic only surface when a person deliberately tries to exploit them.

No regular testing

  • Discovering a vulnerabilityAfter a data breach or an outage
  • ScopeAn automated scan with no review
  • OutputA long export full of false positives
  • FixingYou don't know where to start
  • EvidenceNothing to show clients or auditors

LISTIFY, built for you

  • Discovering a vulnerabilityDuring a planned test
  • ScopeManual testing of logic, permissions and APIs
  • OutputVerified findings ranked by severity
  • FixingSpecific steps for your developers
  • EvidenceA final report and a retest attestation letter

A to Z

We test like attackers. We write like developers.

We know how applications are built, so we know where mistakes happen. The report is written so your team can start fixing straight away.

Scope and rules

We agree on what we test, when and how. You confirm everything with written authorization for the test.
ScopeWritten authorizationTest accounts

Testing

We combine automated tools with manual testing of login, permissions, APIs and application logic.
OWASP Top 10APIPermissions

Report and fixes

Every finding has a severity rating, evidence and steps to fix it. We report critical findings right away, without waiting for the final report.
CVSSEvidenceRecommendations

Retest and repeat

After the fixes, we verify the findings again. We recommend testing at least once a year and after every major change.
RetestAttestationAnnual test

Examples

Every one different. Every one custom-built.

View full portfolio →

Process

From brief to report in 2 to 4 weeks.

We test at an agreed time so the test doesn't disrupt operations. Critical findings are dealt with right away.

  1. What we test, which roles and which environments. You get a fixed-price proposal within 2 business days.

    Step 1 of 5 · Week 1

    What we do

    • Test scope
    • Environments and roles
    • Fixed price within 2 days

    From you

    Written test authorization

    You get

    proposal and test authorization

Technology

The methodologies and tools we test with.

We follow recognized methodologies so results can be compared over time and shown to auditors.

  • OWASP Top 10Most common vulnerabilities
  • OWASP ASVSVerification standard
  • OWASP API Top 10API security
  • CVSSSeverity scoring
  • Burp SuiteManual testing
  • NmapNetwork and services
  • SSL LabsTLS configuration
  • SemgrepStatic code analysis
  • npm auditDependencies

Price and inquiry

What will it cost? Find out in a minute.

Click through what you need and see a ballpark price and timeline right away. We'll send you an exact proposal within 2 business days.

What are we testing?

What should we add?

A final report, a results meeting and one retest after fixes are always included.

Guarantees

The risk is on us.

Retest

Fix verification included

After the fixes, we retest the findings and issue an attestation letter.
NDA

Confidentiality

We sign a non-disclosure agreement before the test starts.
Now

Critical findings

We report critical vulnerabilities immediately, without waiting for the final report.
Fixed

Price up front

You know the price before the test. No extra charges.

FAQ

Your questions. Straight answers.

Didn't find your question? Call us and get an answer right away.

A penetration test looks for vulnerabilities by trying to exploit them. A security audit is broader: besides the test, it also covers code, servers, access management and processes.

More services

Share this page

By email

Do you know how secure your app is?

On a short call, we'll agree on what to test and how. Within 2 business days, you'll have a proposal with a fixed price and a test date.

+420 771 166 199Mon to Fri, 8:30 a.m. to 4:00 p.m. (Prague time) · info@listify.cool

When should we call you?

Pick a day and a time window. We'll call you, and it takes about 15 minutes.

Day