Four stages, one dedicated team throughout. No hand-off between a scoping call and the people actually testing your application.
Timelines below are typical for a single web application or API. They adjust based on scope and your deadline.
A call to walk through the application, the compliance driver behind the engagement, and any deadline you're working against. From there you get a written proposal with scope, price, and a start date.
Manual testing against the agreed scope: authentication, authorization, business logic, and injection classes, along with anything specific to how your application is built. This isn't scan and forward. Every finding is manually verified before it's reported.
A written report covering scope, methodology, findings, and severity, with reproduction steps and remediation guidance for each issue. Formatted for direct submission to an auditor or compliance platform, not just internal reading.
Once your team has addressed the findings, each one is retested and confirmed closed. You get updated documentation showing what was fixed and verified: the evidence an auditor typically asks for.
Send over your application, compliance requirement, and timeline, and you'll get a proposal back directly.