For agencies / Security partnership

Your agency builds.
Gract tests the security.

A client needs a penetration test. A platform is about to launch. Your developers want a second opinion on security. Gract supports web and development agencies with security testing and remediation guidance, without the need to build an in-house security team.

  • For web and development agencies
  • Project-based or ongoing
  • Direct access to the specialist

What you can offer

Security that fits your projects.

/01

Pre-launch security review

A focused review of the application, configuration and architecture. Agree in advance which areas need particular attention.

You receive: prioritised findings and practical improvements.

/02

Web application and API testing

Manual testing of areas such as authentication, access controls and business logic. The scope reflects your client’s application and risks.

You receive: a technical report with evidence, impact and remediation guidance.

/03

Remediation support and retesting

Discuss findings with your developers and have agreed fixes checked. Include a retest in the engagement or arrange it as a follow-up.

You receive: guidance for your team and the status of retested findings.

Your client relationship comes first

A security specialist alongside your team.

You know the client and the project. Gract brings the security expertise. Before we start, we agree who communicates, whose name we work under and how findings are shared.

White-label

Gract delivers the security work under your agency’s name. We align report branding and communication with your client relationship.

Visible security partner

You introduce Gract as your security partner. We can join technical conversations and explain the findings together.

Your agency
Leads the project, manages the client relationship and coordinates work with the development team.
Gract
Performs the agreed security assessment, explains the risks and provides practical remediation guidance.
Agreed together
Scope, timing, fees, confidentiality, report branding, client contact and any retesting are agreed before work begins.

From first conversation to delivery

Start with one client project.

  1. /01

    Share the brief

    Tell us what your agency builds, what your client needs and when the project launches. The first conversation can happen without sensitive client information.

  2. /02

    Define the engagement

    Together we agree scope, access, authorisation, the testing window and deliverables. You receive a proposal before testing begins.

  3. /03

    Test, discuss and improve

    Gract tests the agreed areas. We discuss findings with your team and agree which fixes and retests are needed.

Questions about working together

Can Gract work under our agency’s name?

Yes. We work white-label under your agency’s name or visibly as Gract. Report branding, client contact and responsibilities are agreed before the project starts.

Who speaks with our client?

We agree this together. Communication can run through your agency or a joint technical session. We decide who shares findings and coordinates the next steps.

Do we need an ongoing contract?

You can start with a single, defined project. If security requests become more frequent, we can discuss ongoing support based on your schedule and our capacity.

What does a partnership cost?

Fees depend on the application, testing depth, access and deliverables. We provide a proposal with scope and pricing in advance, including any partner arrangements and retesting.

What do you need to get started?

An outline of the application, your client’s question and your preferred schedule. Before testing, we agree the access and authorisation required, confidentiality and how sensitive information will be shared.

A security question on your next project?

Tell us about your agency, the application and your schedule. We’ll work out whether Gract is a fit and what a useful first step looks like.