Pre-launch security review
A focused review of the application, configuration and architecture. Agree in advance which areas need particular attention.
You receive: prioritised findings and practical improvements.
For agencies / Security partnership
A client needs a penetration test. A platform is about to launch. Your developers want a second opinion on security. Gract supports web and development agencies with security testing and remediation guidance, without the need to build an in-house security team.
What you can offer
A focused review of the application, configuration and architecture. Agree in advance which areas need particular attention.
You receive: prioritised findings and practical improvements.
Manual testing of areas such as authentication, access controls and business logic. The scope reflects your client’s application and risks.
You receive: a technical report with evidence, impact and remediation guidance.
Discuss findings with your developers and have agreed fixes checked. Include a retest in the engagement or arrange it as a follow-up.
You receive: guidance for your team and the status of retested findings.
Your client relationship comes first
You know the client and the project. Gract brings the security expertise. Before we start, we agree who communicates, whose name we work under and how findings are shared.
Gract delivers the security work under your agency’s name. We align report branding and communication with your client relationship.
You introduce Gract as your security partner. We can join technical conversations and explain the findings together.
From first conversation to delivery
Tell us what your agency builds, what your client needs and when the project launches. The first conversation can happen without sensitive client information.
Together we agree scope, access, authorisation, the testing window and deliverables. You receive a proposal before testing begins.
Gract tests the agreed areas. We discuss findings with your team and agree which fixes and retests are needed.
Yes. We work white-label under your agency’s name or visibly as Gract. Report branding, client contact and responsibilities are agreed before the project starts.
We agree this together. Communication can run through your agency or a joint technical session. We decide who shares findings and coordinates the next steps.
You can start with a single, defined project. If security requests become more frequent, we can discuss ongoing support based on your schedule and our capacity.
Fees depend on the application, testing depth, access and deliverables. We provide a proposal with scope and pricing in advance, including any partner arrangements and retesting.
An outline of the application, your client’s question and your preferred schedule. Before testing, we agree the access and authorisation required, confidentiality and how sensitive information will be shared.
Tell us about your agency, the application and your schedule. We’ll work out whether Gract is a fit and what a useful first step looks like.