Pala Software · Professional Services

Security Assessment &Authorized Penetration Testing.

Independent security review and authorized penetration testing for systems you are authorized to test — with clear scope, written authorization and a remediation report, not automated scanning sold as a service.

Who this is for

This service is built for businesses that need an independent, professional security review — not for open-ended or unsolicited testing.

  • Businesses wanting an independent assessment of their website's security
  • Companies preparing for a public launch
  • Teams concerned about exposed configuration or public-facing risk
  • Businesses wanting a second opinion before or after a security incident
  • Owners of systems they are legally and contractually authorized to test

Authorization comes first.

Security testing and penetration testing are performed only on systems for which the client is authorized to request testing. Scope, systems in and out of bounds, and testing windows are agreed in writing before any assessment begins.

Scope of work

What we review.

Each area below is performed only within the agreed and authorized scope of an engagement.

01

Website Security Review

A structured review of a website's public-facing security posture and configuration.

02

Security Configuration Assessment

Checking server, hosting and application configuration against common security risks.

03

Attack Surface Review

Mapping what is publicly exposed and reachable, and whether it should be.

04

Vulnerability Assessment

Identifying known vulnerability classes across the reviewed systems.

05

Authentication & Access Review

Reviewing login, session and access-control behavior for common weaknesses.

06

Authorized Penetration Testing

Hands-on, scoped testing performed only within an agreed and authorized scope.

Boundaries

What we do not do.

These boundaries exist to keep every engagement safe, legal and predictable.

  • Written client authorization required before any testing begins
  • Third-party systems are never tested without their own permission
  • Destructive testing only when explicitly scoped and authorized
  • Testing stays within the agreed scope and testing window
Process

How an engagement runs.

Authorization is the first step, not a footnote at the end of a proposal.

Scope & authorization
Assessment
Validation
Report & remediation
Engagement models

A starting shape for scope, not a fixed price list.

Every engagement starts with a scoping conversation. These describe typical depth, not confirmed pricing or timelines.

Security Review

For businesses that want a baseline security check without invasive testing.

A structured, non-intrusive review of security configuration, exposure and common weak points.

  • Public attack-surface review
  • HTTPS / TLS configuration review
  • Security headers review
  • Cookie & security configuration review
  • Exposed files / config review
  • Basic authentication review
  • Deployment / configuration review
  • Public information exposure review
  • Common misconfiguration checks
Full package scope
  • Risk summary
  • Remediation recommendations
  • Written findings report
  • Follow-up review call
Get a Quote

Vulnerability Assessment

For teams who need a structured, evidence-based view of vulnerability classes across authorized systems.

A deeper assessment identifying and documenting vulnerability classes across authorized systems.

Includes Security Review, plus:
  • Structured vulnerability assessment
  • Broader attack-surface analysis
  • Authentication / session review where in scope
  • Input validation checks
  • Access-control review
  • Common OWASP-oriented checks
  • Dependency / exposure review where applicable
  • Configuration weaknesses review
  • Severity classification
Full package scope
  • Technical evidence documentation
  • Remediation guidance
  • Validation / retest scope if agreed
  • Executive-readable summary
Get a Quote

Authorized Pentest

For organizations that need hands-on, scoped penetration testing on systems they are authorized to have tested.

Hands-on, scoped penetration testing performed strictly within an authorized and agreed scope.

Includes Vulnerability Assessment, plus:
  • Explicitly defined scope
  • Written authorization verification
  • Attack-surface mapping
  • Controlled exploitation where authorized
  • Authentication / authorization testing
  • Input & application-flow testing
  • Business-logic review where applicable
  • Vulnerability validation
  • Evidence collection
Full package scope
  • Severity / risk classification
  • Executive summary
  • Technical findings report
  • Remediation recommendations
  • Retest options where agreed
Get a Quote

Not sure which fits? Get a Quote →

Questions

Security & Penetration Testing FAQ.

Common questions about authorization, scope and reporting.

Do I need to own the website?

You need to be the owner of the system, or have documented authorization from the owner, before any assessment or testing begins.

Do you test third-party systems?

No. We do not test systems belonging to a third party without that third party's own explicit permission.

What does authorization mean here?

Written confirmation from the system owner that testing is permitted, along with an agreed scope, systems in and out of bounds, and a testing window.

Will testing affect production?

Assessment types and testing windows are chosen to minimize disruption, and any risk to production systems is discussed and agreed before testing begins.

What happens after vulnerabilities are found?

Findings are documented with severity and context, and delivered with practical remediation guidance.

Is a report provided?

Yes. Every engagement ends with a written report covering findings, risk context and remediation guidance.

Ready to scope a security assessment?

Tell us about the system you're authorized to test, and we'll follow up to define scope and next steps.

Get a Quote