VAPAN // Пентестинг у Тернополі
Penetration testing, web app pentest and security audit in Ternopil
Перевірка безпеки вашого сайту, API, програми та інфраструктури. Знайдемо і покажемо «діри» в безпеці до того, як ними скористається хтось інший
Як ми працюємо
- Обговорюємо цілі
- Збираю інформацію про ваші сервіси без навантаження на прод
- Перевірка і спроби атаки — акуратно, без руйнування даних
- Звіт + план дій — швидкі перемоги (quick wins) та довгострокові кроки. Ретест — у комплекті
Для кого підходить
- Бізнес Тернополя та області: від малого до середнього
- SaaS, маркетплейси, веб-портали з оплатами та персональними даними
- Команди з вимогами до комплаєнсу або підготовкою до інвест-/партнерського аудиту
Веб-застосунки
Перевіряємо логіку, авторизацію, завантаження файлів, платежі, роботу з даними. Виявляємо XSS/IDOR/SSRF та інші поширені проблеми.
API та мікросервіси
REST/GraphQL, токени, доступи, ліміти, інтеграції між сервісами. Перевіримо, чи можна «обійти» правила або витягнути зайві дані.
Мобільні
iOS/Android: зберігання даних, робота з бекендом, перехоплення трафіку. Перевіримо, що користувацькі дані не витікають.
Інфраструктура
Зовнішній периметр, відкриті порти, слабкі паролі, помилки у налаштуваннях. Допоможемо закрити «зайві двері» в інтернет.
Хмара/Kubernetes
Права доступу (IAM), секрети, політики, контейнерна безпека. Зробимо так, щоб з хмари випадково не «світилось» нічого зайвого.
Соцінженерія
Навчальні фішинг-симуляції та короткі тренінги для команди, щоб співробітники не натискали на підозрілі листи.
Робочий Процес
Скоп та правила
01Узгоджуємо доступи, вікна робіт, контактну особу. Підписуємо NDA.
Розвідка
02Акуратно визначаємо, що видно ззовні та всередині.
Експлуатація
03Імітуємо дії зловмисника без шкоди даним.
Пріоритизація
04Розкладаємо проблеми за рівнем ризику та бізнес-впливом.
Звіт і ретест
05Даємо план виправлень, після фіксів — безкоштовний ретест.
Скоп та правила
01Узгоджуємо доступи, вікна робіт, контактну особу. Підписуємо NDA.
Розвідка
02Акуратно визначаємо, що видно ззовні та всередині.
Експлуатація
03Імітуємо дії зловмисника без шкоди даним.
Пріоритизація
04Розкладаємо проблеми за рівнем ризику та бізнес-впливом.
Звіт і ретест
05Даємо план виправлень, після фіксів — безкоштовний ретест.
Who is accountable for your pentest
Named lead
Every project has a named person responsible on the Vapan side. They run scoping, stay in touch during testing, sign the report and answer questions after delivery.
Methodology
We test manually following OWASP, automation only assists. Every finding comes with reproduction steps, a severity rating and a fix recommendation.
Quality control
We re-verify critical vulnerabilities before the report goes out. After your fixes we run a free retest and confirm the issues are closed.
Specialists we bring in
When the scope is bigger than our core team, we bring in vetted specialists under NDA. They follow our methodology and work under our lead. The contract and the report always come from Vapan.
Full cybersecurity spectrum
Together with our partner Altair Security we cover the whole cycle: red team, GRC, ISO 27001, SOC 2 and PCI DSS readiness, and team training. The full service list and portfolio are on the partner's site.
Partner services and portfolioPenetration testing FAQ
What is a penetration test?
A penetration test is a controlled attack on your website or infrastructure performed by an ethical hacker with your permission. The goal is to find vulnerabilities before real attackers do and show you exactly how to fix them.
How much does a penetration test cost in Ukraine?
A pentest of a small website or web application starts at $300, a full infrastructure audit is quoted individually. The exact price depends on the number of hosts and the app's functionality. We scope your project and send a quote for free within one day.
How long does testing take?
A web application pentest usually takes 5-10 business days, an external perimeter test 3-7 days. The report with remediation guidance is ready within 2-3 days after testing ends.
What do I get as a result?
An OWASP-aligned report: every finding prioritized by CVSS, reproduction steps (PoC) and concrete remediation advice. After you apply the fixes we retest for free and confirm the issues are closed.
Is it legal and is my data safe?
Yes. A pentest runs only with the written consent of the system owner, within an agreed scope and under a contract with an NDA. Your data is never copied or shared with third parties, and every action is documented in the report.
Can I use the pentest report for SOC 2 or ISO 27001?
Yes. An independent pentest is a standard piece of evidence for SOC 2 audits, ISO 27001 certification and security questionnaires from enterprise clients. The report covers methodology, scope, prioritized findings and their remediation status after the retest, which is what auditors ask for. Tell us during scoping which standard you are preparing for and we will match the report format to it.
Готові перевірити безпеку?
Опишіть, що потрібно протестувати — повернусь із планом пентесту, термінами та вартістю. Працюємо в Тернополі та по всій Україні.
What else we do
Development, security, marketing and automation are often bundled. Browse related services and cases.
