Free support may be available subject to capacity.
Manual security testing focused specifically on web applications and realistic application-layer attack paths.
Where accepted into the free programme, web application testing can include scoping, written authorisation, rules of engagement, manual and authenticated testing where appropriate, evidence-led findings, remediation guidance and agreed retesting. Security Aid does not advertise general infrastructure penetration testing.
Free engagements are subject to eligibility, scope and available capacity. Memberships are for guaranteed capacity and ongoing support.
- Testing is limited to the agreed web application scope.
- Written authorisation and rules of engagement are required before testing.
- A submitted URL or description is not authorisation to test.
- Findings include evidence, risk context and practical remediation guidance.