Penetration testing for web applications
Notra attacks your live web app the way a real attacker would — over HTTP, from the outside — and returns only what it could prove. Every finding ships the exact request and response that demonstrated it. Deep Audit is $149 flat, report in about an hour.
How the run works
1 · Map
The agent crawls your app, fingerprints the stack and framework versions, and inventories the attack surface: routes, parameters, cookies, headers, exposed files.
2 · Probe
It probes each surface for auth and session flaws, injection sinks, dangerous exposed files, and known-vulnerable component versions — within a fixed, manifest-pinned request budget.
3 · Gate
Every candidate is re-attacked with a harmless proof-of-exploit. Under 0.8 confidence it never ships — you can watch the gate work live instead of trusting it.
4 · Evidence
What survives the gate ships with its exhibit: the exact HTTP request and response that proved it, plus the fix in plain English.
What the audit goes after
Cookie flags (Secure, HttpOnly, SameSite), token handling, logout behavior, and the JWT/session-chain weaknesses that let a session live longer or travel further than it should.
Injection-class probes proven with harmless PoCs, plus read-only checks for exposed environment files, config backups, debug endpoints, and secrets accidentally shipped to production.
Fingerprinted framework and library versions checked against known CVEs, plus the missing hardening — security headers, TLS posture, CORS — that turns small bugs into exploitable ones.
The honest scope line
Strong at
Known exploit classes with mechanical proofs: injection, exposed files and secrets, auth/session weaknesses, CVE-exposed components, missing hardening.
Not this
Novel multi-step business-logic chains that need human creativity. If you suspect those, a manual engagement is the right buy — Notra fits between their visits.
Not paperwork
The report is evidence you can attach to a customer review, not a signed auditor letter. If the letter is the deliverable, buy the humans.
Want to see the evidence standard before paying anything? Read a sample verified report, or start smaller: the free scorecard passively checks about 16 items in roughly a minute and tells you whether a full audit is worth the $149.
Questions people ask first
Do the probes damage my app?
No. Injection-class findings are proven with harmless proof-of-concept payloads — a benign script tag that proves the sink fires, not a payload that mutates data. Every request the agent makes carries a public abuse contact, and the run is manifest-pinned so you can see exactly what was sent.
Do I need to hand over credentials?
No. The Deep Audit ($149) runs unauthenticated — roughly 360 requests over about 60 minutes against the public surface, targeting up to 20 verified findings. If you want the logged-in surface probed too, Deep+ ($299) accepts one session cookie and runs a larger request budget over about 90 minutes.
What happens if it finds nothing?
You get an honest empty set: the surface was mapped and probed, nothing could be verified, and the report says exactly that. There is no padding with low-confidence maybes — under the 0.8 verification threshold, a candidate never ships.
If the passive checks flag anything, a $149 Deep Audit turns it into verified findings with proof.
Related: see how this stacks up against a manual pentest, the full pricing breakdown, or keep the app covered between releases with continuous monitoring.