Contact us: info@tenendo.com
Flexible pricing for tailored work.
Pricing depends on the size and complexity of your infrastructure or application, the roles and components in scope, and the testing approaches we apply. Every engagement is individually scoped — no hidden costs, no templates.
- Single web app or API in scope
- Manual scan result triage to cut false positives
- Severity-ranked, fix-oriented findings
- Re-test of fixed issues
- Web + mobile + API or desktop thick clients
- Business-logic & OWASP ASVS coverage
- Role-based / authenticated manual objective-oriented testing
- Fewer, more relevant findings — not noise
- Free re-test after remediation
- Everything in Application Pentest
- Security code review (whitebox)
- Re-testing on every major release
- Secure-SDLC & DevSecOps guidance
- External attack surface mapping and enumeration
- Data leak audit during the OSINT step
- Exploitation of exposed services
- Perimeter hardening recommendations
- Re-test of fixed issues
- Attack scenarios tailored to the environment
- IAM exploitation & privilege escalation
- Simulated post-exploitation, based on a defined objective
- Monitoring & detection gap analysis
- Free re-test after remediation
- Security assessment of the architecture
- Cloud segmentation & PCI DSS testing
- Multi-cloud & hybrid coverage
- An advanced, realistic external attack
- In-house tools & payloads
- Complex social engineering and other tailored initial access vectors
- SOC / SIEM / EDR effectiveness evaluation
- Simulated post-exploitation and objective completion
- Threat intelligence-led red teaming scenarios
- DORA & TIBER-EU methodology
- Integrated compliance reporting
- Partner ecosystem (e.g. TI vendors) for full-cycle delivery
- Up to 40% saving vs. fragmented vendors
- Tabletop exercises & role drills
- Ransomware & incident readiness
- SIEM / EDR effectiveness evaluation
- Detection engineering specifically for your infrastructure
Also under Enterprise — audits, compliance & advisory
How scoping works
From questionnaire to scheduled work in days.
01
Complete the questionnaire
Tell us about your application, infrastructure, and goals. It helps us make an offer that’s realistic, accurate, and tailored — not a template.
02
Receive a commercial offer
Once we have your questionnaire, we typically return a fixed, individually-scoped commercial offer within 1–2 business days.
03
We schedule & start
As soon as the offer is accepted, we begin planning and scheduling the work without delay — and keep you in the loop throughout.
Every engagement includes
The same standard, whatever the scope.
▣
Audit-grade reporting
Reports accepted for SOC 2, ISO 27001, PCI DSS, and other certification needs.
↻
Re-testing of fixes
We validate your remediation so you can prove issues are genuinely closed.
◎
Signal, not noise
Fewer, more relevant findings — prioritized so you focus on what matters.
⛨
Defensive recommendations
Detection, monitoring, logging, and hardening guidance drawn from blue-team experience.
See the deliverable
Download an example report.
Get a full, audit-grade sample dossier — with evidence, reproduction steps, and remediation guidance — so you know exactly what lands at the end of an engagement.
Fixed-price projects welcome
Have a specific budget and a clear security challenge? Tell us your priorities and constraints — we’ll craft the most effective solution within your budget on a fixed-price basis.
Why don’t you list one flat price?
A pentest’s cost depends on scope — number of apps, roles, hosts, cloud accounts, and testing depth. Flat pricing either overcharges small scopes or under-delivers on large ones. We scope each engagement so the quote is fair and accurate.
How fast can we start?
Once your questionnaire is in, expect a commercial offer within 1–2 business days. Scheduling begins as soon as it’s accepted.
Do you re-test after we fix issues?
Yes — re-testing of remediated findings is included, so you can demonstrate closure to auditors and stakeholders.
Are reports accepted for compliance?
Our reports are audit-grade and used for SOC 2, ISO 27001, PCI DSS, DORA, and similar frameworks.
Take control
Find out what a real attacker would find first.
Tell us your priorities and constraints. We typically return a tailored commercial offer within 1–2 business days — fixed-price projects welcome.