Security testingbuilt for shipping teams.Clear scope. Defensible evidence.
Fixed-scope discovery, web and API pentesting, AppSec and continuous validation. Argus handles repeatable work; experienced reviewers validate material findings and evidence.
Four focused ways to
produce security evidence.
Start with a structured diagnostic, test a defined application, add checks to selected repositories or keep product evidence current as threats and software change. Every boundary is explicit before work begins.
Website and application pentesting
Four fixed scopes, from a simple public website through authenticated applications, APIs, roles and business logic.
- From €490
- Fixed authorised scope
- Expert-validated findings
- One 30-day retest
Discovery Sprint
A structured, asynchronous diagnostic that maps one product, its security posture and its regulatory exposure — in 10 working days after a complete intake.
- Secure guided intake
- Architecture and data-flow map
- Prioritised security and compliance risks
- Expert-validated 90-day roadmap
Argus Sentinel
Scheduled Argus assessments for one product, with human review reserved for material findings and two focused manual testing windows each year.
- From €30,000/year
- Monthly automated validation
- Two focused manual windows
- No on-call obligation
Argus AppSec
Fast automated checks stay distinct from verified findings. Repository access authorises code analysis only; dynamic testing always requires a separate approved scope.
- Selected-repository onboarding
- Immutable commit fingerprint
- Semgrep and dependency results
- SARIF and repository status checks
- Specialist review queue
Who this is for
Built for companies that need real security evidence — not checkbox compliance.
SaaS and software houses
Pre-sales security questionnaires, ISO 27001, customer audits
Fintech and payments
DORA ICT risk, PCI DSS scope reduction, penetration test evidence
E-commerce and marketplaces
GDPR compliance, NIS2 readiness, API security
MSPs and IT vendors
Vendor security reviews, white-label pentest reports, NIS2 Annex I
Logistics and industry
NIS2 critical infrastructure, OT/IT boundary assessment
Regulated-sector suppliers
Banking, healthcare and public procurement supply chain requirements
Not a fit for: generic IT support, very early-stage startups without revenue, or companies that want checkbox compliance without real remediation.
Automation where it scales. Expert judgment where it matters.
Structured intake and Argus remove repeatable work. Experienced reviewers validate material findings, evidence and remediation guidance before delivery.
| Traditional consultancy | Generic scanner | Kotav Labs | |
|---|---|---|---|
| Scope | Defined through calls | Self-configured | Structured and fixed upfront |
| Client effort | Workshops and meetings | Tool setup | Secure asynchronous intake |
| Testing | Primarily manual | Automated only | Argus-assisted + expert validation |
| Findings quality | Deep, consultant-led | Often unvalidated | Evidence-backed and reviewed |
| Delivery | Project-dependent | Immediate output | Fixed delivery window |
| Retest | Often an add-on | Rescan | One defined retest included |
| Ownership | Report deliverable | Platform-dependent | Report, SARIF and evidence are yours |
Defined engagement or recurring validation.
Same operating discipline.
One-shot engagement
from €490- 01Complete the scope and access checklist.
- 02Sign Rules of Engagement before testing.
- 03Argus-assisted testing with expert validation.
- 04Receive the report, evidence, SARIF and one defined retest.
Argus Sentinel
from €30,000/year- 01One primary product under a 12-month scope.
- 02Monthly Argus validation and quarterly risk review.
- 03Two focused manual testing windows per year.
- 04Portal response within two business days; no incident response.
Slots into your existing security stack.
Evidence that stays useful.
Each engagement produces portable evidence, traceable findings and clear remediation guidance. Argus handles repeatable checks; reviewers protect signal quality.
Start with a complete scope.
Then start testing.
Tell us what you need to assess. We confirm the required intake, the smallest suitable engagement and the next available delivery window.
