// community security · Portugal

Five organisations. One controlled security baseline.

Kotav Labs is sponsoring five authorised application security reviews for organisations operating in Portugal. Two places are by invitation; three are open to public applications.

Cohort 01 / delivery rules
Selected organisations
5
Invitation / application
2 / 3
Application window
7 days
Public disclosure
Opt-in only

No testing starts until the authorised representative has approved the scope and signed the Rules of Engagement.

the programme at a glance

Limited on purpose. Useful by design.

This first cohort is small enough for specialist review, private delivery and a meaningful product scope—not a mass automated scan.

5
selected organisations
first Portuguese cohort
2
invitation places
chosen directly by Kotav
3
public application places
selected after the window closes
90
days of voucher validity
after the initial report
// why we are doing this

Digital services people rely on deserve evidence, not alarm.

Companies, associations, public bodies and community organisations rely on websites, portals and web applications. This programme gives five of them a practical way to validate one important part of that exposed surface.

Controlled from the start

The organisation decides what is in scope, when testing may happen and who must be contacted if something material appears.

Reviewed before delivery

Argus handles repeatable checks. A specialist reviews material findings and the supporting evidence before the report is delivered.

Confidential by default

Findings, evidence and participation stay private. Any public mention or case study requires separate written approval.

// exact service boundary

A meaningful product review with a deliberately narrow scope.

Each selected organisation receives the same Sponsored Application Security Review. It goes beyond a simple website check without pretending to be a full application pentest.

Included

  • One public-facing web application on a single technology stack.
  • One authenticated role and one representative critical workflow.
  • The primary API calls required by that workflow, limited to explicitly approved hosts.
  • Argus-assisted testing plus specialist review of material findings.
  • A concise confidential report with evidence, reproduction steps, impact and remediation guidance.
  • If a Critical finding is confirmed, one targeted verification window for its fix within 30 days.
  • A voucher for 50% off one retest of the original findings, valid for 90 days after the report.

Outside this programme

  • Additional roles, separate administration areas, complex SSO, multi-tenancy or additional workflows.
  • Broad API coverage, mobile applications, infrastructure, cloud configuration or source-code review.
  • Remediation implementation, continuous monitoring, incident response or certification guarantees.
  • A full retest unless the voucher is used; remediated findings remain unverified until they are retested.
  • Any host, method or testing window not explicitly authorised in the signed scope.

This is not the full Web Application Pentest sold from €3,500. Before testing, the signed scope records the application, role, workflow, two-day testing window and the fixed standard price of the optional retest. The voucher reduces that recorded price by 50%. If the target cannot be isolated safely within these limits, it is not eligible for this cohort.

// how participation works

Selection first. Authorisation before testing. Evidence at the end.

Applications are assessed after the seven-day window. This is not first-come, first-served.

  1. 01

    Application or invitation

    The organisation identifies the application, one user role, one important workflow and the responsible contact.

  2. 02

    Fit check

    Kotav confirms that the target can be isolated within the sponsored boundary and that a stable test account can be provided.

  3. 03

    Written authorisation

    The authorised representative approves hosts, dates, methods, limits, emergency contacts and the Rules of Engagement.

  4. 04

    Controlled assessment

    Argus operates only in the approved scope during a two-day testing window. Material signals are checked by a specialist before they become findings.

  5. 05

    Private delivery

    The organisation receives an audit-suitable report with verified evidence and practical remediation guidance.

  6. 06

    Fix verification options

    A confirmed Critical fix gets one targeted verification window. The 50% retest voucher can be used once during the following 90 days.

// selection principles

Every public place follows the same eligibility and selection criteria.

Kotav first checks every mandatory eligibility requirement. Eligible applications are then compared on service fit, ability to act on the results, expected benefit and cohort diversity. There is no draw and submission order gives no advantage.

  • The applicant is an organisation established or operating in Portugal, not an individual or personal project.
  • The organisation owns or manages the target application, or can provide written authority from the owner.
  • The target fits one application, one authenticated role and one representative critical workflow.
  • The organisation can provide a stable test account, protect confidential findings and appoint a technical contact.
  • The organisation accepts the written scope and Rules of Engagement and can coordinate remediation after delivery.
// public application

Apply for one of three public places.

Tell us enough to assess fit. Submission does not authorise testing and does not guarantee selection.

The information is used only to assess and coordinate this programme, under our privacy policy.

// straight answers

Questions we expect.

Is the review really sponsored?

Yes. The defined Sponsored Application Security Review is delivered to all five selected organisations without a fee or purchase obligation. A full retest is not included.

When does testing begin?

Only after selection, a fit check and written approval of the exact scope and Rules of Engagement by an authorised representative.

Will Kotav name the organisation?

No. Participation, findings and evidence are confidential by default. A logo, quote or anonymous case study requires separate written consent.

What exactly can be tested?

One public-facing web application, one authenticated role, one representative workflow and the primary API calls that workflow requires. Broader or more complex targets do not fit this cohort.

How does the retest voucher work?

The signed scope records the fixed standard retest price before testing. The voucher reduces that price by 50%, may be used once within 90 days and covers only the original findings and scope. A confirmed Critical fix has one targeted verification window at no cost.

How are the public places chosen?

Kotav first confirms all eligibility requirements, then compares eligible applications on service fit, readiness to act, expected benefit and cohort diversity. There is no draw and no advantage for applying first.

Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU