Controlled from the start
The organisation decides what is in scope, when testing may happen and who must be contacted if something material appears.
Kotav Labs is sponsoring five authorised application security reviews for organisations operating in Portugal. Two places are by invitation; three are open to public applications.
No testing starts until the authorised representative has approved the scope and signed the Rules of Engagement.
This first cohort is small enough for specialist review, private delivery and a meaningful product scope—not a mass automated scan.
Companies, associations, public bodies and community organisations rely on websites, portals and web applications. This programme gives five of them a practical way to validate one important part of that exposed surface.
The organisation decides what is in scope, when testing may happen and who must be contacted if something material appears.
Argus handles repeatable checks. A specialist reviews material findings and the supporting evidence before the report is delivered.
Findings, evidence and participation stay private. Any public mention or case study requires separate written approval.
Each selected organisation receives the same Sponsored Application Security Review. It goes beyond a simple website check without pretending to be a full application pentest.
This is not the full Web Application Pentest sold from €3,500. Before testing, the signed scope records the application, role, workflow, two-day testing window and the fixed standard price of the optional retest. The voucher reduces that recorded price by 50%. If the target cannot be isolated safely within these limits, it is not eligible for this cohort.
Applications are assessed after the seven-day window. This is not first-come, first-served.
The organisation identifies the application, one user role, one important workflow and the responsible contact.
Kotav confirms that the target can be isolated within the sponsored boundary and that a stable test account can be provided.
The authorised representative approves hosts, dates, methods, limits, emergency contacts and the Rules of Engagement.
Argus operates only in the approved scope during a two-day testing window. Material signals are checked by a specialist before they become findings.
The organisation receives an audit-suitable report with verified evidence and practical remediation guidance.
A confirmed Critical fix gets one targeted verification window. The 50% retest voucher can be used once during the following 90 days.
Kotav first checks every mandatory eligibility requirement. Eligible applications are then compared on service fit, ability to act on the results, expected benefit and cohort diversity. There is no draw and submission order gives no advantage.
Tell us enough to assess fit. Submission does not authorise testing and does not guarantee selection.
Yes. The defined Sponsored Application Security Review is delivered to all five selected organisations without a fee or purchase obligation. A full retest is not included.
Only after selection, a fit check and written approval of the exact scope and Rules of Engagement by an authorised representative.
No. Participation, findings and evidence are confidential by default. A logo, quote or anonymous case study requires separate written consent.
One public-facing web application, one authenticated role, one representative workflow and the primary API calls that workflow requires. Broader or more complex targets do not fit this cohort.
The signed scope records the fixed standard retest price before testing. The voucher reduces that price by 50%, may be used once within 90 days and covers only the original findings and scope. A confirmed Critical fix has one targeted verification window at no cost.
Kotav first confirms all eligibility requirements, then compares eligible applications on service fit, readiness to act, expected benefit and cohort diversity. There is no draw and no advantage for applying first.