// Services

Seven fixed scopes. Built for decisive action.

Choose the smallest service that answers the decision in front of you. Each boundary states what is tested, where specialist review applies and what you receive.

7 services Explicit boundaries Specialist-reviewed evidence
ARGUS / Services07
Choose the smallest service that answers the decision in front of you. Each boundary states what is tested, where specialist review applies and what you receive.
// test what is deployed

Security Validation

Authorised discovery and testing of websites, applications, APIs, infrastructure and external attack surface.

01 / SERVICES

Website Pentest

A fixed-scope assessment for a public website on one technology stack. It covers the root domain, www and up to five owned subdomains that belong to the same website.

// Output
  • 01Root domain, www + up to 5 owned subdomains
  • 02Public, unauthenticated surface
  • 03Argus testing + expert review of material findings
  • 04Concise report with evidence and recommendations
  • 05One retest within 14 days
02 / SERVICES

Web Application Pentest

For a standard web application with one authenticated role, its directly consumed API and up to three critical workflows. Separate admin apps, complex SSO, multi-tenancy and additional roles require a larger scope.

// Output
  • 01One web application
  • 02One authenticated role
  • 03Primary API used by the application
  • 04Up to three critical workflows
  • 05Reviewed report + SARIF
  • 06One retest within 30 days
03 / SERVICES

Focused Validation

A deliberately narrow engagement for teams that need credible validation without paying for unused scope. Suitable for one small web application or API, up to two authenticated roles and a clearly defined test boundary.

// Output
  • 01Signed Rules of Engagement before testing
  • 02One bounded application or API
  • 03Up to two authenticated roles
  • 04Argus-assisted testing and expert validation
  • 05Evidence-backed findings in the portal
  • 06Reviewed report + SARIF
  • 07One retest within 30 days
04 / SERVICES

Full Application Pentest

A deeper assessment for products with authentication, multiple roles and material business logic. Scope includes one web application, its primary API, authenticated and unauthenticated paths, and up to four roles.

// Output
  • 01Web application + primary API
  • 02Up to four authenticated roles
  • 03Authentication, authorisation and session testing
  • 04Business-logic and tenant-isolation testing
  • 05Expert-validated evidence and remediation guidance
  • 06Reviewed report + SARIF
  • 07One retest within 30 days
05 / SERVICES

Discovery Sprint

A structured, asynchronous diagnostic for one product. The client completes a guided intake and uploads existing evidence; automation maps the architecture, data flows and risk surface; the final roadmap is reviewed before delivery.

// Output
  • 01Secure guided intake with completion checks
  • 02One-product architecture and data-flow map
  • 03Access model, integrations and AI component inventory
  • 04Prioritised security and regulatory risk register
  • 05Expert-validated 90-day roadmap
06 / SERVICES

Argus Sentinel

A 12-month validation programme built around scheduled Argus runs and bounded human review. It is not a SOC, a 24/7 monitoring service or incident response. Human effort is reserved for material findings, quarterly risk review and two focused manual testing windows.

// Output
  • 01Baseline Focused Validation
  • 02Monthly Argus validation
  • 03Quarterly risk review
  • 04Two focused manual testing windows per year
  • 05One retest per manual window
  • 06Portal response within two business days
// secure what is shipped

AppSec

Repository and pull-request assurance with immutable commit identity and customer-controlled policies.

01 / SERVICES

Argus AppSec

Fast automated checks stay distinct from verified findings. Repository access authorises code analysis only; dynamic testing always requires a separate approved scope.

// Output
  • 01Selected-repository onboarding
  • 02Immutable commit fingerprint
  • 03Semgrep and dependency results
  • 04SARIF and repository status checks
  • 05Specialist review queue
// next step

Pick a defined scope or start with the intake.

Unsure which engagement fits? Tell us what you need to assess. We will confirm the smallest suitable scope and send a fixed-fee proposal.

Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU