Skip to main content
BilgeQor

Web & App Security Review

For Costa Rica teams, the approved Digital resilience and data-protection readiness context keeps Web & App Security Review focused on documented priority gaps and written remediation direction. It assesses agreed web, API, or mobile application surfaces and provides written severity-led observations with prioritised remediation direction. The work stays within agreed scope and does not certify compliance, issue approval, or guarantee an outcome.

From ₡2 320 000,00 CRC

Informational

Final scope, any applicable taxes, third-party costs, and commercial terms are confirmed in a written proposal. Checkout and payment are not available.

How We Deliver

Delivered through a senior-led review workflow. Findings, severity ratings and remediation priorities are provided in writing under a confidentiality-first process. This review does not provide certification, compliance approval or guaranteed vulnerability detection.

Good fit if

  • ✓You have production-facing web or mobile assets that need documented security observations
  • ✓You need prioritised findings to support customer, procurement, or governance discussions
  • ✓You're preparing for deeper testing, hardening, or compliance readiness work
  • ✓You want a written baseline before deciding on next security steps

Not a fit if

  • –You need immediate remediation implementation rather than assessment
  • –You require 24/7 monitoring, SOC, or MDR services
  • –You need certification, compliance approval, or formal audit opinion
  • –You expect guaranteed elimination of all security issues

Ideal for

  • You are preparing a web, API-backed or mobile product for launch, major release or external review
  • You are handling payments, personal data, authentication or other sensitive digital workflows
  • You need an independent application-security review before procurement, customer review or expansion
  • You need written, prioritised security findings for an agreed application scope

What you'll receive

Written application-security assessment appropriate to the agreed web, API or mobile scope
Severity-graded findings register with evidence references
Authentication, authorisation and sensitive-data handling observations
API or integration-security observations where included in the agreed scope
Prioritised remediation roadmap
Validation / retest outcome where included by the selected tier

After You Request This Service

When you select a package tier, you submit a request. We review scope in writing before any later commercial step. This page does not take payment, open intake, or start work.

Informational scope prices

Starter

₡2 320 000,00 CRC

Informational

One agreed application surface, such as a web application, API-connected product flow or one mobile platform. Focused security review and prioritised remediation guidance.

Request a written proposal
Most Popular

Standard

₡4 410 000,00 CRC

Informational

One complex application scope or agreed connected application flow, such as web or mobile with supporting API review. Deeper security analysis, remediation guidance and one retest.

Request a written proposal

Premium

₡8 830 000,00 CRC

Informational

Broader agreed application scope across multiple connected surfaces or complex product flows. Expanded review, prioritised roadmap and a second validation cycle.

Request a written proposal

Available Penetration Testing Scopes

The right testing scope is confirmed before work begins. Application-focused scopes can be reviewed within this service when agreed for the selected package. Broader infrastructure and specialist environments require separate scoping, authorisation and quotation.

Application Scopes For This Review

These application-focused scopes can be assessed within this service when agreed for the selected tier and confirmed in writing before work begins.

  • Web Application Security Testing — Examines customer-facing web applications for weaknesses in authentication, sessions, forms, access controls, data handling and common application attack paths.
  • API Security Testing — Within the confirmed API-focused scope, the review may examine REST, GraphQL, WebSocket and service-to-service interfaces where present, including authentication, authorisation, business-logic abuse paths, rate limiting, token and session boundaries, tenant isolation, data exposure, endpoint behaviour and integration risk. Evidence-backed findings are severity-prioritised with remediation guidance; any included retest is limited to agreed remediated findings, and implementation remains separately scoped.
  • Mobile Application Security Testing — Examines agreed iOS or Android application surfaces, application data handling, authentication flows, API interaction and security-relevant app behaviour.

Extended Testing Options — Separately Scoped

These areas are available only after separate scope confirmation, written authorisation and quotation. They are not automatically included in the current Starter, Standard or Premium pricing of this service.

  • Desktop Application Security Testing — Review of an agreed desktop application — how it handles user inputs, stores data on the device, communicates with backend services and protects sensitive workflows once installed on a workstation.
  • External Network Security Testing — Review of internet-facing systems from an outside perspective to identify exposed services, weak configurations and pathways an external party could attempt to use against the organisation.
  • Internal Network Security Testing — Review of the internal network environment from an authorised position inside the organisation, looking at how systems, accounts and services could be misused if an attacker reached the internal network.
  • Wireless Network Security Testing — Review of agreed wireless networks and access points — how users connect, how the wireless environment is segmented from sensitive systems, and where weak configurations could be misused.
  • VoIP Security Testing — Review of agreed voice-over-IP telephony components — call routing, authentication, exposed services and abuse paths that could affect communications integrity or call costs.

Specialist Acceptance Only

  • OT / SCADA / ICS Security Testing — Requires specialist technical acceptance, written authorisation, agreed safety constraints and a separate quotation before any work can be confirmed. Not positioned as automatically available for direct online purchase.

No package automatically includes every testing scope listed above. Final targets, environments, access requirements, authorisation, testing conditions and any retest or remediation support are confirmed before work begins.

  • Remediation implementation is not automatically included.
  • Full penetration testing is not automatically included unless separately agreed.
  • Testing does not certify security.
  • Testing does not guarantee that every vulnerability will be identified.
  • DDoS resilience testing, Red Team exercises and Threat Hunting are separate scoped engagements already available through the specialised-engagement path.

Included

  • One agreed application surface for Starter
  • Focused review of the confirmed web, API or mobile application scope
  • Authentication and authorisation review where relevant
  • Sensitive-data handling review where relevant
  • API or integration observations where included in the confirmed scope
  • Written findings and prioritised remediation guidance
  • Tier-appropriate retest / validation where already approved

Excluded

  • Hands-on code fixes (available as add-on)
  • Full penetration testing (custom scope)
  • Ongoing monitoring
  • App store submission assistance (see App Services)

Available Add-ons

  • +Additional agreed application surface
  • +Expanded API or integration review
  • +Hands-on remediation support
  • +Follow-up validation beyond the included tier scope

How it works

1

Purchase & Intake

Customer confirms the agreed application scope, authorised access method and relevant technical context.

2

Security Assessment

Review examines the agreed application surface and related security-relevant flows.

3

Report & Analysis

Written findings and remediation priorities are delivered.

4

Handoff & Guidance

Handoff and included validation proceed according to the selected tier.

Timeline: Confirmed during intake based on scope and package tier. Typical delivery timeframes provided after intake completion.

Methodology illustration

A privacy-safe illustration of how one mobile-application scope can be documented within this service, including an OWASP-referenced findings register and prioritised remediation roadmap.

Illustrative mobile application scopeApplication Security Review — mobile scope illustrationIllustrative Standard-tier structure
Challenge

Illustrative scenario: a mobile application is preparing for an internal release and risk review. The example scope covers one mobile application surface with supporting API review to demonstrate how authentication, authorisation and sensitive-data handling observations may be documented.

Scope applied
  • Standard tier — one agreed mobile application surface with supporting API review
  • Security-focused review of agreed authentication and sensitive-data handling flows
  • Supporting API and integration-security observations within the confirmed scope
  • Prioritised findings and remediation guidance
  • One included retest for agreed remediated findings
Result

This methodology illustration shows how findings may be documented across severity bands with a prioritised remediation roadmap and one validation outcome for agreed remediated findings. It demonstrates one possible agreed scope under the broader application-security review service; scope, findings and outcomes vary by engagement.

Deliverable preview

Application Security Review — Findings Register (Mobile Scope Illustration)

  • Executive summary of application security posture for the agreed mobile scope
  • Severity-graded findings register with relevant OWASP Mobile references for this mobile-scope illustration
  • Supporting API security observations within the confirmed scope
  • Sensitive-data handling review
  • Authentication and authorisation analysis
  • Prioritised remediation roadmap and validation outcome
Findings Register — Illustrative RowFinding 04 — [REDACTED ASSET]: cleartext session token in local storage. Severity: High. OWASP Mobile reference applied for this mobile-scope illustration (M9 — Insecure Data Storage). Remediation: migrate to platform secure storage. Status: Open.

Illustrative document structure. A confirmed engagement receives documentation appropriate to its agreed web, API-backed or mobile application scope.

Security File context

How this deliverable fits into the Security File

This representative deliverable shows the kind of evidence, priorities and follow-through notes that can sit inside a practical BilgeQor Security File after handoff.

The Security File is a decision aid, not a certification, compliance verdict, guarantee of perfect security, or per-company loss estimate.

See the delivery method
Note:Methodology illustration, not a client case study. A confirmed engagement may cover an agreed web, API-backed or mobile application scope. Scope, findings and outcomes vary by engagement.

Frequently Asked Questions

Ready to get started?

Choose a package tier or talk to us about custom scope