Skip to main content

Firepan Pentest

Firepan Pentest is a scoped penetration-testing engagement for agreed websites, applications, APIs, authentication, integrations, cloud, and network assets. Firepan and your team agree the scope, rules of engagement, and report in writing before testing begins. The reviewed report identifies what was tested, what was excluded, the findings and evidence, and practical remediation guidance. A retest is included only if it is agreed in that scope.

A Pentest request does not start testing. It lets our team discuss your targets, objectives, access needs, timing, and report requirements with you. Do not place credentials or other secrets in the request; Firepan arranges a separate secure handoff if test accounts or infrastructure access are needed.

Request and payment​

Start with the Pentest request. You can use the same Firepan account as Scan, Probe, and Audit, and you do not need a GitHub repository or commit SHA for a Web2 request. Name the assets you want to discuss and any exclusions or blackout periods. You must have authority to request testing, and the final written scope and authorization must be in place before active testing.

Firepan quotes each engagement separately. The quote sets the price, any card deposit, the remaining invoice, timing, and delivery terms. No fixed price or recurring Pentest subscription is implied by the request. Paying a deposit does not automatically start testing or change a Scan quota.

Use your account to submit and track a request. Firepan confirms any quote and deposit terms before payment. A cancellation request needs team follow-up; submitting it does not itself confirm that testing or a payment has stopped.

Choosing the right offer​

OfferScope
Firepan PentestAuthorized Web2 testing of an agreed application or infrastructure scope, with a reviewed report.
Contract HuntEVM exploit validation at a pinned contract revision or deployment, with bounded evidence and a reviewed disposition.
Scan / Probe / AuditAutomated smart-contract source analysis: Scan discovers common signals, Probe investigates a selected commit, and Audit is a deeper adversarial review.

A Contract Hunt does not cover its website or backend unless those are named in a separate Web2 scope. A Web2 Pentest does not imply a smart-contract audit. Combined work must state both scopes and outputs explicitly.

A Pentest report may support security reviews, enterprise procurement, and SOC 2 readiness. It is not a SOC 2 certification, a guarantee of security, or a promise that an auditor will accept the report without discussing the applicable controls and evidence.