Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Testing · Security testing packages

The three packages are different depths of the same method. Which one fits depends on your number of assets, the complexity of your application and who will read the report; we map the scope together before you decide.

  • Authorized scope
  • Risk table
  • Finding evidence
  • Remediation plan
01 / What this service includes

Need, not size, decides the package.

01

We define the scope precisely

In every package the quote lists which assets are reviewed, to what depth and in how many rounds. Needs that arise later are added through a new scope version.

02

The method is the same in every package

Even in the Starter package findings are verified manually and reported with evidence. The difference between packages is not rigour but the breadth and depth of what is examined.

03

A retest is part of the package

After you apply the fixes, the same findings are tested again. A “fixed” claim and a “closure verified” result are shown separately in the report.

02 / How it works

The packages side by side

The comparison below is indicative; the exact scope is written in the quote once your assets have been reviewed.

Starter

  • External surface review
  • Manually verified findings
  • Retest
  • Authenticated user testing
  • Business-logic and permission scenarios
  • Executive briefing and roadmap

Standard

  • External surface review
  • Manually verified findings
  • Retest
  • Authenticated user testing
  • Business-logic and permission scenarios
  • Executive briefing and roadmap

Comprehensive

  • External surface review
  • Manually verified findings
  • Retest
  • Authenticated user testing
  • Business-logic and permission scenarios
  • Executive briefing and roadmap
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Authorized scope
  • 02Risk table
  • 03Finding evidence
  • 04Remediation plan
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Assessment

    We assess the current state against agreed criteria and note gaps with evidence.

  3. 03

    Reporting

    We share what was done, the result and the next step in a plain report.

  4. 04

    Retest

    We retest fixed findings and confirm with evidence that they are closed.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • One retest within 30 days of the report is included in the price.
  • Evidence, a risk level (critical, high, medium, low) and a fix recommendation for every finding.
  • An executive summary and a risk table.

Not included

  • Phishing and phone-based social engineering (each needs separate written approval).
  • Tests that could disrupt a service (only with separate written approval, in a controlled setting).
  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A signed written authorisation.
  • A scope list: domains, IP addresses, applications and the date range.
  • Test accounts for a grey-box test.

Timing and delivery

  • Tests run on weekdays between 09:00 and 18:00 (Türkiye time).

What sets the price

  • Package level: Starter, Standard or Comprehensive.
  • Number of web assets (one domain, its subdomains and one connected application).
  • Number of network blocks (up to 256 IP addresses each).

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
How do I know which package to choose?

In the first meeting we discuss your assets, user roles and any previous test results. Based on that we recommend a package; if your need differs, we can combine packages into a custom scope.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.