What is in scope?
Applications, API hosts, mobile clients, relevant cloud services, and environments.
Share the applications, APIs, roles, tenant model, deadline, and reason for testing. No testing begins until scope, authorization, safety rules, timeline, and commercial terms are signed.
The first response will confirm fit, identify missing scope inputs, and suggest the smallest useful next step. If a pentest is not the right next step, we will say so.
Prefer email? contact@balhence.com
Not ready to share details? Build a private Draft Scope Brief first.
Review the planning output before sending it. Nothing is submitted until you use the form below.
You do not need perfect documentation. These four inputs are enough to begin.
Applications, API hosts, mobile clients, relevant cloud services, and environments.
Customer roles, admins, partners, support access, tenant hierarchy, and SSO states.
Payments, sensitive data, approvals, exports, invitations, integrations, or other critical workflows.
Engineering, leadership, an enterprise customer, an auditor, or another decision-maker.