Free planning tool · no sign-up

Build a web and API pentest scope brief in minutes.

Use this private scope template to map applications, APIs, roles, tenants, workflows, environments, safety controls, timing, and report needs before you request a quote.

  • About 5 minutes
  • Saved only in this browser
  • No secrets requested
Scope topology Planning
TRIGGEREnterprise dealEvidence due
SURFACESWeb + API2 trust boundaries
OUTCOMEVerified evidenceReport + re-test

Good scope connects what the business needs to the exact boundaries an attacker will test.

01Bounded surfaces
02Trust model
03Safety prerequisites
04Draft scope brief
Scope before price

Build a defensible first draft.

Only counts and planning choices are collected. You can validate target names and access details later under an NDA.

Do not enter credentials or secrets. Never put passwords, API keys, session tokens, customer data, private hostnames, or exploit details into a scoping tool.

Step 1 of 6Business outcome

Answers stay on this device
01 / Business outcomeWhy does the test need to happen now?

The buying trigger determines which evidence matters and how hard the deadline really is.

Primary trigger

Choose the event that would make the engagement valuable even if no severe finding appears.

02 / Target surfacesWhat can an attacker reach?

Select deployable surfaces, then bound the number of distinct applications and API groups.

In-scope surfaces

Choose every surface that needs active testing in this engagement.

03 / Trust modelWhich boundaries must hold?

Authorization and tenant isolation usually create more meaningful work than endpoint count alone.

Tenant model

Authentication paths

Choose every identity path that should be examined.

04 / Critical workflowsWhere would abuse hurt most?

The best tests follow value and privilege through the product, not just a generic vulnerability checklist.

Priority abuse paths

Choose the workflows that deserve manual business-logic testing.

Business-logic depth

05 / Environment & readinessCan testing start safely?

A shorter test window is only credible when access, test data, contacts, and stop conditions are ready.

Test environment

Safety window

Inputs already available

Missing items become explicit readiness gaps in your brief.

06 / Evidence & timingWhat does “done” need to look like?

Select the outputs required to make a decision, fix the findings, and show closure.

Required outputs

The result is a planning brief, not a quote. Balhence will validate the asset inventory, access assumptions, safety rules, calendar, and exclusions before issuing a statement of work.

What the planner does and does not do

A useful boundary, before a commercial promise.

Scope is a model of attack paths, access, depth, evidence, and safety. The final statement of work still requires a human review.

01 / BOUNDS

Counts what changes effort

Applications, APIs, roles, tenants, authentication paths, integrations, workflows, and environments.

02 / SAFETY

Surfaces missing prerequisites

Authorization, controlled accounts, safe data, contacts, documentation, windows, rate limits, and stop conditions.

03 / HONESTY

Returns a band, not a quote

The output is deliberately indicative. Asset validation and rules of engagement can still change timing or commercial terms.