Web-app pentest
from CHF 1,490
One web application tested against the OWASP Top 10 and business logic. Audit-ready report with CVSS rating, retest included.
A penetration test, often called a pentest or ethical hacking for short, is a simulated, manual attack on your critical systems. SIDD testers work to OWASP, PTES and OSSTMM, with a named lead tester and a traceable report. No scanner output, but real business-logic findings.
Working for regulated industries and SMEs
Synonyms for the same process: an authorised attack on your critical systems in order to find real vulnerabilities before real attackers do.
Simple, low-cost pentests are often (partly) automated and use off-the-shelf tools to scan for known vulnerabilities. They identify surface-level issues but miss business-logic flaws, design flaws or zero-days. Manual penetration tests are carried out by certified pentesters who develop tailored attack scenarios, penetrate more deeply and provide concrete remediation recommendations, including a complete, business-readable report.
For pure vulnerability scans, we offer the separate Vulnerability scan from CHF 5'000.
We test in line with the three leading industry standards.
We cover the full scope, individually or combined:
Pentests are not off-the-shelf products, but we provide you with transparent price ranges per test type. Final price after scoping.
| Test type | Typical duration | Price range |
|---|---|---|
| Web app (medium) | 5–10 days | CHF 12'000 – 25'000 |
| External network | 3–7 days | CHF 8'000 – 18'000 |
| Internal network | 5–10 days | CHF 12'000 – 28'000 |
| API (REST/GraphQL) | 4–8 days | CHF 10'000 – 22'000 |
| Mobile app (iOS/Android) | 6–10 days | CHF 14'000 – 26'000 |
The final price depends on the scope, the number of endpoints/hosts, the desired depth (black/grey/white box) and retest requirements.
Web-app pentest
from CHF 1,490
One web application tested against the OWASP Top 10 and business logic. Audit-ready report with CVSS rating, retest included.
Infrastructure pentest
on request
External perimeter or internal network. Scope based on the number of hosts and services, fixed price after the scoping call.
Full scope
on request
Web, API, cloud and network combined. For certifications, FINMA audits and due diligence.
Six phases, transparently documented.
Digital service agreement and Rules of Engagement.
Define objectives, scope, methodology and schedule. Grant authorisations.
Gathering information on target systems, IP addresses and applications.
Manual and automated tests identify attack vectors and assess risks.
Vulnerabilities are exploited, access, data extraction, privilege escalation, all documented.
Detailed report with findings, CVSS scores, remediation recommendations and lessons learned. Debrief call included.
A pentest is only as good as the person carrying it out, and only as credible as the firm behind it: at SIDD, certified testers, in-house engineering and legal confidentiality come together.
You know who is attacking your systems: a named, certified lead tester (OSCP, CREST-trained) remains your dedicated point of contact from scoping through to remediation sign-off. No rotating subcontractors, no anonymous reports.
Our CTO Oliver Stutz leads an in-house InfoSec and software engineering team. Those who build applications themselves recognise business logic flaws and auth/authZ weaknesses that pure scanners and pure consultants overlook.
Where Dr Staiger acts as your lawyer, your vulnerabilities fall under Swiss professional secrecy pursuant to Art. 321 SCC. Findings are shared exclusively with the persons you designate, a level of confidentiality that purely technical providers cannot offer.
We do not first sell you the gap and then the product that closes it. The penetration test remains an independent assessment, which keeps the report audit-credible against ISO 27001, DORA or NIS2.
Rules of engagement, commissioned processing and liability questions are clarified by lawyers holding doctorates while the InfoSec team conducts the testing. This way, contract, authorisation and data protection are properly settled before the first attack is launched.
SIDD has operated as a Swiss brand since 2017, with a first response within 24 hours and a dedicated contact person. Mandates in CH, EU, UK and US allow penetration tests to span multiple locations and jurisdictions.
For SMEs we offer penetration tests as a fixed-price package with a clearly defined scope: one web application, the external perimeter or a delimited network segment. You receive the same manual testing approach and the same traceable report as our corporate clients, at a predictable price.
Beyond the penetration test itself, our IT security audit assesses your technical and organisational measures against recognised frameworks such as ISO 27001 and the Swiss ICT minimum standard. You receive a prioritised list of measures with which risks can be demonstrably reduced.
You receive an audit-ready report: management summary, technical findings with CVSS score, reproduction steps and concrete remediation recommendations. After remediation, a retest is included.
Our report is accepted by the bodies that matter to you:
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the pentest report, concretely: LexCommand ties each finding to the specific obligation it breaches with a cited source and, via the framework crosswalk, surfaces which ISO 27001, DORA, NIS2 and revFADP requirements the same gap touches at once, keeping the report audit-credible.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Depending on the scope, 3–10 tester-days. Including reconnaissance, test execution, reporting and debrief, the calendar duration is 2–4 weeks from kick-off.
We usually recommend grey box (limited prior information, possibly a standard account). Black box is realistic but time-consuming. White box uncovers the most vulnerabilities per day, well suited to internal audits.
On request, yes. A retest after your remediation typically costs 20–30 % of the initial effort and is agreed as part of many mandates.
Both. The report contains an executive summary for executive management/the board of directors and a technical detail section for your IT/developers, each with CVSS scores and remediation recommendations.
If you want to check regularly for known vulnerabilities, the Vulnerability Scan. To validate business logic, auth/authZ and manual attack paths, you need a penetration test. Many clients combine the two (scan quarterly, penetration test annually).
Yes. Findings are shared exclusively with the persons you designate. Enquiries are subject to professional secrecy under Art. 321 SCC.
30-minute scoping call. We will give you the price and timeframe immediately afterwards.