Web & API Review

Web, API & cloud-adjacent review. Bounded scope. Reviewed evidence.

The current service covers authorized web applications, APIs, and agreed cloud-adjacent exposure. Automated provider connections, account-wide discovery, and continuous cloud scanning remain on the roadmap and are not part of the live service.

Preparing a test? Read the cloud pentest checklist for SaaS teams, how automated vulnerability assessment compares to a manual pentest, and how to evaluate an AI security testing provider.

Current scope and roadmap

Two one-time pilot checkouts are available: €50 for a focused review and €199 for a deeper review. The authorized scope and safety limits are still reviewed before testing. Recurring billing is not offered through the website, and the live service does not include unattended monitoring or automatic provider discovery.

The cloud account scanner is roadmap-only. AWS, Azure, GCP, and GitHub connections, account-wide asset discovery, secure credential vaulting, tenant isolation, automated runner lifecycle, and human report publishing gates must be completed before that product is available.

What the current service covers

Loki's current service is a bounded, human-reviewed assessment of authorized web applications and APIs. A written scope can add cloud-adjacent exposure such as internet-facing cloud services, integrations, identity boundaries, or configuration evidence that the customer is permitted to provide.

The current service does not provide automatic AWS, Azure, GCP, or GitHub account connections, account-wide discovery, unattended monitoring, or continuous cloud scanning. Those capabilities belong to the cloud account scanner roadmap and will require secure provider integrations, persisted scope, credential vaulting, tenant isolation, runner controls, and a human report-publishing gate before launch.

Validated attack paths, not scanner noise

Candidate findings are reviewed against the authorized scope and available evidence. When validation is safe, the report includes reproducible evidence and business impact. When a path is blocked, theoretical, or intentionally left untested, the report labels that limit instead of converting it into an absolute security claim.

The handoff includes an owner summary, engineering evidence, remediation guidance, and retest criteria. One remediation retest can be included when it is agreed in the scope; a retest confirms only the conditions checked at that time.

Scoped for SaaS teams that need practical evidence

The live offer is designed for a bounded decision: review a defined web or API surface, explain the most important validated risks, help engineering understand the fix, and agree how remediation will be checked. Testing starts only after scope, authorization, access, safety constraints, commercial terms, and timing are confirmed.

Two one-time pilot checkouts are available: €50 for a focused review and €199 for a deeper review. The authorized scope and safety limits are still reviewed before testing. Recurring billing, automated renewals, automated change detection, and continuous testing are not offered through the website. Custom work is quoted separately.

Frequently asked questions

How much does a scoped security review cost?

The focused one-time pilot is €50 and the deeper one-time pilot is €199. The authorized scope and safety limits are reviewed before testing. Custom work is quoted separately. The website does not currently sell an automated cloud account scan or an auto-renewing subscription.

How long does an assessment take?

Timing is confirmed after scope review. It depends on the number of surfaces, authenticated roles, safety limits, access readiness, evidence depth, and whether remediation retesting is included.

Do you need credentials or agents installed in our cloud?

The current service can begin from the approved public web and API surface. Deeper cloud-adjacent evidence may use customer-provided test accounts, API keys, or scoped read access only when explicitly agreed. Automatic provider connections and account-wide discovery are roadmap capabilities, not current features.

Is the testing safe for production environments?

Scope and safety controls are set during onboarding: excluded systems, rate limits, maintenance windows, and destructive-action boundaries. Production-safety limitations are documented per finding and per report, and validation addenda cover high-risk paths that were deliberately left untested.

What does the report include?

The report includes reviewed findings, available reproduction evidence, business impact, remediation guidance, fix acceptance criteria, and labels for blocked or untested paths. A fictionalized sample report is available on this page.

Can we retest after fixing findings?

A remediation retest can be included in the written scope. It checks the agreed fix against the tested condition; it is not continuous monitoring or an automatic guarantee that every related risk is closed.