Only real findings
A person checks every result before release. Anything we could not prove stays clearly labeled.
// SKYEN — WEB & API SECURITY
SKYEN checks one agreed web application or API at a time. Scope and timing are confirmed by a person. You receive a human-reviewed report with evidence, business impact, practical fixes, and one scoped retest. One fully executed agreement may cover multiple named and scheduled assessments.
Preparing a test? Read the cloud pentest checklist for SaaS teams, how automated vulnerability assessment compares to a manual pentest, and how to evaluate an AI security testing provider.
// CLEAR SECURITY RESULTS
A person checks every result before release. Anything we could not prove stays clearly labeled.
The report explains what happened, why it matters, and which practical fix fits.
The retest criteria are clear, so your team can request the agreed scoped retest after the fix.
SKYEN starts at €500 per month excluding VAT. That includes one bounded web or API assessment per agreed month, a human-reviewed report, practical fix guidance, one agreed retest, and a closure memo. Multiple named and scheduled assessments may be covered by one fully executed agreement. Larger scopes are quoted separately.
SKYEN is Loki's current web and API evidence plan, starting at €500 per month excluding VAT. Each month covers one bounded assessment of one company-controlled, internet-facing web application or API. One fully executed agreement may authorize all assessments it expressly names and schedules. Up to two supplied roles or test accounts can be included. Larger or more complex scopes are quoted.
Work starts after the applicable signed agreement covers the target, schedule, scope, access, testing rules, exclusions, rate limits, data terms, and stop contact. Delivery is usually about 10 business days from that point. Each execution is internally bound to a covered assessment, and every finding and report is reviewed by a human before publication.
A human reviews each possible finding against the agreed scope and the evidence. When it is safe and allowed, the report shows a reproducible attack path and its business impact. Blocked, unproven, and untested paths stay clearly labelled.
The coverage record names the in-scope hosts and routes, supplied roles or accounts, authentication states, agreed test categories, exclusions, blocked areas, and test window. Each finding records its human-review status, preconditions, redacted request and response, exact reproduction steps, observed result, expected control, impact, and acceptance criteria.
You receive a short owner summary, detailed evidence for engineers, practical remediation guidance, one scoped retest, and a closure memo. A retest passes when the stated attack path no longer reproduces and the expected control behaves as recorded; it confirms only that fix under the conditions checked at that time.
SKYEN starts at €500 per month excluding VAT. Larger or more complex scopes are quoted. Requests start with a scope conversation; quote, order, invoice, and payment are handled separately.
The signed agreement names and schedules the target, scope, rules, timing, and written authorization for every covered assessment. One agreement may cover multiple planned monthly assessments; no separate per-assessment signature, Work Order, or human execution release is required. After the work, a human reviews and releases the report. A monthly plan by itself does not authorize unattended testing.
The target is about 10 business days after the signed scope, access, Rules of Engagement, stop contact, and data terms are complete. Timing can change with the size of the surface, the number of roles, safety limits, access readiness, and current capacity. There is no public first-response or capacity SLA; actual timing is confirmed manually.
Yes. SKYEN can start from the agreed public web or API surface, and up to two supplied test roles or accounts can be included when they are part of the written scope.
Before work starts, we agree exclusions, rate limits, safe-test rules, a test window, a cost ceiling, and a stop contact. High-risk actions can be excluded or left untested, and those limits are shown in the report.
The report includes the agreed scope and limits, the surface reviewed, human-validated findings, reproducible evidence where safe, business impact, practical fixes, retest criteria, and clear labels for blocked or untested paths.
There is no public default on this page. The written quote or agreement confirms duration, cancellation, and any renewal terms before acceptance. A request does not create or renew a subscription. One fully executed agreement may authorize every bounded assessment it expressly names and schedules; anything outside that signed envelope needs a signed amendment or new agreement.
A one-off or agency request can be considered, but it has no public fixed price and exists only after a separate written quote and order are accepted. For agency work, the target owner must also provide written authorization.
Quote, legal entity, VAT treatment, invoice, and payment are handled manually. International VAT or reverse-charge treatment is confirmed from the buyer's legal and VAT details in the written quote or order; this page does not assume a tax treatment.