$ pentest --target your-site.com --mode real

We attack your site before real hackers do.

Manual penetration testing by an expert with 15 years in IT and cybersecurity. Fixed price up front, a readable report in 5 days, and a free re-test once you've fixed what we found.

Brand operated by KaliCertif SAS · 15 years of IT and cybersecurity expertise · Data hosted in France

Packages

  • Essential, 990 € excl. VAT. Showcase site or e-commerce, black box. 2 days of manual testing, report prioritised by severity, 30-min debrief call.
  • Application, 2 490 € excl. VAT. Web app or SaaS with user accounts, grey box. 5 days of manual testing, free re-test, attestation you can show your clients.
  • Complete, 4 900 € excl. VAT. App, API and exposed infrastructure. 10 days of manual testing, video call walkthrough, prioritised remediation plan, 30-day follow-up.
  • Ready For Prod, 490 €. Pre-production security validation of an app built with AI (Cursor, Claude, Lovable, v0, Bolt.new). Free re-check after 7 days.

How it works

  1. Scoping and authorisation. A 30-min call to define the scope, then you sign a scan authorisation (mandatory and legally required). We can start the same day.
  2. Manual attack. We test your site the way a real attacker would: manual intrusion assisted by AI, going far beyond automated scanners.
  3. Clear report. For every vulnerability: what it is, where it is, how to exploit it, how to fix it, and in what order. Readable by a human, not just an expert.
  4. Re-test and attestation. Once you've applied the fixes, we verify everything is in order (included free with Application and Complete) and hand you an attestation.

Your expert

Mehdi, founder. 15 years in IT and cybersecurity. Client list kept confidential, experienced with sensitive sectors (law firms, accountants, healthcare).

Our manual tests are AI-assisted. Our organisation is approved through Anthropic's verification program for offensive cybersecurity use cases (pentesting, red teaming).

FAQ

Is it legal to attack my site like this?
Yes, as long as you authorise us to. Before any test, you sign a scan authorisation (takes 5 minutes). Without it, we do nothing. That's what protects both you and us.

Could the test break my site?
No. We use controlled techniques and, with 15 years of experience, have broken zero sites to date. On a sensitive site, we schedule the tests overnight.

Will my information stay confidential?
Yes. Our client list is private, and we publish nothing without your written consent. We're used to working with sensitive practices (law firms, accountants, healthcare).

How long does it take?
Once you've ordered and the authorisation is signed: a report in 5 business days for Essential and Application, 10 days for Complete.

How does payment work?
A fixed price shown up front, no endless quoting. You order and pay directly online by card via Stripe. Pentest prices are shown excluding VAT; applicable VAT is added at checkout. Invoiced by KaliCertif SAS.

Do you use AI to test?
Yes. Our manual tests are AI-assisted. Our organisation is approved through Anthropic's verification program for offensive cybersecurity use cases (pentesting, red teaming). Every report is still manually reviewed.

Contact

Want to book a slot this week? Email us at bonjour@kalisecu.fr.