Vulnerability assessment and penetration testing
VAPT services for websites and web apps, done by hand.
VAPT means vulnerability assessment and penetration testing. A real security expert tests your site, then sends you a full written report with exact fixes. Fixed price from $49, paid once in US dollars.
What VAPT means: assessment plus penetration testing
The two halves answer two different questions. A vulnerability assessment asks “what could be wrong?” Penetration testing asks “what can an attacker actually do with it?” Doing only one leaves a gap.
| Vulnerability assessment | Penetration testing | |
|---|---|---|
| Question it answers | What weak points exist? | Which of them can really be used, and how badly? |
| How it works | Wide and fast. Tools map the site and flag known problems. | Deep and hands-on. A person acts like an attacker. |
| Risk if used alone | A long list with false alarms and no sense of what matters. | Strong on the paths tested, but can miss the wider surface. |
Together they give you both. At Bug Circuit, tools only map the surface. A person does the testing, and every finding in your report is confirmed by that person, so you do not get a pile of scanner noise.
VAPT testing for a website or web app: what we cover
- Login and sessions: password rules, password reset, and how sign-in is kept safe.
- Access control: can one user see another user’s data, or reach an admin page?
- Injection and input handling: SQL injection and cross-site scripting in forms and links.
- Business logic: checkout, coupons, roles and flows that scanners do not understand.
- Exposed files and settings: backups, admin panels, debug pages and open services.
- Security headers and HTTPS: the browser protections that should be switched on.
VAPT is often split by target: websites, APIs, mobile apps, networks and cloud. Our fixed-price plans are for websites and web apps. Here is how they map to VAPT:
- Circuit, $49 once: a real security expert manually audits one website and delivers the full report. For most customers this is the whole VAPT. Start with Circuit.
- Signal, $299 for 3 months: everything in Circuit, plus we fix the high and critical issues with you, re-test them, and keep watch as you ship changes. Also $335 for 6 months or $407 for 12 months. Start with Signal.
What is in a VAPT report
- Executive summary in plain English that you can forward to a manager or a customer.
- Methodology: what was tested and how.
- Every finding with a severity (Critical, High, Medium, Low or Info), the evidence, why it matters, and the exact steps to fix it.
- Remediation roadmap: a prioritised list so your developers know what to do first.
A report describes your site on the days it was tested. It is not a promise that nothing can go wrong later. See the real format in our sample VAPT report.
VAPT cost: market prices and our fixed prices
VAPT cost depends on the scope and on who does the work. Traditional penetration tests often cost $5,000 to $20,000 or more. Experienced manual testers bill roughly $900 to $2,200 per day. Free scanners cost nothing, but they miss logic and access-control flaws, so they are a first step, not a full VAPT.
| Option | Typical cost | What to expect |
|---|---|---|
| Free scanner | $0 | A fast list of known issues. Misses logic and access-control flaws. |
| Traditional firm | $5,000 to $20,000 or more | A formal engagement, often with scoping calls first. |
| Experienced tester by the day | About $900 to $2,200 per day | Skilled manual work. The total depends on days and scope. |
| Bug Circuit, Circuit plan | $49 once | Manual audit of one website with a full written report. |
| Bug Circuit, Signal plan | $299 for 3 months | Audit, fixes, re-testing and cover. |
Prices are fixed, in US dollars, paid once through Stripe, with no subscription. There is a 14-day money-back guarantee if testing has not started (see refunds). Want to compare for your own site? Try the pentest cost calculator or see pricing.
Who usually asks for a VAPT report
A VAPT report is often requested by:
- Customers who want proof before they sign or renew.
- Partners who connect their systems to yours.
- Investors doing due diligence.
- Regulators and auditors.
- Banks and enterprise procurement teams with a security questionnaire.
Bug Circuit is not a PCI-DSS QSA, not a HIPAA auditor, and does not issue compliance certificates. Our manual audit is supporting evidence. If a request names a specific certificate or an accredited firm, read the wording first and ask us if you are unsure.
How VAPT testing works at Bug Circuit
- 1
Verify your domain
Prove you own the site with an email code, a DNS TXT record, a file or a meta tag.
- 2
Authorize the test
You give a recorded Authorization to Test. We only test sites you own or may test.
- 3
Manual testing
A person tests your site by hand. Tools only map the surface, and a person confirms every finding.
- 4
Report and fixes
Your report usually arrives within about 5 business days. On Signal we fix the high and critical issues with you and re-test.
VAPT for several sites, apps or APIs
Many buyers in South Asia, the Middle East and Southeast Asia call this service VAPT. Bug Circuit is run from Sri Lanka and works with customers worldwide, fully online. If you need VAPT across several websites, apps or APIs, go to Enterprise. It is one scoped engagement with a custom fixed quote in USD, fixes, up to 12 months of cover and a dedicated security lead. You can read the Authorization to Test before you start.
Frequently asked questions
What is VAPT?
How much does VAPT cost?
How long does VAPT take?
What is the difference between VAPT and penetration testing?
How often should you do VAPT?
Can VAPT be done remotely?
Do I get a VAPT certificate?
Keep reading
Start with a free scan, then get your VAPT
Run the free passive check first. When you are ready, a full manual VAPT starts at $49.
Ready for the full manual audit? See pricing