notra·
Web applications

Penetration testing for web applications

Notra attacks your live web app the way a real attacker would — over HTTP, from the outside — and returns only what it could prove. Every finding ships the exact request and response that demonstrated it. Deep Audit is $149 flat, report in about an hour.

How the run works

1 · Map

The agent crawls your app, fingerprints the stack and framework versions, and inventories the attack surface: routes, parameters, cookies, headers, exposed files.

2 · Probe

It probes each surface for auth and session flaws, injection sinks, dangerous exposed files, and known-vulnerable component versions — within a fixed, manifest-pinned request budget.

3 · Gate

Every candidate is re-attacked with a harmless proof-of-exploit. Under 0.8 confidence it never ships — you can watch the gate work live instead of trusting it.

4 · Evidence

What survives the gate ships with its exhibit: the exact HTTP request and response that proved it, plus the fix in plain English.

What the audit goes after

Auth & sessions

Cookie flags (Secure, HttpOnly, SameSite), token handling, logout behavior, and the JWT/session-chain weaknesses that let a session live longer or travel further than it should.

Injection & exposed files

Injection-class probes proven with harmless PoCs, plus read-only checks for exposed environment files, config backups, debug endpoints, and secrets accidentally shipped to production.

Components & hardening

Fingerprinted framework and library versions checked against known CVEs, plus the missing hardening — security headers, TLS posture, CORS — that turns small bugs into exploitable ones.

The honest scope line

Strong at

Known exploit classes with mechanical proofs: injection, exposed files and secrets, auth/session weaknesses, CVE-exposed components, missing hardening.

Not this

Novel multi-step business-logic chains that need human creativity. If you suspect those, a manual engagement is the right buy — Notra fits between their visits.

Not paperwork

The report is evidence you can attach to a customer review, not a signed auditor letter. If the letter is the deliverable, buy the humans.

Want to see the evidence standard before paying anything? Read a sample verified report, or start smaller: the free scorecard passively checks about 16 items in roughly a minute and tells you whether a full audit is worth the $149.

Questions people ask first

Do the probes damage my app?

No. Injection-class findings are proven with harmless proof-of-concept payloads — a benign script tag that proves the sink fires, not a payload that mutates data. Every request the agent makes carries a public abuse contact, and the run is manifest-pinned so you can see exactly what was sent.

Do I need to hand over credentials?

No. The Deep Audit ($149) runs unauthenticated — roughly 360 requests over about 60 minutes against the public surface, targeting up to 20 verified findings. If you want the logged-in surface probed too, Deep+ ($299) accepts one session cookie and runs a larger request budget over about 90 minutes.

What happens if it finds nothing?

You get an honest empty set: the surface was mapped and probed, nothing could be verified, and the report says exactly that. There is no padding with low-confidence maybes — under the 0.8 verification threshold, a candidate never ships.

Run the free scorecard. Then decide.

If the passive checks flag anything, a $149 Deep Audit turns it into verified findings with proof.

Get your free scorecard

Related: see how this stacks up against a manual pentest, the full pricing breakdown, or keep the app covered between releases with continuous monitoring.