Authorised assessment

Named public systems. Written authorisation first.

No qualifying finding, no fee.

Default severity tariff, USD. Binds only when signed.
Severity Fee
Info$0
Low$500
Medium$1,500
High$4,000
Critical$10,000
Assessment cap$15,000

Redifact assesses public-facing websites, applications, APIs, and internet-facing infrastructure that you name in a signed scope. Work is remote and non-destructive.

Nothing is tested until both parties sign the scope, the rules, and a maximum invoice.

Not billed

A verified finding is charged. The rest is not.

Each verified finding is billed at its severity band. The cap is per assessment, not per finding. These items are recorded when useful. They are never charged.

  • Unverified scanner output
  • Version banners
  • Duplicate findings
  • Issues outside the signed scope
  • Best-practice notes with no attack path
  • Self-XSS
  • Missing headers without an attack path
  • Issues that need destructive tests to prove

Read the full fee rules

One product

For agencies, MSPs, IT providers, and founders.

Redifact does one kind of work: an authorised assessment of the public systems you name. There is no menu of extra services on this site. If the asset is not in the signed scope, it is not tested.