Viewee
Start free
Pricing
Sign in
← Legal and assurance

16 September 2026

Bottom line

Commission one grey-box penetration test of the production-like admin app and the first production-ready API before any real resident/family/staff feedback enters a pilot. Ask for unauthenticated and authenticated testing across every role, tenant isolation and business-logic abuse, with one included retest and a customer-shareable executive summary. For a compact early-stage product, budget £4,000-£10,000 + VAT as a planning range, then obtain three fixed-price quotes. Precursor, Cognisys and Cyndicate Labs are the strongest first quote set; all have current CREST directory evidence, while the shortlist spans smaller specialists through larger assurance firms.

Status key

Verified = directly supported by CREST, NCSC or the provider’s current site. Estimated = planning assumption based on published vendor rates and common engagement shapes; confirm in a written quote.

  1. Precursor Security - smaller offensive-security specialist and the clearest public pricing signal. CREST lists penetration-testing accreditation. Its site explicitly covers web apps/APIs and publishes web-app testing from £3,750 and an approximate £1,200 consultant-day benchmark. Best first call for a bounded startup scope. Verified except final Viewee price.

  2. Cognisys Group - specialist/mid-tier option. CREST lists penetration testing; its official pages cover web applications and REST, GraphQL, SOAP and gRPC APIs, with manual OWASP API Top 10 testing. Strong fit if the API will be in scope at the same time. Verified.

  3. Cyndicate Labs - boutique offensive-security team. CREST lists penetration testing and its site positions the firm around penetration testing, threat simulation and specialist security work. Ask specifically for recent multi-tenant SaaS and care/health data examples. Verified capabilities; SaaS-sector depth to confirm.

  4. Closed Door Security - smaller UK option. CREST lists penetration testing; its site offers penetration testing and security assessments. Potentially better access to senior testers than a large consultancy. Confirm dedicated web/API experience, report sample and retest terms. Verified capabilities; fit details to confirm.

  5. Pen Test Partners - established specialist with broad technical depth. CREST lists penetration testing and its site covers application/security testing across many sectors. Good comparator where unusual attack paths or deeper business logic matter, though likely less price-led than boutiques. Verified.

  6. Blaze Information Security - specialist offensive-security firm. CREST lists penetration testing; the provider explicitly combines web application and API penetration testing and stresses manual testing beyond OWASP Top 10. Good SaaS-shaped alternative; confirm UK delivery team and data-handling location. Verified.

  7. Bridewell - larger cyber consultancy. CREST lists penetration testing; Bridewell’s web-application service explicitly includes APIs. Useful if Viewee may later want cloud, compliance or managed-security work under one supplier. May be heavier than the first pilot needs. Verified.

  8. NCC Group - large established provider. CREST lists penetration testing; its UK Digital Marketplace service covers web services/APIs through penetration testing, source-code review or threat modelling. Strong enterprise-recognition option, but likely higher process and cost overhead. Verified.

What to buy now

In scope:

Usually separate or optional:

The Astro marketing site should not consume much manual time unless it has forms, authentication, previews, server functions or integrations. Ask bidders to separate a light external exposure check from the app/API effort.

Cost: planning range

Estimated for Viewee: £4,000-£10,000 + VAT for roughly 5-8 consultant days across one modest app, several roles and a compact API, including reporting and one bounded retest. A very small app with few endpoints and two roles might quote near £3,000-£5,000. A larger API, many workflows/roles, complicated tenant logic or cloud review can push the total to £8,000-£15,000+.

Evidence behind the estimate: Precursor publishes web-app testing from £3,750, overall testing from £2,500 and about £1,200 per CREST-accredited consultant day. EJN Labs publishes a £5,000 starting point for a small web app and an API heuristic of roughly 25-30 endpoints per day, with small API estimates of £2,400-£3,600. These are vendor-authored 2026 price signals, not neutral tariffs. Most CREST firms quote after scoping. Do not pick the cheapest quote unless it names manual authenticated testing, roles, endpoints, business logic, report and retest.

Optional-cost effects:

Timeline

Estimated practical plan:

Allow 4-8 elapsed weeks from first outreach to closed retest. Ask for retest validity, included days and scheduling terms in the quote; “free retest” often has limits.

When Viewee should test

Before the resident-data pilot: test after the app/API is production-like and major flows are stable, but before any real resident, family or staff feedback is loaded. Fix all critical/high findings and retest them before go-live. Do not test too early against a disposable architecture.

Before general availability: do a targeted delta test if authentication, roles, tenancy, APIs, hosting, exports or major workflows changed after the pilot test. If changes were minor and the provider confirms coverage remains representative, retain the pilot report and commission a shorter focused test rather than automatically repeating everything.

After launch: annual full external testing is a sensible baseline, plus targeted testing after material security-relevant changes. Examples: new API surface, authentication/SSO, role or tenant model, file handling, new cloud architecture, major data export/import, acquisition/integration or a serious incident. Continuous scanning and dependency/secret checks should run between tests. NCSC warns a penetration test only reflects the systems and known issues at the time of the test; it is assurance, not the primary vulnerability-management process.

Ready-to-adapt scoping brief

Subject: Request for quote - Viewee web application and API penetration test

Company and purpose

Viewee is an early-stage UK SaaS platform for adult social care providers. It collects feedback from residents, families and staff and turns it into themes, owned actions and evidence of change. We want independent security assurance before a pilot uses real feedback data.

Target timing

Preferred test window: [dates]. Target pilot date: [date]. We need the final report and retest closure by [date].

Environment

Users and workflows

Please test unauthenticated access and these roles: [platform admin], [provider admin/manager], [staff], [read-only/reviewer], [other]. Key workflows are invitations/login/reset, feedback capture/import, viewing and editing feedback, themes, actions, evidence/change history, file handling, search, reporting and export. The platform is multi-tenant; cross-tenant and cross-role access is a priority.

Requested scope

Rules and exclusions

Deliverables

Please include in the quote

  1. CREST company accreditation and proposed tester qualifications.

  2. Named assumptions: application size, roles, workflows and API endpoints.

  3. Consultant days, fixed price excluding/including VAT, earliest dates and report turnaround.

  4. Exactly what is excluded, and prices for optional cloud configuration review and source-code review.

  5. Retest allowance, deadline and cost if the allowance is exceeded.

  6. Example redacted report and two relevant SaaS references/case studies, ideally multi-tenant and sensitive-data products.

  7. Professional indemnity/cyber insurance, data location/retention, subcontractors and NDA terms.

Quote evaluation scorecard

Send the brief to Precursor, Cognisys and Cyndicate Labs first. Add Pen Test Partners or Bridewell as a larger-firm comparator. Give each the same 30-minute product walkthrough and request fixed-price quotes against identical targets, roles and endpoint counts. Choose on scope and tester quality, not badge or price alone.

Sources