We define scope together during a kick-off call, covering target URLs, APIs, IP ranges, and any exclusions specific to your environment.
Yes, we offer both methodologies and recommend the best approach based on your application type and compliance requirements.
All packages include one complimentary re-test within 30 days so you can validate that vulnerabilities have been resolved.