Skip to main content
Back to Cantina

Web2 security

Scope your Web2 security review

Tell us about your application, infrastructure, and timeline. We’ll use your answers to shape the right security engagement.

Contact information

Engagement context

What business requirement is driving the test—for example, compliance, a customer request, or strengthening your security posture?

What is the worst-case business impact of a breach or hack?

Testing approach

Choose the level of information sharing you expect during testing.

Application scope

Can testing take place during normal business hours?

How many user roles are in scope, and what are they?

Approximate the pages and application functions in scope.

Include the approximate number, API types, and representative examples.

Describe whether the application is a single-page application, traditional request/response application, or another architecture.

List any cloud-native services used by the application.

Include the frontend, backend, databases, and other important technologies.

List all in-scope endpoints, URLs, and IP addresses.

Authentication

Will the test use authenticated access?

Application demo

Can your team demonstrate the application to the researchers?