Is this just an automated scan?
No. Suitable tools support the assessment, while manual validation helps establish which findings are credible and what they mean. Deeper business-logic and access-control testing belongs in the agreed pentest scope.
Can you test a live production website?
The environment and techniques are agreed before work begins. Production testing uses the approved limits and stop conditions. A suitable staging environment may be preferred for checks that change application state.
Do I need to provide user accounts?
External assessments do not include login coverage. Authenticated testing requires agreed test accounts, roles, and test data; same-role accounts help validate access boundaries between users.
What determines the price?
The application size, covered workflows, APIs, user roles, integrations, environment, and required testing depth. A quote follows scoping; there is no universal price per website.
How is evidence handled?
Evidence is minimized, redacted, and transferred securely. Unless otherwise agreed, retained evidence is deleted 30 days after the retest window closes or the included retest is completed, whichever is later.
Does this certify compliance?
No. The launch service provides a scoped security assessment and remediation guidance. It does not issue compliance certification or promise an application is completely secure.