Bluefire Redteam — VAPT Scope Questionnaire Form

Get an Accurate Quote for Your Security Assessment

Every organization is unique — and so are their security risks.
This questionnaire helps our security engineers understand your environment, attack surface, and business context so we can deliver a precise scope, realistic timelines, and a transparent fixed-price quote.

Whether you’re looking for Web App Pentesting, Mobile App Security Testing, API Security, Cloud Security Review, Network Pentest, Code Review, or Red Teaming, this form ensures we gather exactly what is needed from Day 1.

Completing this form takes 2–4 minutes and allows us to respond with a tailored proposal within 24–48 hours.

1
Basic Info
2
Select Assets
3
Asset Details
4
Review & Submit

Let's start with the basics

Tell us about your organization and testing requirements

What assets need testing?

Select all that apply — you can provide details in the next step

🌐
Web Application
📱
Mobile App
🔌
API Testing
☁️
Cloud Infrastructure
🌍
External Network
🏢
Internal Network
💻
Code Review (SAST)
🎯
Red Team Exercise
🔒
Physical Security
📋
Other

Asset details

Provide specific information about your selected assets

Almost done!

Review your information and provide final details

📄 Legal & Compliance
Specify any activities that should be avoided during testing

Frequently Asked Questions (FAQ) - Pentest Scope Questionnaire

  • A Pentest Scope Questionnaire is a structured set of questions that helps us understand your application, infrastructure, and testing needs in detail.
    It ensures we clearly know:

    • What assets are in scope

    • How complex the systems are

    • What environments we will test

    • What level of authentication or access is required

    • Any compliance or business constraints

    This questionnaire allows us to provide an accurate quote, avoid misunderstandings, and tailor the assessment to your real-world use case.

  • Every application or environment is different. The questionnaire helps us:

    • Provide an exact price (not guesswork)
    • Determine whether black-box, grey-box, or white-box testing is appropriate
    • Understand technologies, roles, sensitive flows, and critical assets
    • Avoid delays later by gathering details upfront
    • Ensure we don’t miss anything important in your threat surface

    The more accurate the details, the better and faster the proposal.

  • Typically 24–48 hours.
    If you choose the “urgent” option or write it in the form, we can send you a quote the same day.
  • No problem.
    Fill what you can — our team will ask follow-up questions only if needed.
    Even incomplete data still gives us enough direction for initial scoping.
  • Yes.
    We follow strict internal security policies:

    • NDA available on request before sharing anything

    • Information stored securely

    • Shared only within the Bluefire Redteam security team

    • Automatically purged after the engagement if you choose so

    We treat client data with the same protection as our own.

  • You can include:

    You can mix-and-match multiple assets — the questionnaire dynamically adjusts to show relevant questions.

  • Not at all.
    This is purely for scoping and early discussion.
    There is no cost and no obligation until you approve the final quote.
  • Yes — we provide complimentary retesting and update the report accordingly.
  • Depending on scope:

    • Web app/API: 5–12 days

    • Mobile app: 7–14 days

    • Cloud review: 5–10 days

    • Red Team: 2–4 weeks

    • Full multi-asset pentest: varies

    We’ll outline everything clearly in your proposal.