Self-Managed Atlassian
Approved Pentesting

CREST-accredited testing for Marketplace partners. Fixed price, reports written to Atlassian’s template, free retest.

CREST accredited: Penetration Testing CREST accredited: Vulnerability Assessment CREST accredited: App Security Testing CREST accredited: Mobile App Security Testing

Trusted by Atlassian partners

Self-Managed Atlassian App
Penetration Testing

Three Atlassian policies decide how you buy a pentest. We are built for all three.

01

Enterprise Certified · 1.1

“Evidence that a current annual penetration test has been completed.”

Accepted from Atlassian’s Bugcrowd program or a CREST-accredited vendor. A bug bounty alone does not satisfy it.

Read the requirement
02

Marketplace Pentest Program

“You must use a CREST Accredited testing vendor.”

Your report goes to Atlassian via an ECOHELP ticket. We write it to drop straight into that flow.

Program page
03

Security Bug Fix Policy

Critical in 10 days. High in 4 weeks.

A missed Critical hides your app. We flag Criticals within 24 hours and retest your fix free, inside the window.

Policy

Pricing for Fellow Atlassians

Discounted pricing for every Atlassian Marketplace partner. Priced per application by endpoint count, and fixed after a 15-minute scope call.

Under 20 endpoints

$2,500

  • Per application
  • Flat discounted price, limited time
  • Free retest, attestation letter
Book a scope call

Under 40 endpoints

$4,500

  • Per application
  • Report to Atlassian’s template
  • Free retest, attestation letter
Book a scope call

Under 60 endpoints

$6,000

  • Per application
  • Report to Atlassian’s template
  • Free retest, attestation letter
Book a scope call

Every tier includes

  • Manual testing by CREST-accredited engineers, with our AI Pentest Agent covering the breadth
  • Scope and report written to Atlassian’s penetration test scoping template
  • Findings CVSS-scored and Jira-ready, with reproduction steps and the fix
  • Criticals flagged within 24 hours, not at the end of the engagement
  • Free retest of every fix, inside Atlassian’s Bug Fix Policy window
  • Clean health report and signed attestation letter for your enterprise customers
  • Report formatted to attach to your ECOHELP ticket and your SOC 2 or ISO 27001 audit file
  • Professional liability cover and Koop cyber insurance on every engagement

ECOHELP Tickets in Two Weeks

From scope call to submitted report, with Atlassian’s steps built in.

  1. 1

    Scope

    Fifteen minutes with Usama.

    Endpoint count, Forge or Connect, the badge you are chasing and your deadline. You leave the call with a fixed price and a start date.

    Fixed quote on the call
  2. 2

    Test

    Four to five working days.

    The AI Pentest Agent maps your app and its APIs at speed. Accredited engineers then exploit, chain and validate what it finds, so you get real attack paths, not scanner noise.

    Criticals flagged in 24h
  3. 3

    Fix

    Jira-ready, timed to Atlassian’s clocks.

    Each finding arrives CVSS-scored with reproduction steps and the fix your engineers need, ordered by Atlassian’s windows: Critical 10 days, High 4 weeks.

    Help on the fix included
  4. 4

    Submit

    Retest, clean report, attestation.

    We re-run every exploit to confirm it is closed, then issue the clean health report and attestation letter. Attach it to your ECOHELP ticket and move on.

    Free retest

Tired of “contact sales”?

The price is on this page. The call is for scoping, not for a quote.

Book a call

The questions partners ask on the scope call.

Does Atlassian accept a CyberFortify pentest?

Atlassian’s Enterprise Certified requirement 1.1 accepts a current annual penetration test from its Bugcrowd program or from a CREST-accredited vendor, and its self-managed pentest route requires a CREST-accredited vendor. CyberFortify is a CREST member company accredited for Penetration Testing and AI-Enabled Penetration Testing; the listing is on the CREST Marketplace. Atlassian reviews each report through an ECOHELP ticket, which is why we write to their scoping template.

We already have a bug bounty. Do we still need this?

For Enterprise Certified, yes. Requirement 1.1 is the pentest and requirement 1.2 is the bug bounty program; they are listed separately, not as alternatives. A pentest also gives you a dated report and an attestation letter that enterprise procurement teams ask for, which a bounty cannot.

Forge or Connect, does it matter?

We test both. A Connect app’s scope includes your hosted backend, its iframe integration and the JWT handling; a Forge app’s scope centres on resolvers, storage, egress permissions and Custom UI. Tell us which on the scope call and the endpoint count follows.

What counts as an endpoint?

One distinct API route, page or function in scope. Most single-product Marketplace apps land under 20, which is the $2,500 tier. We confirm the count together on the scope call and the price is fixed from then on.

How fast can you start, and how fast is the report?

Scheduling is usually within a week of the scope call. Testing for most apps takes about a week. Criticals are flagged within 24 hours of discovery rather than held for the final report.

What happens if you find a Critical?

You hear about it within 24 hours with reproduction steps and a recommended fix. Atlassian’s Security Bug Fix Policy gives you 10 days for a Critical and 4 weeks for a High once it is filed, so we help with the fix and retest it free inside that window.

Can the same report serve our SOC 2 or ISO 27001 audit?

Yes. Findings are mapped to the relevant controls and the clean health report plus attestation goes into your audit file as the independent penetration test evidence. Gold and Platinum Marketplace partners who need SOC 2 Type 2 or ISO 27001 anyway get both uses from one engagement.

Who actually does the testing?

CREST-accredited engineers led by Usama Gul, CyberFortify’s founder, who is also your first call. Our AI Pentest Agent handles breadth; every finding is validated and exploited by a human before it reaches your report.

Is the engagement insured?

Every assignment is covered by professional liability insurance and cyber-insured through Koop. Our ISO 27001 and ISO 9001 certificates are available on request.

Your badge deadline doesn’t move.
Neither does our price.

Your first call is with Usama Gul, the founder and the engineer who leads your test. You’ll leave with a clear scope and a fixed price.