Skip to main content

§ masterplan.md

Penetration Testing Service

A dark-premium cybersecurity service site with service tiers, methodology and a vulnerability report sample.

All ideas
Dark Premium

01

App overview and objectives

A service site for a security testing firm that sells trust: methodology in the open, a redacted sample report, transparent scoping and pricing, and a fast path to a scoping call.

02

The problem worth solving

Buyers of security testing cannot evaluate quality before purchase, so they fall back on price. Publishing the method and a real sample report converts scepticism into a booked call.

03

Target audience

  • Primary — CTOs and engineering leads at small and mid-size companies buying their first or annual test.
  • Secondary — Compliance officers needing evidence for certification.

04

Roles and permissions

  • Visitor — read-only public pages, can sign up.
  • Member — owns their own records, cannot see other users' data.

05

Core features

  • Service pages by test type: web app, mobile, network, cloud configuration
  • Methodology page mapped to recognised standards
  • Redacted sample report download behind a light email gate
  • Scoping questionnaire that produces an indicative price band
  • Case studies with permission and anonymisation
  • Booking flow for a scoping call with calendar integration

Deliberately later

  • Client portal for live findings
  • Retest scheduling
  • Continuous monitoring subscription

06

Technical stack

Static-rendered marketing site, one server function for the questionnaire, a scheduling integration.

Why: The site is a trust document — speed, uptime and clean security headers matter more than any dynamic feature.

Alternatives: A page builder (fast, poor security posture and headers) or a full client portal from day one (valuable later, distracting at launch).

07

Conceptual data model

Service — type, scope description, deliverables, duration band

Lead — company, contact, scope answers, indicative band, status

CaseStudy — sector, scope, findings summary, outcome, permission record

ReportRequest — email, sent_at, follow-up status

08

Integrations

  • Calendar scheduling
  • CRM or email pipeline
  • Email delivery

09

UI design principles

  • Deep neutral background, one saturated accent, thin borders instead of heavy cards.
  • Monospace for data and code; tight, technical spacing.
  • Subtle glow and gradient only where you want the eye to land.

10

Security considerations

  • The firm's own site must be exemplary: strict headers, no third-party scripts, published security.txt.
  • Lead data encrypted and access-limited; scoping answers can describe sensitive infrastructure.
  • Case studies require written client permission recorded in the system.

11

Development phases

Phase 1 — Prove the core

  • — Service pages by test type: web app, mobile, network, cloud configuration
  • — Methodology page mapped to recognised standards
  • — Redacted sample report download behind a light email gate
  • — Static content and design system in place
  • — Basic analytics

Phase 2 — Make it real

  • — Scoping questionnaire that produces an indicative price band
  • — Case studies with permission and anonymisation
  • — Booking flow for a scoping call with calendar integration
  • — Accounts, sign-in and password reset
  • — Empty, loading and error states everywhere

Phase 3 — Polish and launch

  • — Performance, accessibility and SEO pass
  • — Legal pages, contact route and 404 handling
  • — Wire up: Calendar scheduling
  • — Wire up: CRM or email pipeline

Phase 4 — Grow

  • — Client portal for live findings
  • — Retest scheduling
  • — Continuous monitoring subscription

12

Challenges and solutions

Risk — Buyers cannot compare vendors

Solution — A comparison page explaining what to demand from any vendor, including competitors.

Risk — Lead quality is low

Solution — Scoping questionnaire filters out projects below minimum engagement size before a call is booked.

Risk — Confidentiality limits marketing

Solution — Sector-level anonymised case studies and a strong sample report instead of named logos.

13

Future expansion

  • Training workshops
  • Managed vulnerability disclosure programmes
  • Partner channel for agencies

14

Page list (12 pages)

  1. 01 PUBLIC Services — What can be tested and what you receive.
  2. 02 PUBLIC Methodology — How tests are run, mapped to standards.
  3. 03 PUBLIC Pricing — Bands and the scoping questionnaire.
  4. 04 PUBLIC Report Sample — A real, redacted deliverable.
  5. 05 PUBLIC Contact — Book a scoping call.
  6. 06 AUTH Sign up — Create an account with email or a social provider.
  7. 07 AUTH Log in — Return to the account, with error and lockout states.
  8. 08 AUTH Reset password — Request a reset link and set a new password.
  9. 09 APP (signed in) Account settings — Profile, email, password, language and delete account.
  10. 10 LEGAL & SYSTEM Privacy policy — What data is collected, why, and how to remove it.
  11. 11 LEGAL & SYSTEM Terms of service — Rules of use, liability and account termination.
  12. 12 LEGAL & SYSTEM 404 not found — Friendly dead end with search and links back.

15

Page map

PUBLIC            AUTH               APP (signed in)      LEGAL & SYSTEM
────────────────  ─────────────────  ───────────────────  ───────────────────
├─ Services       ├─ Sign up         └─ Account settings  ├─ Privacy policy
├─ Methodology    ├─ Log in                               ├─ Terms of service
├─ Pricing        └─ Reset password                       └─ 404 not found
├─ Report Sample
└─ Contact

key flows:
  Services ──▶ Pricing
  Methodology ──▶ Report Sample
  Pricing ──▶ Contact
  Report Sample ──▶ Contact