§ masterplan.md
Penetration Testing Service
A dark-premium cybersecurity service site with service tiers, methodology and a vulnerability report sample.
01
App overview and objectives
A service site for a security testing firm that sells trust: methodology in the open, a redacted sample report, transparent scoping and pricing, and a fast path to a scoping call.
02
The problem worth solving
Buyers of security testing cannot evaluate quality before purchase, so they fall back on price. Publishing the method and a real sample report converts scepticism into a booked call.
03
Target audience
- Primary — CTOs and engineering leads at small and mid-size companies buying their first or annual test.
- Secondary — Compliance officers needing evidence for certification.
04
Roles and permissions
- Visitor — read-only public pages, can sign up.
- Member — owns their own records, cannot see other users' data.
05
Core features
- Service pages by test type: web app, mobile, network, cloud configuration
- Methodology page mapped to recognised standards
- Redacted sample report download behind a light email gate
- Scoping questionnaire that produces an indicative price band
- Case studies with permission and anonymisation
- Booking flow for a scoping call with calendar integration
Deliberately later
- Client portal for live findings
- Retest scheduling
- Continuous monitoring subscription
06
Technical stack
Static-rendered marketing site, one server function for the questionnaire, a scheduling integration.
Why: The site is a trust document — speed, uptime and clean security headers matter more than any dynamic feature.
Alternatives: A page builder (fast, poor security posture and headers) or a full client portal from day one (valuable later, distracting at launch).
07
Conceptual data model
Service — type, scope description, deliverables, duration band
Lead — company, contact, scope answers, indicative band, status
CaseStudy — sector, scope, findings summary, outcome, permission record
ReportRequest — email, sent_at, follow-up status
08
Integrations
- Calendar scheduling
- CRM or email pipeline
- Email delivery
09
UI design principles
- Deep neutral background, one saturated accent, thin borders instead of heavy cards.
- Monospace for data and code; tight, technical spacing.
- Subtle glow and gradient only where you want the eye to land.
10
Security considerations
- The firm's own site must be exemplary: strict headers, no third-party scripts, published security.txt.
- Lead data encrypted and access-limited; scoping answers can describe sensitive infrastructure.
- Case studies require written client permission recorded in the system.
11
Development phases
Phase 1 — Prove the core
- — Service pages by test type: web app, mobile, network, cloud configuration
- — Methodology page mapped to recognised standards
- — Redacted sample report download behind a light email gate
- — Static content and design system in place
- — Basic analytics
Phase 2 — Make it real
- — Scoping questionnaire that produces an indicative price band
- — Case studies with permission and anonymisation
- — Booking flow for a scoping call with calendar integration
- — Accounts, sign-in and password reset
- — Empty, loading and error states everywhere
Phase 3 — Polish and launch
- — Performance, accessibility and SEO pass
- — Legal pages, contact route and 404 handling
- — Wire up: Calendar scheduling
- — Wire up: CRM or email pipeline
Phase 4 — Grow
- — Client portal for live findings
- — Retest scheduling
- — Continuous monitoring subscription
12
Challenges and solutions
Risk — Buyers cannot compare vendors
Solution — A comparison page explaining what to demand from any vendor, including competitors.
Risk — Lead quality is low
Solution — Scoping questionnaire filters out projects below minimum engagement size before a call is booked.
Risk — Confidentiality limits marketing
Solution — Sector-level anonymised case studies and a strong sample report instead of named logos.
13
Future expansion
- Training workshops
- Managed vulnerability disclosure programmes
- Partner channel for agencies
14
Page list (12 pages)
- 01 PUBLIC Services — What can be tested and what you receive.
- 02 PUBLIC Methodology — How tests are run, mapped to standards.
- 03 PUBLIC Pricing — Bands and the scoping questionnaire.
- 04 PUBLIC Report Sample — A real, redacted deliverable.
- 05 PUBLIC Contact — Book a scoping call.
- 06 AUTH Sign up — Create an account with email or a social provider.
- 07 AUTH Log in — Return to the account, with error and lockout states.
- 08 AUTH Reset password — Request a reset link and set a new password.
- 09 APP (signed in) Account settings — Profile, email, password, language and delete account.
- 10 LEGAL & SYSTEM Privacy policy — What data is collected, why, and how to remove it.
- 11 LEGAL & SYSTEM Terms of service — Rules of use, liability and account termination.
- 12 LEGAL & SYSTEM 404 not found — Friendly dead end with search and links back.
15
Page map
PUBLIC AUTH APP (signed in) LEGAL & SYSTEM ──────────────── ───────────────── ─────────────────── ─────────────────── ├─ Services ├─ Sign up └─ Account settings ├─ Privacy policy ├─ Methodology ├─ Log in ├─ Terms of service ├─ Pricing └─ Reset password └─ 404 not found ├─ Report Sample └─ Contact key flows: Services ──▶ Pricing Methodology ──▶ Report Sample Pricing ──▶ Contact Report Sample ──▶ Contact
