Skip to content
Full service page

Security

A security review you can act on, written in plain language.

Application security reviews are best done early, documented, and by somebody who has also built the kind of system they are examining. We read your code, architecture and infrastructure against a written baseline, and we evidence every finding.

Pricing
Scoped
Typical timeline
1–2 weeks
Stack
OWASP ASVS · Dependency scanning · Hardening checklists · Threat review

What you receive is findings ranked by real risk to your situation, a walkthrough with your team, and a fix plan with estimates. What you do not get is a report nobody can act on.

What this covers

Code and dependency review

Where the sensitive decisions actually live: secrets, authentication and authorisation checks, and a scan of dependencies for known vulnerabilities and licence problems.

Infrastructure review

Hosting configuration, access and least privilege, backups (and whether a restore has ever been tested), and the settings that get forgotten on launch day.

A written risk register

Findings ranked by likelihood and impact for your specific situation, with enough context that a developer who was not in the room can act on them.

A prioritised fix plan

What to fix first, in what order, and roughly what each item costs. Fixing is priced separately or included where the scope warrants it — your choice.

How a review runs

  1. 01

    The scope comes first

    A written scope before anything else: which environments, frontend, backend and dependencies we test, how far we go, and what is explicitly out of scope. You approve it, then we start — the same way every project works here.

  2. 02

    A documented review

    We check the agreed surface, record every finding with evidence and a severity, and write the report in plain language. You know what to fix, why it matters, and how much it should cost elsewhere.

  3. 03

    Fixes, agreed separately

    Fixing what we find can be quoted as part of the same engagement or handed to your in-house team with the report. Either way, the fixes are written down before any code changes.

What you get

  • A written security review with a risk register
  • Findings ranked by likelihood and impact for your situation
  • A walkthrough of the findings with your team
  • A prioritised fix plan with estimates
  • An honest note on what we did and did not review

A review is scoped to a written specification and quoted as the other services are. There is no published price because every application surface is different.

Full service details

Worried about your app's security?

Book a call