Security
A security review you can act on, written in plain language.
Application security reviews are best done early, documented, and by somebody who has also built the kind of system they are examining. We read your code, architecture and infrastructure against a written baseline, and we evidence every finding.
- Pricing
- Scoped
- Typical timeline
- 1–2 weeks
- Stack
- OWASP ASVS · Dependency scanning · Hardening checklists · Threat review
What you receive is findings ranked by real risk to your situation, a walkthrough with your team, and a fix plan with estimates. What you do not get is a report nobody can act on.
What this covers
Code and dependency review
Where the sensitive decisions actually live: secrets, authentication and authorisation checks, and a scan of dependencies for known vulnerabilities and licence problems.
Infrastructure review
Hosting configuration, access and least privilege, backups (and whether a restore has ever been tested), and the settings that get forgotten on launch day.
A written risk register
Findings ranked by likelihood and impact for your specific situation, with enough context that a developer who was not in the room can act on them.
A prioritised fix plan
What to fix first, in what order, and roughly what each item costs. Fixing is priced separately or included where the scope warrants it — your choice.
How a review runs
- 01
The scope comes first
A written scope before anything else: which environments, frontend, backend and dependencies we test, how far we go, and what is explicitly out of scope. You approve it, then we start — the same way every project works here.
- 02
A documented review
We check the agreed surface, record every finding with evidence and a severity, and write the report in plain language. You know what to fix, why it matters, and how much it should cost elsewhere.
- 03
Fixes, agreed separately
Fixing what we find can be quoted as part of the same engagement or handed to your in-house team with the report. Either way, the fixes are written down before any code changes.
What you get
- A written security review with a risk register
- Findings ranked by likelihood and impact for your situation
- A walkthrough of the findings with your team
- A prioritised fix plan with estimates
- An honest note on what we did and did not review
A review is scoped to a written specification and quoted as the other services are. There is no published price because every application surface is different.
Full service details