Skip to content

Step 2: fixed-price fixes for what the assessment finds

The assessment (step 1) shows what’s missing. Then we put it in place: each fix hardens one part of your product, at a fixed price, and you only buy the ones the person asking needs.

Free 30-minute call. Fixes are priced once the assessment has shown what’s missing.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

What we fix, and what your developers fix

Two kinds of work close the gaps. We make four fixes at fixed prices. Your developers make the code changes, working from our pattern.

The fixes we make

FixWhat we set upCalendar time
IdentityMFA covers only the people who deploy.MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced.3 to 4 weeks
Cloud monitoringCloud logs are kept, but nobody is alerted.CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team.1 to 2 weeks
Backups and recoveryNightly backups have never been restored in a test.Backups configured with retention, and made immutable where your platform allows it. One restore test, documented.1 week
EdgeNothing filters traffic in front of the app.A web application firewall in front of your app: count mode first, then tuning, then block.2 to 3 weeks

The code changes your developers make

Grouped by the boundary each one repairs. Fernleaf’s developers estimate 4 to 6 weeks for all five.

Work packageFindingsWhat changesHow you know it worked
Customer data isolationARC-01APP-01AI-01The account is taken from the signed-in session for every request, export job and search. No field the caller controls can widen what they see.Own-account and cross-account cases run through the screens, the API, exports and search, cached results included.
Roles and membershipAPP-02APP-03AI-02Current role, current membership and a person’s verified sign-off are checked before any change or external action.Refused cases leave nothing behind. Removals and expired sign-offs take effect on the next request.
Production identityCLD-01CLD-02Only the production workflow can assume the production role, and it can pass on only the runtime roles on its list.A matrix of allowed and refused subjects and roles, checked with every policy layer in place.
Webhook destinationsARC-02An application rule for allowed destinations, backed by network egress controls.Internal, redirected and re-resolved addresses fail from the real delivery network.
Release imagesCLD-03Sign-off and deployment both use the same verified image digest.The deployed digest matches the one signed off, and any other image is refused.

Retest

We check each fix. One round of retesting is included.

Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd21 / 26
The plan, from our fictional sample report: the fixes we make, and the code changes your developers make.Read the whole sample report

The six fixes

What each one includes, how long it usually takes, and its starting price.

FixWhat’s includedTypical calendar timeFrom
Identity

Your team

MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced.3 to 4 weeks€5,000
Cloud monitoring

Cloud account

CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team.1 to 2 weeks€2,300
Backups and recovery

Cloud account

Backups configured with retention, and made immutable where your platform allows it. One restore test, documented.1 week€1,800
Email trust

Your team

SPF, DKIM and DMARC for your domain, taken from monitoring to quarantine to reject. Most of the calendar is watching the reports.4 to 8 weeks€700
Devices

Your team

A device management baseline and endpoint protection across your laptops, with enrolment support for your people. Licences are extra.3 to 6 weeks€3,600
Edge

Web app and API

A web application firewall in front of your app: count mode first, then tuning, then block.2 to 3 weeks€1,400

Sized for one cloud, one workspace tenant and under about 50 people. Larger estates are quoted. Secrets management and data-deletion routines live in your application code. We give your developers the pattern and check the result.

Which fixes each offer usually needs

The assessment decides. This is where each offer usually lands.

OfferIdentityCloud monitoringBackups and recoveryEmail trustDevicesEdge
Customer security reviewUsually neededUsually neededUsually neededNot usually neededNot usually neededUsually needed
Audit preparationUsually neededUsually neededUsually neededNot usually neededUsually neededNot usually needed
Insurance renewalUsually neededNot usually neededUsually neededUsually neededUsually neededNot usually needed
AI feature checkUsually neededUsually neededNot usually neededNot usually neededNot usually neededNot usually needed
Pentest follow-upUsually neededUsually neededNot usually neededNot usually neededNot usually neededUsually needed

Not included

Secrets management and data-deletion routines live in your application code. We give your developers the pattern and check the result.

  • Changes to your application code. Your developers make them from our pattern, and we retest.
  • The certification, audit or test itself, and its fees: SOC 2, ISO 27001, the pentest, the insurer's own checks.
  • Licences, such as Entra ID P1, endpoint protection or device management seats, and insurer or broker fees.
  • Incident response.

How we handle your systems and data

The same ground rules for every assessment and every fix.

Nothing starts without your written OK
You name the systems, the accounts and the time window. We start when you’ve signed that off.
What you share stays private
We can sign your NDA before you share any system details. Reports go only to the people you name.
We keep as little as we can
Only the evidence a finding needs, and as little personal data as possible. An assessment never changes production.
Every change is agreed before it’s made
Each fix lists its changes, the day they happen and how to roll them back. We use a named account you create, with only the rights the fix needs, and you can see everything it does.
You get your access and data back
When we’re done we delete or return our working data, and you remove the accounts you set up for us.
What the report won’t cover
Every report lists what we didn’t check. It isn’t a compliance certificate, and the audit, test or insurer’s decision stays theirs.

Start with the assessment

It shows which fixes you need, and which you don’t. We reply within one working day.

Request a free call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.
Who’s asking? See every offer