Skip to content

How it works

A free call, then a fixed-price assessment of your product, then the fixes it needs. You know the price before each step starts.

We reply within one working day.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

What we fix, and what your developers fix

Two kinds of work close the gaps. We make four fixes at fixed prices. Your developers make the code changes, working from our pattern.

The fixes we make

FixWhat we set upCalendar time
IdentityMFA covers only the people who deploy.MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced.3 to 4 weeks
Cloud monitoringCloud logs are kept, but nobody is alerted.CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team.1 to 2 weeks
Backups and recoveryNightly backups have never been restored in a test.Backups configured with retention, and made immutable where your platform allows it. One restore test, documented.1 week
EdgeNothing filters traffic in front of the app.A web application firewall in front of your app: count mode first, then tuning, then block.2 to 3 weeks

The code changes your developers make

Grouped by the boundary each one repairs. Fernleaf’s developers estimate 4 to 6 weeks for all five.

Work packageFindingsWhat changesHow you know it worked
Customer data isolationARC-01APP-01AI-01The account is taken from the signed-in session for every request, export job and search. No field the caller controls can widen what they see.Own-account and cross-account cases run through the screens, the API, exports and search, cached results included.
Roles and membershipAPP-02APP-03AI-02Current role, current membership and a person’s verified sign-off are checked before any change or external action.Refused cases leave nothing behind. Removals and expired sign-offs take effect on the next request.
Production identityCLD-01CLD-02Only the production workflow can assume the production role, and it can pass on only the runtime roles on its list.A matrix of allowed and refused subjects and roles, checked with every policy layer in place.
Webhook destinationsARC-02An application rule for allowed destinations, backed by network egress controls.Internal, redirected and re-resolved addresses fail from the real delivery network.
Release imagesCLD-03Sign-off and deployment both use the same verified image digest.The deployed digest matches the one signed off, and any other image is refused.

Retest

We check each fix. One round of retesting is included.

Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd21 / 26
The plan from our sample report: what we fix, and what your developers fix.Read the whole sample report

The three steps

The same for everyone, whoever’s asking.

  1. A free call

    Tell us what you need and who’s asking. We’ll say what we’d check and give you a fixed price.

    30 minutesFree

  2. We check your product

    Your app, your cloud and how code gets to production. You get a report, a plan and a one-page summary to send to whoever’s asking.

    About two weeksfrom €3,600

  3. We fix what’s missing

    We set up what your product lacks, like MFA, alerts and tested backups. Your developers make any code changes, with our help. Then we retest, at no extra cost.

    Fixed price per fixfrom €700

See all six fixes and their prices

What you get from the assessment

Written for your engineers, with a summary for whoever’s asking.

See a sample report
  • A report your engineers can act on, with the evidence for each problem
  • What to fix first, and how to check each fix worked
  • A one-page summary to send to your customer, auditor or insurer
  • A call to walk your engineers through it
  • One retest after the fixes, included

What isn’t included

So there are no surprises later.

  • Changes to your application code. Your developers make them from our pattern, and we retest.
  • The certification, audit or test itself, and its fees: SOC 2, ISO 27001, the pentest, the insurer's own checks.
  • Licences, such as Entra ID P1, endpoint protection or device management seats, and insurer or broker fees.
  • Incident response.

Not sure where to start?

Tell us who’s asking and when they need an answer. We’ll say where to start. We reply within one working day.

Request a free call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.
What we check, part by part