Skip to content

Your pentest findings fixed and checked before the retest

Your pentester’s report has forty findings and a retest date. We work out which matter, fix the infrastructure ones, hand your developers the rest with a pattern, and check everything before the tester comes back.

Free 30-minute call. The assessment is a fixed fee, confirmed before any work begins.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

Ten findings and their proposed owners

Ordered by area. Risk is likelihood multiplied by impact, each scored from 1 to 5 (page 7).

ID and riskFindingProposed ownerPage
ARC-01High4 × 4 = 16Export workers trust the account named in the requestA customer can download another customer’s invoices through the export feature.Platform engineering9
ARC-02Medium3 × 3 = 9Webhook destinations can reach the internal networkA customer can set a webhook that calls services inside Fernleaf’s own network.Platform and network engineering10
APP-01High4 × 4 = 16Invoice reads skip the account ownership checkChanging one number in an invoice link shows another customer’s invoice.Application engineering11
APP-02High4 × 4 = 16Members can send invitations that grant Billing adminA user with read-only access can give someone full control of the customer account.Application and identity engineering13
APP-03Medium3 × 3 = 9Removed users keep access until their session expiresA person removed from a customer account can still see its data while they stay signed in.Identity and application engineering14
CLD-01High3 × 4 = 12Production role trusts every branch in the repositoryA test branch can get the same production access as an approved release.Cloud platform and release engineering15
CLD-02High3 × 5 = 15Deployment permissions can pass an unintended admin roleThe release pipeline can run code under an admin role it was never meant to use.Cloud security and platform engineering16
CLD-03Medium3 × 3 = 9Release approval is not bound to the deployed imageThe release you approve isn’t guaranteed to be the one that goes live.Release engineering17
AI-01High4 × 4 = 16Assistant search returns other customers’ documentsThe AI search can show one customer’s documents to another customer.AI platform and application engineering18
AI-02High3 × 4 = 12The assistant can send email without the required approvalThe AI assistant can email a report outside the company without anyone approving it.Agent platform and product engineering19

All findings are open. Start with the High findings that expose another customer’s data, then adjust the order for how reachable each path is and what depends on it.

Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd4 / 26
An example of the findings register, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • A pentest or VAPT report has landed and nobody owns it.
  • The retest is booked and findings are still open.
  • The same findings came back as last year.

What you get, and what it costs

Step 1 is the assessment, at one fixed fee. Step 2 is only the fixes the person asking needs. Every fix, with prices.

Step 1: what the assessment includes

  • The findings triaged: what matters, what’s noise, and what’s one root cause showing up several times.
  • A fix plan split into the fixes we make and your developers’ items.
  • Our pattern for each code fix, and a check of each fix before the retest.
  • A one-page closure summary for whoever asked for the pentest.

How it works

Three steps. You know the price before each one starts.

  1. A free call

    Tell us what you need and who’s asking. We’ll say what we’d check and give you a fixed price.

    30 minutesFree

  2. We check your product

    Your app, your cloud and how code gets to production. You get a report, a plan and a one-page summary to send to whoever’s asking.

    About two weeksPrice on the call

  3. We fix what’s missing

    We set up what your product lacks, like MFA, alerts and tested backups. Your developers make any code changes, with our help. Then we retest, at no extra cost.

    Fixed price per fixfrom €1,400

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you run the retest?

No. Your original tester does, and that’s who signs off. We make sure there’s nothing left for them to find.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Send us the report

How many findings, which systems they touch, and when the retest is booked. Leave the report itself out of a first enquiry.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

Send a short outline of what you want checked and any deadline.

Email Unmesha

Please leave out passwords and customer data. How we handle enquiry information.