Skip to content

What the assessment checks, part by part

Whoever’s asking, their questions land on one of these parts. One assessment can cover every part of your product an attacker could use.

Free 30-minute call. Not sure a pentest is enough? Read the comparison.

A typical software product, part by part.

How it works

From a free call to closed gaps.

  1. We agree what to look at

    On a free call we work out who’s asking, what they asked for and when they need it. We confirm the fee before any work begins.

  2. We check your systems

    We read the settings, the design and the code with your team. Where you’ve agreed it, we test hands-on with the access you set up.

  3. You get the answers and a plan

    The form or report answered with evidence, the gaps in the order to close them, and a one-page summary you can forward.

  4. We close the gaps

    We make the infrastructure fixes, each at a fixed price. Code changes go to your developers with our pattern. We check every fix.

What it costs

One assessment can cover several parts, at one price. The fixes that close what it finds are priced after it.

Included

  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes

How we handle your systems and data

The same ground rules for every assessment.

Nothing starts without your written OK
You name the systems, the accounts and the time window. We start when you’ve signed that off.
What you share stays private
We can sign your NDA before you share any system details. Reports go only to the people you name.
We keep as little as we can
Only the evidence a finding needs, and as little personal data as possible. An assessment never changes production.
Every change is agreed before it’s made
Each fix lists its changes, the day they happen and how to roll them back. We use a named account you create, with only the rights the fix needs, and you can see everything it does.
You get your access and data back
When we’re done we delete or return our working data, and you remove the accounts you set up for us.
What the report won’t cover
Every report lists what we didn’t check. It isn’t a compliance certificate, and the audit, test or insurer’s decision stays theirs.

Not sure which parts apply?

Tell us what you’re building and what’s changing, and we’ll suggest where to start. We reply within one working day.

Request a free call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.