What the assessment checks, part by part
Whoever’s asking, their questions land on one of these parts. One assessment can cover every part of your product an attacker could use.
Free 30-minute call. Not sure a pentest is enough? Read the comparison.
Every part, one assessment
Each part has its own assessment. Pick the ones you need, or cover them all at once.
Web app and API
Could one of your customers see another customer’s data?Application & API security assessmentCloud account
Who and what can reach your production cloud, and would you notice?Cloud security assessmentCode and releases
Who can change your live product without anyone checking?Code delivery & developer access assessmentAI features
Could your AI feature leak data or do something you never intended?AI & agent security assessmentYour team
How easy would it be to get into your company through email or a staff account?Company IT security assessmentThe platform’s design
Is your platform’s design safe to keep building on?SaaS architecture assessment
How it works
From a free call to closed gaps.
We agree what to look at
On a free call we work out who’s asking, what they asked for and when they need it. We confirm the fee before any work begins.
We check your systems
We read the settings, the design and the code with your team. Where you’ve agreed it, we test hands-on with the access you set up.
You get the answers and a plan
The form or report answered with evidence, the gaps in the order to close them, and a one-page summary you can forward.
We close the gaps
We make the infrastructure fixes, each at a fixed price. Code changes go to your developers with our pattern. We check every fix.
What it costs
One assessment can cover several parts, at one price. The fixes that close what it finds are priced after it.
Included
- The assessment of the systems we agree
- A findings report with the evidence for each issue
- What to fix first, and how to check each fix
- A walkthrough call with your engineers
- One round of retesting after your fixes
How we handle your systems and data
The same ground rules for every assessment.
- Nothing starts without your written OK
- You name the systems, the accounts and the time window. We start when you’ve signed that off.
- What you share stays private
- We can sign your NDA before you share any system details. Reports go only to the people you name.
- We keep as little as we can
- Only the evidence a finding needs, and as little personal data as possible. An assessment never changes production.
- Every change is agreed before it’s made
- Each fix lists its changes, the day they happen and how to roll them back. We use a named account you create, with only the rights the fix needs, and you can see everything it does.
- You get your access and data back
- When we’re done we delete or return our working data, and you remove the accounts you set up for us.
- What the report won’t cover
- Every report lists what we didn’t check. It isn’t a compliance certificate, and the audit, test or insurer’s decision stays theirs.
Not sure which parts apply?
Tell us what you’re building and what’s changing, and we’ll suggest where to start. We reply within one working day.
- We reply within one working day. We set up the call, and you meet the people who’d do the work.
- We send a proposal with the scope, the timing and a fixed fee.
- Work starts when you say go.
