DefensiveAI

Services

Three ways to work with us.

Prices are published — see Pricing.

Assessment

One-time · from $3,500

A complete analysis of your codebase: every line read, every observation validated, every finding tied to what it means for your business. Delivered as a written report with remediation guidance and a walkthrough with your team. Includes a summary letter suitable for customer security questionnaires and audits. Most assessments deliver within two weeks of access.

For companies that have never had a real security review, or haven’t since the codebase changed. Anyone facing a security questionnaire.

Continuous

Monthly · from $600

A monthly services agreement. The analysis runs again on a schedule or on merge. An analyst reviews what changed — new observations, resolved ones, anything that combines with something already known. You get a short note each month and an immediate alert if something serious appears. No standing meetings.

For companies shipping continuously. Anyone who has been through an Assessment and wants the posture to hold.

Fixes

Per finding, or hourly

We implement the remediations. Scoped per finding with a fixed price agreed in advance, or hourly for open-ended work. Delivered as pull requests against your repository for your team to review.

How an engagement works

Access
Read-only access to your repository, or an archive delivered through a channel we agree on. We never ask for production credentials for analysis.
Where it runs
On infrastructure we control, isolated per client. For clients who require it, the analysis can run inside your own environment.
Who sees it
The analysts assigned to your engagement. No one else.
Retention
Your code and all derived reports are deleted 30 days after delivery. Under a Continuous agreement, they’re retained for the life of the agreement and deleted 30 days after it ends.
Training
Your code is never used to train models. Ours or anyone’s.
Confidentiality
Every engagement is confidential. We never name a client without written consent. When we describe past work publicly, it’s anonymized to the point where the pattern is recognizable and the client is not.
Stress testing
Requires written authorization naming the targets, runs against staging by default, and has agreed stop conditions. We provide the authorization template.

The same commitments in the Terms

Start with a free evaluation.

A top-level pass over your codebase and a 30-minute conversation about what we saw. No charge, no obligation.