Assessment
One-time · from $3,500
A complete analysis of your codebase: every line read, every observation validated, every finding tied to what it means for your business. Delivered as a written report with remediation guidance and a walkthrough with your team. Includes a summary letter suitable for customer security questionnaires and audits. Most assessments deliver within two weeks of access.
For companies that have never had a real security review, or haven’t since the codebase changed. Anyone facing a security questionnaire.
Continuous
Monthly · from $600
A monthly services agreement. The analysis runs again on a schedule or on merge. An analyst reviews what changed — new observations, resolved ones, anything that combines with something already known. You get a short note each month and an immediate alert if something serious appears. No standing meetings.
For companies shipping continuously. Anyone who has been through an Assessment and wants the posture to hold.
Fixes
Per finding, or hourly
We implement the remediations. Scoped per finding with a fixed price agreed in advance, or hourly for open-ended work. Delivered as pull requests against your repository for your team to review.
How an engagement works
- Access
- Read-only access to your repository, or an archive delivered through a channel we agree on. We never ask for production credentials for analysis.
- Where it runs
- On infrastructure we control, isolated per client. For clients who require it, the analysis can run inside your own environment.
- Who sees it
- The analysts assigned to your engagement. No one else.
- Retention
- Your code and all derived reports are deleted 30 days after delivery. Under a Continuous agreement, they’re retained for the life of the agreement and deleted 30 days after it ends.
- Training
- Your code is never used to train models. Ours or anyone’s.
- Confidentiality
- Every engagement is confidential. We never name a client without written consent. When we describe past work publicly, it’s anonymized to the point where the pattern is recognizable and the client is not.
- Stress testing
- Requires written authorization naming the targets, runs against staging by default, and has agreed stop conditions. We provide the authorization template.