Security and QA checks
An independent security review and a test pass before you launch.
Every project we build goes through two independent checks before launch: a security baseline review and a QA pass. We also run both as standalone engagements for software we did not build — inherited code, a vendor deliverable, or a system about to be handed to a new team.
- From
- $450
- Typical timeline
- 2 to 3 working days
- Stack
- OWASP guidance · Dependency scanning · HTTPS and header checks · Playwright · Lighthouse
A security baseline review checks configuration and common web risks. It is not a penetration test, and we do not sell compliance certification or claim it.
The QA deliverable is as much the test pack as the pass or fail run: each item is marked against a requirement with a result and a reason, so your team can re-run it after any future change.
What this covers
Website security baseline
An authorised scan plus a manual configuration review: HTTPS, headers, cookies, exposed files, CMS and dependency versions, form protection, backups and admin access.
App health check
One repository reviewed against common web risks: sign-in and sessions, access control, input handling, secrets, dependencies and logging, with a prioritised fix plan.
Dependency and secret scanning
Known vulnerable dependencies and committed secrets surfaced before they become a phone call.
QA test packs
Up to 40 test cases executed across browsers and phones, with bug reports your team can execute and re-run.
QA on demand
A dedicated tester for part of the week when you release regularly — regression checks before each release, bug reports and re-tests.
Plain-language findings
Severity-ranked findings with step-by-step fixes and a walkthrough call, written so a developer who was not in the room can act on them.
What you get
- A written, severity-ranked report with specific fixes
- A walkthrough call with your team
- A re-check after fixes within the agreed window
- A test pack your team can re-run going forward
- An honest note on what we did and did not review
Stack
- OWASP guidance
- Dependency scanning
- HTTPS and header checks
- Playwright
- Lighthouse
We use a small, well-understood stack deliberately. Fewer surprises, faster decisions, and estimates that hold.
Packages
Website Security Baseline
Owners of an existing website who want to know what is exposed and how to fix it.
$450
2 to 3 working days
See full packageApp Health Check
Owners of an existing app, or of code someone else wrote, who need to know how healthy it is.
$1,500
5 working days
See full packageDeep Health Check
Products with several repositories, infrastructure or mobile apps.
From $3,500
8 to 10 working days
See full packageCommon questions
- Is this a penetration test?
- No — we are explicit about that. We review configuration, code and common web risks against a written baseline. Where a project genuinely needs an independent penetration test, we arrange a third party rather than implying we run one in-house.
- Do you hold SOC 2 or ISO 27001?
- No, and we will not imply otherwise. We apply a written security baseline to every project and can evidence each item when you send a security questionnaire.
- Can you review or test software you did not build?
- Yes — that is the standard case for these engagements. Inherited code, a vendor deliverable, or a system about to be handed to a new team all benefit.
- Do you fix what the review finds?
- Fixes are quoted separately, or credited where the fee note says so. The review and the fix stay separate decisions.