Skip to content
All services

Security and QA checks

An independent security review and a test pass before you launch.

Every project we build goes through two independent checks before launch: a security baseline review and a QA pass. We also run both as standalone engagements for software we did not build — inherited code, a vendor deliverable, or a system about to be handed to a new team.

From
$450
Typical timeline
2 to 3 working days
Stack
OWASP guidance · Dependency scanning · HTTPS and header checks · Playwright · Lighthouse

A security baseline review checks configuration and common web risks. It is not a penetration test, and we do not sell compliance certification or claim it.

The QA deliverable is as much the test pack as the pass or fail run: each item is marked against a requirement with a result and a reason, so your team can re-run it after any future change.

What this covers

Website security baseline

An authorised scan plus a manual configuration review: HTTPS, headers, cookies, exposed files, CMS and dependency versions, form protection, backups and admin access.

App health check

One repository reviewed against common web risks: sign-in and sessions, access control, input handling, secrets, dependencies and logging, with a prioritised fix plan.

Dependency and secret scanning

Known vulnerable dependencies and committed secrets surfaced before they become a phone call.

QA test packs

Up to 40 test cases executed across browsers and phones, with bug reports your team can execute and re-run.

QA on demand

A dedicated tester for part of the week when you release regularly — regression checks before each release, bug reports and re-tests.

Plain-language findings

Severity-ranked findings with step-by-step fixes and a walkthrough call, written so a developer who was not in the room can act on them.

What you get

  • A written, severity-ranked report with specific fixes
  • A walkthrough call with your team
  • A re-check after fixes within the agreed window
  • A test pack your team can re-run going forward
  • An honest note on what we did and did not review

Stack

  • OWASP guidance
  • Dependency scanning
  • HTTPS and header checks
  • Playwright
  • Lighthouse

We use a small, well-understood stack deliberately. Fewer surprises, faster decisions, and estimates that hold.

Common questions

Is this a penetration test?
No — we are explicit about that. We review configuration, code and common web risks against a written baseline. Where a project genuinely needs an independent penetration test, we arrange a third party rather than implying we run one in-house.
Do you hold SOC 2 or ISO 27001?
No, and we will not imply otherwise. We apply a written security baseline to every project and can evidence each item when you send a security questionnaire.
Can you review or test software you did not build?
Yes — that is the standard case for these engagements. Inherited code, a vendor deliverable, or a system about to be handed to a new team all benefit.
Do you fix what the review finds?
Fixes are quoted separately, or credited where the fee note says so. The review and the fix stay separate decisions.

Tell us the problem and the deadline.

Book a call