Application security reviews
A security review you can act on, written in plain language.
Application security reviews are best done early, documented, and by somebody who has also built the kind of system they are examining. We read your code, architecture and infrastructure against a written baseline, and we evidence every finding.
- Pricing
- Scoped
- Typical timeline
- 1–2 weeks
- Stack
- OWASP ASVS · Dependency scanning · Hardening checklists · Threat review
What you receive is findings ranked by real risk to your situation, a walkthrough with your team, and a fix plan with estimates. What you do not get is a report nobody can act on.
What this covers
Code and dependency review
Where the sensitive decisions actually live: secrets, authentication and authorisation checks, and a scan of dependencies for known vulnerabilities and licence problems.
Infrastructure review
Hosting configuration, access and least privilege, backups (and whether a restore has ever been tested), and the settings that get forgotten on launch day.
A written risk register
Findings ranked by likelihood and impact for your specific situation, with enough context that a developer who was not in the room can act on them.
A prioritised fix plan
What to fix first, in what order, and roughly what each item costs. Fixing is priced separately or included where the scope warrants it — your choice.
What you get
- A written security review with a risk register
- Findings ranked by likelihood and impact for your situation
- A walkthrough of the findings with your team
- A prioritised fix plan with estimates
- An honest note on what we did and did not review
Stack
- OWASP ASVS
- Dependency scanning
- Hardening checklists
- Threat review
We use a small, well-understood stack deliberately. Fewer surprises, faster decisions, and estimates that hold.
Common questions
- Is this a penetration test?
- No — we are explicit about that. We review code, architecture and configuration against a written baseline. Where a project genuinely needs an independent penetration test, we arrange a third party rather than implying we run one in-house.
- Do you hold SOC 2 or ISO 27001?
- No, and we will not imply otherwise. We apply a written security baseline to every project and can evidence each item when you send a security questionnaire — most come back within a day.
- Can you review software you did not build?
- Yes, and this is often the most valuable kind: inherited code, a system a previous vendor handed over, or an app about to be audited. We document what is actually there before recommending anything.