services

Three scopes. Fixed prices. No surprises.

Each one is scoped on a short call and priced before it starts. Prices below are starting points for a typical application; scope drives the final figure, and you see it before you commit.

Web application & API test

Manual testing of your web application and the APIs behind it, authenticated as every user role, against the OWASP testing guides.

From £2,950per application, fixed price after scoping

  • Manual testing aligned with the OWASP Web Security Testing Guide and the OWASP API Security Top 10, supported by tooling rather than driven by it
  • Authentication, session management, access control and multi-tenancy isolation
  • Injection, file handling, business-logic and workflow abuse testing
Full details →

Medical-device & SaMD web application test

The same testing, plus the evidence structure that regulatory submissions and notified-body reviews ask for.

From £5,950per application, fixed price after scoping

  • Everything in the web application & API test
  • Test plan and test specification written before testing, so the work is traceable
  • Findings mapped to your security risk management (ISO 14971-aligned) and threat model
Full details →

Cloud configuration review

A configuration and identity review of the Azure environment your application runs in, with prioritised, practical fixes.

From £1,950per environment, fixed price after scoping

  • Identity and access review: privileged roles, conditional access, service principals and key rotation
  • Network exposure: what is reachable from the internet and why
  • Data protection: storage, encryption and secret handling
Full details →

terms

What you can hold me to.

  • Fixed-price quote within 2 working days of the scoping call
  • Report delivered within 5 working days of testing ending
  • One retest of fixed findings included, within 60 days
  • Critical findings reported as soon as they are confirmed, not saved for the report

boundaries

What is never in scope.

  • Written authorisation and rules of engagement before any testing begins
  • No denial-of-service testing, and no destructive actions without explicit agreement
  • No social engineering, phishing or physical testing
  • Third-party platforms are tested only with that provider’s permission where required
  • Findings are handled confidentially and are never disclosed to anyone but you

request a scope

Find out what a test would cost

A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.

Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days