Skip to content

We sort out your pentest findings and check every fix before the retest

Your pentest report has a long list of findings and a retest date. We sort out which matter, fix the infrastructure ones, tell your developers what to change in the rest and check everything before the tester comes back.

The first call is free. Services start from $1,500, and we agree a fixed price before any work starts.

An example of the findings register, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • A pentest or VAPT report has landed and nobody owns it.
  • The retest is booked and findings are still open.
  • The same findings came back as last year.

A finding that passes the retest but is still open

A made-up example of what can go wrong here.

  1. The report flags one endpoint

    The tester shows it handing back other customers’ records.

  2. The team patches that endpoint

    The retest no longer flags it, so the finding is marked fixed.

  3. The cause is elsewhere

    The missing check sits in shared code that ten other endpoints use.

  4. Ten endpoints are still open

    Other customers’ records can still be read through the ones the report didn’t name.

So we ask: Does each fix remove the cause, or only the example in the report?

For your engineer

Two files, after the patch

// api/invoices/[id].ts: patched for the report
const invoice = await findOwned("invoices", id, user.accountId);

// lib/records.ts: still used by ten other endpoints
export const findById = (table, id) => db(table).where({ id }).first();

What you get

We agree a fixed price after the free call, once we know what’s in scope. Services start from $1,500.

Request a free call
  • The findings sorted: what matters, what’s noise, and which ones share a cause.
  • A fix plan: what we fix, and what your developers fix.
  • A worked example for each code fix, and a check of each fix before the retest.
  • A one-page closure summary for whoever asked for the pentest.

Not included: changes to your app’s code (your developers make them, with our help), the audit, certificate or pentest itself, software licences, insurer or broker fees, and incident response.

Before we touch anything

Nothing starts without your written OK
You name the systems, the accounts and the dates first.
We work from a named account you create
It has only the rights the work needs, and you can see everything it does.
You take the access back when we’re done
We delete or return our working data, and you remove the account.

All six ground rules

How it works

Three steps. You agree the price before each one starts. Services start from $1,500.

  1. A free call

    Tell us who’s asking and when they need an answer. We’ll say what we’d check, then send you a fixed price.

    30 minutesFree

  2. We check what they asked about

    We check your product and setup against their questions, and test where it matters. You get the answers with evidence, a plan and a one-page summary to send them.

    About two weeksPriced after the call

  3. We fix what’s missing

    We fix your cloud and account setup ourselves. Your developers make the code changes, with our help. Then we check every fix, at no extra cost.

    Usually web firewall, sign-in security and cloud alerts. What each fix does.

    1 to 8 weeks a fixPriced after the assessment

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you run the retest?

No. Your original tester does, and that’s who signs off. We check every fix first, so you know what they’ll find.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Tell us about the pentest report

How many findings, which systems they touch, and when the retest is booked. Leave the report itself out of a first enquiry.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

We only use it to follow up on your enquiry.

When does whoever’s asking need an answer?

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.