SaaS security assessments, part by part
One assessment can cover every part of your product an attacker could use. We follow the paths to your data and your customers’.
Request a scoping callFree 30-minute scoping call. Not sure a pentest is enough? Read the comparison.
Every part, one assessment
Each part has its own assessment. Pick the ones you need, or cover them all at once.
Packages and pipeline
Who can change your live product without anyone checking?Code delivery & developer access assessmentCloud account
Who and what can reach your production cloud, and would you notice?Cloud security assessmentWeb app and API
Could one of your customers see another customer’s data?Application & API security assessmentAI features
Could your AI feature leak data or do something you never intended?AI & agent security assessmentYour team
How easy would it be to get into your company through email or a staff account?Company IT security assessmentThe platform’s design
Is your platform’s design safe to keep building on?SaaS architecture assessment
How it works
From a free call to checked fixes.
We agree what to look at
On a free scoping call we work out which parts of your platform carry the most risk. You decide what’s in.
We review and test
We read the design, code and settings with your engineers. Where you’ve agreed it, we test hands-on with the access you set up.
You get a clear report
Every finding comes with its evidence and why it matters. They’re listed in the order we’d fix them.
We retest your fixes
Every fix comes with a way to confirm it worked. Once your team has made the fixes, we retest them. One round is included.
What it costs
One assessment can cover several parts, at one price.
Fixed fee for the agreed scope, quoted before work starts.
We quote it after the scoping call, once we know what’s in. If the scope grows later, we price the extra before we start it.
Included
- The assessment of the systems we agree
- A findings report with the evidence for each issue
- What to fix first, and how to check each fix
- A walkthrough call with your engineers
- One round of retesting after your fixes
Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Further retests after the first and extra scope added once work has started.
How we handle your systems and data
The same ground rules for every review.
- Nothing starts without your written OK
- You name the systems, the accounts and the time window. We start when you’ve signed that off.
- What you share stays private
- We can sign your NDA before you share any system details. Reports go only to the people you name.
- We keep as little as we can
- Only the evidence a finding needs, and as little personal data as possible. We don’t touch production without asking.
- You get your access and data back
- When we’re done we delete or return our working data and hand back every login you gave us.
- What the report won’t cover
- Every report lists what we didn’t test. It isn’t a compliance certificate.
Not sure which parts apply?
Tell us what you’re building and what’s changing, and we’ll suggest where to start. We reply within one working day.
