Skip to content

Is your platform’s design safe to keep building on?

Your engineers walk us through how the whole platform fits together. We tell you which design changes to make first.

Free 30-minute call.

A typical software product. An architecture assessment looks at how every part connects.

A webhook setting that reaches inside your network

A made-up example of what can go wrong here. It’s ARC-02 in our sample report.

  1. A customer adds a webhook

    Your app lets each customer give a web address for event notifications.

  2. The address points inside

    Instead of their own server, they enter an address inside your network.

  3. Your server makes the call

    The request now comes from inside, where your internal services trust it.

  4. Internal services answer

    A customer can reach services that were never meant to face the internet.

So we ask: Can an address a customer gives you make your platform call something inside your own network?

For your engineer

webhooks/deliver.ts

export async function deliver(event, subscription) {
  const body = JSON.stringify(event);
  // The address is whatever the customer saved.
  await fetch(subscription.url, { method: "POST", body });
}

What we look at

The questions we start from. We agree the final list with you on the call.

Best done before a big redesign or a large integration, while changes are still cheap.

  • Who and what can sign in, and what is each one allowed to do?
  • Is each customer’s data kept apart everywhere, including background jobs and exports?
  • Where do your keys and passwords live, and who can use them?
  • If one part were broken into, how far could it reach, and would you notice?

What you get

We agree a fixed price after the free call, once we know what’s in scope. Services start from $1,500. If the scope grows later, we price the extra before we start it.

Request a free call
  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes
  • The threat model we build with your team, for you to keep up to date

Not included: Changes to your application code (your developers make them from our pattern), a compliance certificate and anything outside the agreed scope. Quoted separately: The fixes that close what we find, quoted after the assessment, further retests after the first and extra scope added once work has started.

Before we touch anything

Nothing starts without your written OK
You name the systems, the accounts and the dates first.
We work from a named account you create
It has only the rights the work needs, and you can see everything it does.
You take the access back when we’re done
We delete or return our working data, and you remove the account.

All six ground rules

Before you enquire

What people ask us most. Wondering whether a pentest would do? Is a VAPT enough?

What do you need from us?

Your architecture diagrams, current or planned, and a working session with your engineers. Please leave sensitive diagrams out of a first enquiry.

Where do you stop?

We review the design and what you show us. Checking that the live system matches it is a separate test.

Is this a penetration test?

No. We review how the platform is designed. If you want us to test hands-on as well, we’ll put that in the scope.

Is retesting included?

Yes, one round. Once your team has made the fixes, we retest them. Each finding also comes with a check your team can run themselves.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Planning a redesign? Bring it to us before the tickets are written

What are you changing, and when do the design decisions need to be made?

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

We only use it to follow up on your enquiry.

When does whoever’s asking need an answer?

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.