Priced by tester-day, not by finding.
Three tiers — automated, hybrid, human-led — scoped to the obligation you have to demonstrate. From an external Nuclei sweep for the seed-stage founder to a PTES + WSTG + ASVS L2 grey-box for the enterprise that answers to SEC 17 CFR §229.106 or DORA Article 26.
Fixed fees, tester-days on the invoice, one re-test within 90 days included on human-led work. No surprise line items.
Custom Audit
Automated Nuclei + Naabu + Subfinder sweep of your public attack surface, with TLS posture graded to RFC 9325 and headers to the OWASP Secure Headers Project. CVSS 4.0-scored, signed PDF, no analyst booking.
- Nuclei · Naabu · Subfinder pipeline
- TLS 1.2/1.3 + cipher grading (RFC 9325)
- Security headers per OWASP SHP baseline
- CVSS 4.0 severities, signed PDF
- No surprise fees, no lock-in
Advanced Audit
Automation from Custom plus one to two targeted manual tests where machines cannot rule — authorisation-adjacent business logic, session integrity, multi-tenant BOLA / BFLA. Report tuned to SOC 2 CC7.1 or ISO 27001 A.5.30 on request.
- Automated pipeline + 1–2 human-led checks
- Business-logic + session-integrity spotchecks
- Findings mapped to CWE + ATT&CK technique
- AI-drafted executive summary, human-signed
- Framework mapping (SOC 2 CC7.1 / ISO 27001 A.5.30)
Expert Manual Audit
PTES phases 1–7, OWASP WSTG v4.2, OWASP ASVS Level 2, MITRE ATT&CK v14 kill-chain mapping. Grey-box against a production-equivalent stage. Executive summary, technical findings with replayable proof, remediation roadmap, one re-test within 90 days.
- PTES phases 1–7 · WSTG v4.2 · ASVS L2
- Multi-role & multi-tenant depth (BOLA, BFLA, BOPLA)
- MITRE ATT&CK v14 kill-chain mapping per finding
- Compliance dossier: SOC 2, ISO 27001, NIS2 Art. 21, DORA Art. 26
- Suitable for SEC 17 CFR §229.106 disclosure evidence
A 15-minute call to find the right tier.
No sales pitch — an honest read on what your asset surface, compliance profile, and budget line up with.
Book a call →