The Baseline Sweep
Automated crawl and active scanning with Burp Suite Professional, followed by full triage and manual verification of the core OWASP Top 10 classes.
- Verified findings report
- Remediation priority list
Stop wasting engineering hours on 60-page scanner dumps. We combine automated discovery with hands-on manual verification and deliver a short, prioritised report your developers can act on the same day.
Traditional assessments hand over raw tool output and leave your team to work out what's real. We do that work before the report reaches you.
If a finding is in your report, an engineer has manually confirmed that it is real and exploitable in your environment. Anything we can't reproduce stays out.
Each finding comes with the affected endpoint, exact reproduction steps and the specific code-level fix, ready to paste into Jira or Linear.
A 1-page risk attestation that founders can hand to enterprise clients, auditors or investors without needing to explain it.
Three productised engagements built for B2B SaaS teams from seed to Series B.
Automated crawl and active scanning with Burp Suite Professional, followed by full triage and manual verification of the core OWASP Top 10 classes.
A full authenticated crawl across two or more user roles, plus deep manual testing for IDOR, privilege escalation, tenant isolation and API abuse, which are the flaws scanners can't see.
Continuous automated monitoring, with delta scans and targeted manual checks on every major release or route change. Security that keeps pace with your shipping cadence.
We agree on targets, exclusions, test window and roles, then sign a mutual Rules of Engagement before any testing starts.
We run authenticated crawling and active scanning with Burp Suite Professional, rate-limited and scheduled off-peak by default.
Engineers reproduce every candidate finding by hand and test the business logic that automated tools miss.
You receive the verified report, developer tickets and an executive attestation, followed by a walkthrough call with your team.
Here is a sanitised excerpt from a Logic & Access Audit. Every finding in your report follows the same structure.
A user in Tenant A can view and download confidential invoices belonging to Tenant B by changing a single parameter.
/api/v1/invoices/download?id=1045 (your own invoice).id to 1046, which belongs to Tenant B.200 OK with the other tenant's PDF.// Enforce object-level authorisation before serving the file if (invoice.tenant_id !== currentUser.tenant_id) { return res.status(403).end(); }
Every engagement starts with a signed mutual Rules of Engagement that defines exactly which assets are in scope, when testing happens and what is off-limits. Your production stability matters as much as your security.
Explicit scopeNamed domains, URLs and IP ranges only. Third-party services such as payment gateways are excluded by default.
Agreed test windowHeavy automated scanning is limited to off-peak hours in your time zone unless you ask otherwise.
Non-destructive by policyNo denial-of-service, no social engineering and no destructive data modification.
Confidential by defaultFindings and evidence are shared only with your named contacts.
A scanner is where we start, not what we deliver. The value is in the triage: we remove false positives, reproduce what's real by hand and add the manual access-control and logic testing that automated tools can't do.
Our 1-page attestation is written for procurement and vendor-risk teams. It states the scope, methodology, dates and outcome in plain language. Many buyers accept it alongside your questionnaire answers.
We prefer to test in staging. When production is in scope, scans are rate-limited and run in an agreed off-peak window, and destructive actions are prohibited under the Rules of Engagement.
We need a list of in-scope domains or APIs, test accounts for each role you want covered, a preferred test window and a signed Rules of Engagement. Most engagements can start within a week.
The Logic & Access Audit includes one free re-test within 30 days, and we update the attestation to reflect the fixes.
Tell us what you're building and when you need the report. We'll come back with a fixed scope and price within one business day.
Or email us directly at [email protected]