Full Web App Audit

Automated scanners can't log in, reason about permissions, or notice that one customer can read another customer's data. A manual audit can, and it covers what enterprise buyers' security questionnaires ask about.

Price
$900–1,800 CAD
Turnaround
3–5 business days

What's included

A hands-on review of your web application, the way an attacker would approach it.

  • OWASP Top 10 review
  • Login, session and permission testing
  • API checks
  • Header and TLS review
  • Dependency audit
  • Prioritized report and walkthrough call
  • Email Authentication Hardening included as a same-day quick win

How it runs

  1. Start with what's public

    A free finding or a Security Snapshot. It only looks at what anyone on the internet can already see, so no access or passwords are needed.

  2. Talk it through

    A short call in plain English: what each finding means for your business, and which ones actually matter this month.

  3. Get the fix, not just the finding

    Deeper testing only happens under a written scope agreement. Fixes arrive as pull requests your developer can review, DNS records ready to paste, or takedown reports already filed.

  4. Keep watching

    Look-alike sites come back under new domains and new email senders appear. A retainer keeps someone watching after the report is done.

Often requested by

  • Dental, physio and med-spa clinics

    Under PHIPA you're accountable for patient information. Online booking tools, forgotten staging logins and outdated plugins are where it leaks.

  • Pre-seed and seed SaaS

    An enterprise buyer's security questionnaire can stall a deal for weeks. A leaked API key or open staging environment is far cheaper to fix now than mid-deal.

Ask about Full Web App Audit

Say what you run and when you need it. You'll get a fixed quote within the published range before any work starts.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.