Security Audit for Startups & SMBs

The security audit for teams without a security team.

A fixed-price, two-week cybersecurity audit for startups and small businesses: code, cloud, authentication, dependencies, email, and public surface. AI does the exhaustive sweep, a senior engineer verifies and signs every finding, and you get a written report with a fix roadmap your team can start on the same day. If SOC 2 is on your horizon, we map the gaps before the auditors arrive.

$4,500 to $7,500, fixed on the first callTwo weeks, start to reportA senior engineer signs every finding
$4.4M

global average cost of a data breach (IBM Cost of a Data Breach Report, 2025)

60%

of breaches involve the human element: phishing, stolen credentials, mistakes (Verizon DBIR, 2025)

241

days on average to identify and contain a breach. Most victims find out from someone else (IBM, 2025)

When companies call us

Security debt is invisible, right up until someone asks about it.

An enterprise customer sent a security questionnaire

The deal is real, the questions are specific, and nobody on your side can answer them with a straight face. Every week it sits unanswered, the deal cools.

SOC 2 is suddenly on the roadmap

A contract requires it and nobody knows how far away you are, what it costs, or where to start. The honest first step is a gap assessment, not an auditor.

Nobody independent has ever looked

The product was built by a small team, an agency, or years of fast shipping. It works. Whether it's secure is a question nobody has actually checked.

Your cyber insurer wants answers

The renewal form asks about MFA, backups, access control, and incident response. Guessing on that form is how claims get denied later.

What we check

Six passes, from your code to the cloud it runs on.

A real audit reads the code and checks the doors. Scanners do neither well.

01

Secrets & credentials

Client bundles, repos, commit history, and configs, swept for anything an attacker could pick up off the floor: keys, tokens, passwords, connection strings.

02

Authentication & access control

Auth flows, session handling, MFA coverage, and authorization boundaries: who can see what, and what an attacker can reach by just changing an ID.

03

Dependencies & supply chain

Every package checked against known CVEs, plus the abandoned and unmaintained dependencies that turn into next year's incident.

04

Cloud & infrastructure config

Storage buckets, IAM, CORS, security headers, TLS, backups, and infrastructure-as-code, reviewed for the misconfigurations that put companies in headlines.

05

Email & domain security

SPF, DKIM, and DMARC, spoofability, and lookalike exposure. Phishing is still the front door of most small-business breaches; we check whether yours is locked.

06

Architecture & data flows

Where customer data lives, where it flows, tenancy boundaries, and scaling hazards: whether the shape of the system can carry the business you're building on it.

SOC 2 readiness

Need SOC 2? Start with the gap, not the auditor.

When SOC 2 is the goal, we run the audit against the Trust Services Criteria and hand you a readiness gap assessment: which controls you already satisfy, which need building, and the order to build them in. You walk into the attestation knowing exactly what it will find.

One thing we'll always be straight about: the SOC 2 report itself is issued by a licensed CPA firm, full stop. Anyone selling you "the whole thing" is either reselling an auditor or auditing their own preparation work, which is exactly the conflict SOC 2 exists to prevent. We do the engineering side, we make the auditor's job boring, and we'll help you choose the firm when you're ready.

  • Gap assessment mapped to the SOC 2 Trust Services Criteria
  • Remediation roadmap ordered by effort and audit impact
  • Handoff support: we help you scope and select the CPA firm
How it works

Two weeks. Sweep, verify, roadmap.

AI gives the audit reach. Human judgment gives it value. You get both, on a fixed clock.

01

Sweep

Days 1 to 5. With read-only access, we run a full AI-assisted pass over your code, dependencies, configuration, and public surface. Every file gets read, many of them for the first time since they were written.

02

Verify

Days 6 to 9. A senior engineer takes everything the sweep surfaced, kills the false positives, and rates what's real by severity and exploitability. Nothing reaches the report until a human has reproduced it.

03

Roadmap

Days 10 to 14. You get a written report with an executive summary you can hand to customers, insurers, and investors, plus a prioritized fix roadmap: what to fix now, what to fix soon, what to consciously accept. We walk you through all of it on a call.

Engineers who can secure what they build

We've worked in security since 2016 and run production systems since 2017.

We're not a scanner with a landing page. Federico De Faveri, the engineer who signs every report, has been fractional CTO of a New York promotions agency since 2017: he built and still runs Receipt Rewards, the OCR receipt-validation platform behind national promotions for Unilever, Knorr, Hellmann's, Scotch, Fandango, and Novamex. 100,000 receipts processed to date, 3 to 6 national campaigns a year, and the 2 a.m. emergencies the client never has to think about.

And the problems this audit hunts are not hypothetical. In one recent week of passive, public-surface reviews of five freshly launched products: one exposed its database configuration in the client bundle, three could have their email domain spoofed by anyone, and three shipped with no defense against clickjacking. Nobody had looked. That's the whole problem.

2016

In security work since

2017

Running production systems since

~100k

Receipts processed on our platform

Every

Finding signed by a named engineer

“Always available, endlessly patient in explaining every decision, calm in every emergency, and the quality of the platform has never let us down.”
Michael Eliran, CEO of Gamma Communications, New York
Pricing and scope

One fixed price. An honest scope.

Here is what the audit costs and where it ends. Every engagement is shaped around your product, your stack, and your stage, never a template; the range is what it is. Classic pentests run $10,000 to $30,000 and hand you a vulnerability list. This costs a fraction of that, and it answers the question a vulnerability list can't: whether the foundations are worth building on.

The audit
$4,500-7,500

Quoted on the first call, agreed before we start. It never moves.

  • Two weeks, start to report
  • Begins with read-only access
  • Shaped around your product, never a template
  • Never more than three audits at a time, so nothing gets skimmed
In the engagement
  • Complete sweep of code, dependencies, configuration, and public surface
  • Every finding reproduced and triaged by hand
  • Written report with a summary built for customers, insurers, and your board
  • Prioritized fix roadmap, ordered by real risk
  • SOC 2 readiness gap assessment, when that's your goal
  • Walkthrough call with the engineer who did the work
  • One retest of the fixed criticals, within 30 days of the report
Not in it, on purpose
  • ×The SOC 2 attestation itself: a licensed CPA firm issues that, and we prepare you for it
  • ×Certification audits: ISO 27001, PCI QSA, FedRAMP
  • ×A formal attestation penetration test
  • ×Continuous monitoring or managed security

Need one of those instead? We'll say so up front and point you toward the right kind of firm.

AI does the volume. A human signs the report.Nothing intrusive ever runs without written authorization.

The report is written for your own team to execute; the roadmap never assumes you'll hire us again. But if you'd rather have it handled, the audit rolls straight into our fractional CTO engagement: we fix what we found, then stay on to run your technology.

FAQ

Frequently asked questions.

It covers more ground than most pentests at this price: full code review, cloud configuration, dependencies, email security, and architecture, with targeted testing of running systems under your written authorization. What it is not is a formal attestation pentest, the kind an enterprise procurement team sometimes requires from a certified testing firm. If that's what your contract demands, we'll tell you on the first call and point you to the right kind of firm.

We map your product and practices against the SOC 2 Trust Services Criteria and hand you the gap list: what already holds up, what needs building, and in what order. The attestation itself is always issued by a licensed CPA firm, no matter who prepares you. Our job is to make that engagement short and boring, and we'll help you pick the auditor when you're ready.

Yes. SOC 2 readiness is an option inside the audit, not the point of it. Most clients come to us because a customer asked a hard question, an insurer sent a form, or they simply don't know where they stand. The audit answers that on its own.

A fixed fee between $4,500 and $7,500, set on the first call based on the size of your codebase and surface area. There is no hourly meter: the number is agreed before any work starts and doesn't change mid-engagement.

It stays under our control. The review runs on our machines, and AI assistance goes through enterprise API agreements that do not train on your code. Access is read-only and revoked when the engagement ends, we retain nothing but the report we wrote for you, and we'll sign your NDA before seeing anything.

It changes the risk profile, not the process. If most of your code was written with Cursor, Claude Code, or Copilot, our AI-Built Product Security & Rescue Audit is the same engagement tuned for exactly that failure mode. Agency-built and inherited codebases fit this audit as-is: an independent read of code nobody on your side has reviewed is precisely the point.

Then the report says so, plainly. You get the same deliverable: what we checked, what held up, and the short list worth tightening anyway. A clean report is a fine outcome, and a useful one to show customers, insurers, and investors. We don't inflate severity to justify a fee.

You get a prioritized roadmap your team can execute on its own. If you'd rather have us fix it and run it, that's our fractional CTO engagement: we remediate the findings and take ongoing ownership of your technology.

Two weeks from now

You'll know exactly where you stand.

Bring your product to a free 30-minute call. We'll tell you straight whether the audit is worth it for your stage, and put a fixed number on it if it is.

Book a Free 30-Min Call

Not ready for a call?

Tell us what you run and we'll reply within one business day, with a straight answer on whether the audit fits.

No newsletter, no follow-up sequence. One reply from an engineer.