Secrets & credentials
Client bundles, repos, commit history, and configs, swept for anything an attacker could pick up off the floor: keys, tokens, passwords, connection strings.
A fixed-price, two-week cybersecurity audit for startups and small businesses: code, cloud, authentication, dependencies, email, and public surface. AI does the exhaustive sweep, a senior engineer verifies and signs every finding, and you get a written report with a fix roadmap your team can start on the same day. If SOC 2 is on your horizon, we map the gaps before the auditors arrive.
global average cost of a data breach (IBM Cost of a Data Breach Report, 2025)
of breaches involve the human element: phishing, stolen credentials, mistakes (Verizon DBIR, 2025)
days on average to identify and contain a breach. Most victims find out from someone else (IBM, 2025)
The deal is real, the questions are specific, and nobody on your side can answer them with a straight face. Every week it sits unanswered, the deal cools.
A contract requires it and nobody knows how far away you are, what it costs, or where to start. The honest first step is a gap assessment, not an auditor.
The product was built by a small team, an agency, or years of fast shipping. It works. Whether it's secure is a question nobody has actually checked.
The renewal form asks about MFA, backups, access control, and incident response. Guessing on that form is how claims get denied later.
A real audit reads the code and checks the doors. Scanners do neither well.
Client bundles, repos, commit history, and configs, swept for anything an attacker could pick up off the floor: keys, tokens, passwords, connection strings.
Auth flows, session handling, MFA coverage, and authorization boundaries: who can see what, and what an attacker can reach by just changing an ID.
Every package checked against known CVEs, plus the abandoned and unmaintained dependencies that turn into next year's incident.
Storage buckets, IAM, CORS, security headers, TLS, backups, and infrastructure-as-code, reviewed for the misconfigurations that put companies in headlines.
SPF, DKIM, and DMARC, spoofability, and lookalike exposure. Phishing is still the front door of most small-business breaches; we check whether yours is locked.
Where customer data lives, where it flows, tenancy boundaries, and scaling hazards: whether the shape of the system can carry the business you're building on it.
When SOC 2 is the goal, we run the audit against the Trust Services Criteria and hand you a readiness gap assessment: which controls you already satisfy, which need building, and the order to build them in. You walk into the attestation knowing exactly what it will find.
One thing we'll always be straight about: the SOC 2 report itself is issued by a licensed CPA firm, full stop. Anyone selling you "the whole thing" is either reselling an auditor or auditing their own preparation work, which is exactly the conflict SOC 2 exists to prevent. We do the engineering side, we make the auditor's job boring, and we'll help you choose the firm when you're ready.
AI gives the audit reach. Human judgment gives it value. You get both, on a fixed clock.
Days 1 to 5. With read-only access, we run a full AI-assisted pass over your code, dependencies, configuration, and public surface. Every file gets read, many of them for the first time since they were written.
Days 6 to 9. A senior engineer takes everything the sweep surfaced, kills the false positives, and rates what's real by severity and exploitability. Nothing reaches the report until a human has reproduced it.
Days 10 to 14. You get a written report with an executive summary you can hand to customers, insurers, and investors, plus a prioritized fix roadmap: what to fix now, what to fix soon, what to consciously accept. We walk you through all of it on a call.
We're not a scanner with a landing page. Federico De Faveri, the engineer who signs every report, has been fractional CTO of a New York promotions agency since 2017: he built and still runs Receipt Rewards, the OCR receipt-validation platform behind national promotions for Unilever, Knorr, Hellmann's, Scotch, Fandango, and Novamex. 100,000 receipts processed to date, 3 to 6 national campaigns a year, and the 2 a.m. emergencies the client never has to think about.
And the problems this audit hunts are not hypothetical. In one recent week of passive, public-surface reviews of five freshly launched products: one exposed its database configuration in the client bundle, three could have their email domain spoofed by anyone, and three shipped with no defense against clickjacking. Nobody had looked. That's the whole problem.
In security work since
Running production systems since
Receipts processed on our platform
Finding signed by a named engineer
“Always available, endlessly patient in explaining every decision, calm in every emergency, and the quality of the platform has never let us down.”
Here is what the audit costs and where it ends. Every engagement is shaped around your product, your stack, and your stage, never a template; the range is what it is. Classic pentests run $10,000 to $30,000 and hand you a vulnerability list. This costs a fraction of that, and it answers the question a vulnerability list can't: whether the foundations are worth building on.
Quoted on the first call, agreed before we start. It never moves.
Need one of those instead? We'll say so up front and point you toward the right kind of firm.
The report is written for your own team to execute; the roadmap never assumes you'll hire us again. But if you'd rather have it handled, the audit rolls straight into our fractional CTO engagement: we fix what we found, then stay on to run your technology.
It covers more ground than most pentests at this price: full code review, cloud configuration, dependencies, email security, and architecture, with targeted testing of running systems under your written authorization. What it is not is a formal attestation pentest, the kind an enterprise procurement team sometimes requires from a certified testing firm. If that's what your contract demands, we'll tell you on the first call and point you to the right kind of firm.
We map your product and practices against the SOC 2 Trust Services Criteria and hand you the gap list: what already holds up, what needs building, and in what order. The attestation itself is always issued by a licensed CPA firm, no matter who prepares you. Our job is to make that engagement short and boring, and we'll help you pick the auditor when you're ready.
Yes. SOC 2 readiness is an option inside the audit, not the point of it. Most clients come to us because a customer asked a hard question, an insurer sent a form, or they simply don't know where they stand. The audit answers that on its own.
A fixed fee between $4,500 and $7,500, set on the first call based on the size of your codebase and surface area. There is no hourly meter: the number is agreed before any work starts and doesn't change mid-engagement.
It stays under our control. The review runs on our machines, and AI assistance goes through enterprise API agreements that do not train on your code. Access is read-only and revoked when the engagement ends, we retain nothing but the report we wrote for you, and we'll sign your NDA before seeing anything.
It changes the risk profile, not the process. If most of your code was written with Cursor, Claude Code, or Copilot, our AI-Built Product Security & Rescue Audit is the same engagement tuned for exactly that failure mode. Agency-built and inherited codebases fit this audit as-is: an independent read of code nobody on your side has reviewed is precisely the point.
Then the report says so, plainly. You get the same deliverable: what we checked, what held up, and the short list worth tightening anyway. A clean report is a fine outcome, and a useful one to show customers, insurers, and investors. We don't inflate severity to justify a fee.
You get a prioritized roadmap your team can execute on its own. If you'd rather have us fix it and run it, that's our fractional CTO engagement: we remediate the findings and take ongoing ownership of your technology.
Bring your product to a free 30-minute call. We'll tell you straight whether the audit is worth it for your stage, and put a fixed number on it if it is.
Book a Free 30-Min Call→