Fix plan
Each finding names the fix and where it sits in the queue. Your engineers can start Monday, not decode a PDF.
How it works
Everything that happens between your URL and your report card, in plain words. Sending the URL does not start a test. Your signature on the scope does.
https://yourapp.com
Nobody outside the team has tested the API. We launch soon.
A URL · two sentences
Found by agent · confirmed by hand
Signed by a senior reviewer
IllustrativeSample marks, not a client result.
Step 01 · Brief
A URL and two sentences about what worries you is enough. We reply with the questions the scope needs. No deck, no call, no form.
Step 02 · Scope & consent
The scope goes in writing: what we may touch, how hard, and when. Staging by default; read-only on production, and only when the scope says so. One-page consent, an NDA, your signature. Nothing starts before that.
Step 03 · The test
Security first, because a miss there costs most. Then UI & UX, usability & performance, and conversion. People, real devices and controlled agents work the agreed scope; a senior reviewer confirms each finding by hand. Nothing runs outside it.
Step 04 · Report card
One card, four subjects, security first. Every finding comes with evidence, impact, priority and a fix plan, in plain language. A page you can hand to your team. A senior reviewer signs it.
After the report
Every finding carries a fix plan, so the card reads as a queue. Fix the top of it, then retest. A scan forgets the last run. A retest remembers it.
Each finding names the fix and where it sits in the queue. Your engineers can start Monday, not decode a PDF.
Book a retest once, or on a schedule you set. We run the tested scope again and mark what moved. Same card, next term.
The same four subjects every time, so one card reads against the last. Open risks stay on the card until they move.
A separate contract, not included by default: a deeper third-party security test, then hands-on help with the fixes. Scoped in writing, with its own timeline and your written consent. Nothing starts until you sign.
About the security test →A written scope and a fixed quote, not a discovery phase and a day rate.
Questions
Read-only by default; anything destructive runs on staging, with your written consent.
A one-page consent and an NDA, signed by the authorised owner. Both before anyone touches anything.
Least access, shared the way you choose. Credentials rotated the minute the test ends. Nothing about your systems kept.
Next step
Retest Cybersecurity contracts get their own timeline, in writing, before work starts.
Book a test
A URL and two sentences is enough. The scope comes back in writing; nothing starts until you sign it.