Skip to content

How it works

Four steps to one report card.

Everything that happens between your URL and your report card, in plain words. Sending the URL does not start a test. Your signature on the scope does.

Who
Founders and product leads before a launch or a relaunch. Teams that suspect the checkout, not the product.
When
Before a launch, or after a release that moved the numbers the wrong way. Before a redesign decision.
Where
Sign-up, onboarding and checkout, on the phones your users hold and the networks they are on. Read-only on production when the scope says so. Staging by default.

IllustrativeSample marks, not a client result.

Step 01 · Brief

You send a brief.

  • A URL
  • two sentences
  • no deck

A URL and two sentences about what worries you is enough. We reply with the questions the scope needs. No deck, no call, no form.

What you do
Email the URL, what the product does, and what worries you. Leave out passwords and keys.
What we do
We read it, ask the questions the scope needs, and send back a fixed quote. The number does not move once you accept it.
What you get
A fixed quote and a draft scope, both in writing.
How long
Two sentences on your side. No clock runs yet.

Step 02 · Scope & consent

We write the scope. You sign it.

  • Scope
  • consent
  • NDA
  • least access

The scope goes in writing: what we may touch, how hard, and when. Staging by default; read-only on production, and only when the scope says so. One-page consent, an NDA, your signature. Nothing starts before that.

What you do
Read the scope, strike anything we may not touch, and name the environment. Then the authorised owner signs.
What we do
We draft the scope: environment, allowed actions, stop conditions, access. We ask for the least access the test needs and agree how you share it. Credentials rotate the minute the test ends.
What you get
A written scope, a one-page consent and an NDA, all signed. The line where the test stops, in writing.
How long
As long as your review takes. Nothing runs until you sign.

Step 03 · The test

We test, security first.

  • People
  • real devices
  • controlled agents
  • a reviewer

Security first, because a miss there costs most. Then UI & UX, usability & performance, and conversion. People, real devices and controlled agents work the agreed scope; a senior reviewer confirms each finding by hand. Nothing runs outside it.

What you do
Keep shipping; we work inside the agreed window and environment. You can say stop at any point. We stop.
What we do
People test the journeys, devices test the breakage, agents cover the breadth — inside the approved scope, under human review. The card's security subject is a scoped security test with confirmed findings. Retest Cybersecurity is a separate contract: a deeper third-party test of the company, plus hands-on fix help. A senior reviewer confirms what makes the card.
  • Security
  • UI & UX
  • Usability & Performance
  • Conversion
What you get
Each finding, once confirmed, gets evidence, impact, priority and a fix plan written beside it. No raw scanner export.
How long
The test window is written in the scope. We stay inside it.

Step 04 · Report card

Your report card lands within 72 hours.

  • Four subjects
  • evidence
  • fix plans
  • signed

One card, four subjects, security first. Every finding comes with evidence, impact, priority and a fix plan, in plain language. A page you can hand to your team. A senior reviewer signs it.

What you do
You do not translate findings into tickets; the fix plan comes attached. Hand the card to your team.
What we do
We grade each subject and write every finding in plain language: what it is, why it matters, what to fix first. A senior reviewer strikes the false ones and signs the card.
What you get
A signed report card: a grade per subject, every finding with evidence, impact, priority and fix plan, and the open risks named. Not a PDF for the shared drive.
How long
Report card within 72 hours. The whole card, signed.

After the report

Fix. Retest. Compare.

Every finding carries a fix plan, so the card reads as a queue. Fix the top of it, then retest. A scan forgets the last run. A retest remembers it.

Fix plan

Each finding names the fix and where it sits in the queue. Your engineers can start Monday, not decode a PDF.

Retest

Book a retest once, or on a schedule you set. We run the tested scope again and mark what moved. Same card, next term.

What moved

The same four subjects every time, so one card reads against the last. Open risks stay on the card until they move.

Retest Cybersecurity

A separate contract, not included by default: a deeper third-party security test, then hands-on help with the fixes. Scoped in writing, with its own timeline and your written consent. Nothing starts until you sign.

About the security test

A written scope and a fixed quote, not a discovery phase and a day rate.

Questions

Three questions people ask here.

  • Will testing break production?

    Read-only by default; anything destructive runs on staging, with your written consent.

  • Do we need legal?

    A one-page consent and an NDA, signed by the authorised owner. Both before anyone touches anything.

  • Is it safe to give you access?

    Least access, shared the way you choose. Credentials rotated the minute the test ends. Nothing about your systems kept.

Next step

How an engagement starts.

  1. You send a brief — a URL and two sentences about what worries you.
  2. We send back a fixed quote. The number does not move once you accept it.
  3. We agree the scope in writing and you sign the consent. Nothing starts before that.
  4. We test, and your report card lands within 72 hours. Every finding in plain language, a fix plan attached.

Retest Cybersecurity contracts get their own timeline, in writing, before work starts.

Book a test

Tell us what needs testing.

A URL and two sentences is enough. The scope comes back in writing; nothing starts until you sign it.

Report card in 72 hoursNDA + written consentSigned by a senior reviewer