Pricing

Three ways to check — one that matters most.

The Automated audit tests your public surfaces only and stops at your login screen. The Fully Managed audit goes past it, testing what a logged-in user can reach — an employee, a customer, a competitor who signed up — which is where the serious leaks happen. The Custom Platform Assessment covers several products at once.

Everything behind your login screenRecommended

Fully Managed Security Audit

$59,950per platform — e.g. your agent portal, client portal, and the CRM behind them

A cybersecurity expert tests your entire system by hand — going past the login screen into the private, logged-in areas where the worst leaks hide. This is the deep one: we test what your own users, customers, and employees can actually reach.

  • Everything in the Automated audit, plus the full test of everything behind your login
  • Whether a free or trial user can quietly turn themselves into an administrator
  • Whether one paying customer can open another customer’s account and records
  • Whether an ordinary user can delete or destroy your application’s data
  • Whether one user can harm another — changing their details, locking them out, or acting as them
  • Whether a user can walk out with financial records, Social Security numbers, or health information
  • Fully manual, expert-overseen testing from start to finish
  • Guidance on the possible ways to close each gap, plus up to 4 hours of calls with your technical team
  • Our own step-by-step retest checklist, so your team can confirm for themselves that a fix worked
  • Full compliance mapping and an executive summary for your board or carrier
  • We never do the fixing ourselves — we show your team the possible paths to close each gap, and we can refer you to people who do that work
80% money-back guarantee

Typically two to four weeks. Backed by our money-back guarantee below. Your Automated fee (if you ran one) credits toward this, and you can add a retest for $5,995 — up to three within a year of signing.

Public surfaces only — it stops at your login screen

Automated Security Audit

$7,995per platform · nothing behind the login

A fast, expert-reviewed check of everything a stranger can reach before anyone logs in. An affordable first look that deliberately stops at your login screen.

  • Privacy leaks on your checkout and payment pages — where tracking tools quietly hand customers’ private details to advertisers. The FTC has brought enforcement actions and levied fines over exactly this kind of leak.
  • Whether pages and files that are supposed to require a login can be opened by someone with no account at all — we test from the outside, never with one of your logins
  • Your sign-up and account-creation flows, and how someone could abuse them to get in
  • Passwords and access keys accidentally left exposed in your website’s code, where anyone could find them
  • Your public website and email security — including whether scammers could impersonate your company
  • Every issue rated by how serious it is, in plain English
  • A one-hour call with a cybersecurity expert to walk you through what we found, and a dated summary of what was and wasn’t tested
  • Anything that requires logging in. We only test what an outsider with no account can reach — this audit cannot tell you what a logged-in user, customer, or employee can reach.
  • The “who can see what” testing where the 70,000-record leaks live — that’s the Fully Managed audit
  • Guidance on how to close what we find, up to 4 hours of calls with your technical team, or our retest checklist — those come with the Fully Managed audit

Results in about a week. Public surfaces only — it stops at your login screen. Your fee counts toward the Fully Managed audit if you upgrade within 12 months.

Several products, one coordinated plan

Custom Platform Assessment

Custompriced per scope, after a discovery call

For companies running more than one product, or several platforms that need testing together. We scope everything you run, test it as one, and hand your team one prioritized list — highest-risk system first, with the possible paths to close each gap.

  • Multiple products or platforms assessed together, not as separate one-off audits
  • A scope built around your business — sequenced so the highest-risk system goes first
  • A prioritized action list: which gaps to close first, the possible paths for closing each one, and our retest checklist so your team can confirm its own fixes worked
  • Working sessions with your technical leads across every product in scope
  • One combined view of risk across every product you run — for your board or carrier
  • We never do the fixing ourselves — the list is built for your team, or a partner we can refer you to, to work through

Scoped with you on a short discovery call, then quoted as a fixed price. Guarantee terms, if any, are agreed in writing as part of that scope.

Who you’re trusting

A security firm you can actually vet.

For a job this sensitive, who does the work matters as much as what they find. Here’s exactly who you’re handing the keys to.

You get the founders — not a junior

Both founders do the testing themselves, from your first call to your final report. Your account is never handed to a junior or a subcontractor.

Authorized and insured

Every engagement is authorized in writing, and we carry professional liability insurance — so bringing us in protects you, it doesn’t expose you.

We sign a BAA

Giving a security firm access to systems full of health and personal data is a real decision. We’re glad to sign a Business Associate Agreement before any testing begins.

Your data stays in the US

All test-login access and any client data stays in the United States, under strict controls — and we prove problems without ever pulling a real client’s record.

Side by side

What each package includes.

The difference isn’t how hard we work — it’s how far in we test. The Automated audit stops at your login screen. Only the Fully Managed audit goes past it, where the serious leaks live.

What each audit package includes, compared across the Automated, Fully Managed, and Custom Platform tiers.
What we testAutomated — $7,995Fully Managed — $59,950Custom Platform — quoted
Tests everything behind your login (the “who can see what” testing)
Tests what a stranger can reach without logging in (pages, sign-up forms, public files)
Privacy leaks on checkout & payment pages
Leaked passwords & access keys in your site’s code
Can a free user make themselves an administrator?
Can one customer open another customer’s records?
Can a user delete your data, or harm another user?
Can a user steal financial, Social Security, or health information?
One-hour consult with a cybersecurity expert
Fully manual, expert-overseen testing
Guidance on possible ways to close each gapCustom plan
Calls with your technical teamUp to 4 hoursScoped
Our retest checklist, so your team can verify their own fixes
Multiple products assessed together
Compliance mapping (HIPAA, SOC 2, and more)Public-surface snapshotFull mapping + exec summaryAcross every product
Typical turnaround~1 week2–4 weeksScoped with you
80% money-back guaranteeBy agreement
Optional retest ($5,995, up to 3 within a year)Priced in your scope
What a breach could cost

Put the price in perspective.

Enter how many people’s records your software holds. Using industry-average breach costs, here’s a rough sense of what’s at stake — right next to the audit that helps prevent it.

25,000

Estimated exposure if breached

$3.8M$5.0M

Roughly 63× the cost of the full audit that helps prevent it.

Potential breach exposure$3.8M+
The full audit$59,950

A rough, conservative estimate anchored to IBM’s 2025 Cost of a Data Breach figure of about $160 per record (all-in: response, notification, and lost business). Per-record costs fall for very large breaches, so this is most accurate up to ~100,000 records. For comparison, real legal settlements alone for breaches this size have run six to seven figures — a ~39,000-record health breach recently settled for $1.1M.

80% money-back guarantee

You only pay in full if we find something serious.

We put our own fee on the line that your logged-in access has gaps. Run the Fully Managed audit and if we find nothing serious, you get 80% of your money back — the other 20% covers the expert time it took to prove it. In this industry, a clean result is the exception.

Applies to the Fully Managed audit only. “Serious” means any confirmed High or Critical issue, scored on the standard industry severity scale — the exact threshold is agreed in writing before we begin. If the result is clean, we simply waive your final payment and refund anything you’ve paid above the 20%; you don’t have to pay in full first. Findings we rate Medium or below don’t, on their own, affect the guarantee. It does depend on you giving us the agreed access, so we can actually complete the audit.

What we need from you

A short, safe kickoff.

Most audits take two to four weeks from start to final report, depending on the size of your system.

  • A couple of test logins we can use — so we never touch real client information
  • A quick okay in writing that we’re allowed to test your system
  • Optional: a look at how your software is built, which lets us dig even deeper
Questions

Frequently asked.

What’s the difference between the Automated and Fully Managed audit?

The Automated audit tests your public surfaces only — everything a stranger can reach before anyone logs in, including your checkout pages, sign-up flows, exposed passwords and keys, and public website security. It deliberately stops at your login screen. The Fully Managed audit goes past that screen and tests everything behind your login: whether a free user can make themselves an administrator, whether one customer can open another’s records, whether someone can delete your data or walk out with Social Security numbers and health information.

How does the money-back guarantee work?

It applies to the Fully Managed audit: if we test the full system and find nothing serious — no confirmed High or Critical issue on the standard industry severity scale — you keep 80% of your fee. You don’t have to pay in full first: we simply waive your final payment and refund anything you’ve paid above the 20%. The 20% covers the expert time it took to prove the result. If we do find something serious, you pay in full and get the findings and the possible paths to close them. The exact threshold is agreed in writing before we start, and the guarantee depends on you giving us the access we agreed on.

Which package should I choose?

If you handle regulated client data — Social Security numbers, health details, bank info — choose the Fully Managed audit; it’s the only one that tests what a logged-in user can reach, which is where the serious breaches happen. The Automated audit is a smart, affordable first look at your public surfaces, and its fee counts toward the full audit if you upgrade. If you run several products or platforms, the Custom Platform Assessment covers them together with one prioritized plan.

Do you fix the problems you find?

No — and we’re upfront about that. We show your team the possible paths to close each gap and spend up to four hours walking them through every finding, so they fully understand the problem and their options. We also hand over our own step-by-step retest checklist so your team can confirm for themselves that a fix actually worked. We never do the fixing ourselves, and we can’t guarantee that someone else’s fix will resolve an issue. If you want hands-on help, we’re glad to refer you to people who do that work.

Can you re-check our system after we fix things?

Yes, on the Fully Managed and Custom engagements. A retest is $5,995 and confirms whether the specific issues we found appear resolved. You can run up to three retests at that price within twelve months of signing. The Automated audit doesn’t include retests.

We run several different products — how does that work?

That’s the Custom Platform Assessment. One audit fee covers a single platform — all the connected software your team runs as one system, like an admin portal, a client portal, and the CRM behind them. If you sell separate products to different customers, we scope them together and test everything you run as one engagement, then hand your team a prioritized list that sequences the highest-risk system first. It’s quoted per scope after a short discovery call.

Will your testing put our clients’ data at risk?

No. We prove a problem exists without ever opening a real person’s record, and we never change or delete anything in your live system. Protecting your clients’ information is the whole point — we won’t put it at risk to test it.

Why do we need this if we’ve never had a problem?

Most of these weaknesses are invisible until someone finds them — and by the time a client or regulator notices, the damage is already done. An audit finds them while they’re still quiet, private, and inexpensive to fix.

Our software is from a vendor — is it even our responsibility?

Yes — and it catches a lot of teams off guard. If a breach happens in software you license, it’s still your clients’ data, your reportable breach, and your standing with the carriers on the line; the vendor rarely carries that for you. We test what your agreement allows — usually your own accounts and settings — and help you get authorization to check the rest. Where a vendor’s core system is off-limits, we tell you plainly what we could and couldn’t test.

How long does it take?

The Automated audit takes about a week. The Fully Managed audit typically takes two to four weeks from start to final report, depending on the size of your system.

Do you need to understand how our software was built?

Not up front. We start from the outside with no inside knowledge — the same position an intruder would be in — and figure it out as we go. If you can share how it’s built, we can dig even deeper.

Is this the same as being HIPAA or SOC 2 certified?

No. Our audit shows how well your security lines up with those rules and gives you a big head start, but it isn’t the official certification itself — it works alongside it.

Will you sign an NDA?

Yes. We’re glad to work under your confidentiality agreement and agree on the ground rules before any testing begins.

Not sure which one you need?

Book a short call and we’ll help you scope the right audit for your business — in plain English.