Three ways to check — one that matters most.
The Automated audit tests your public surfaces only and stops at your login screen. The Fully Managed audit goes past it, testing what a logged-in user can reach — an employee, a customer, a competitor who signed up — which is where the serious leaks happen. The Custom Platform Assessment covers several products at once.
Fully Managed Security Audit
A cybersecurity expert tests your entire system by hand — going past the login screen into the private, logged-in areas where the worst leaks hide. This is the deep one: we test what your own users, customers, and employees can actually reach.
- Everything in the Automated audit, plus the full test of everything behind your login
- Whether a free or trial user can quietly turn themselves into an administrator
- Whether one paying customer can open another customer’s account and records
- Whether an ordinary user can delete or destroy your application’s data
- Whether one user can harm another — changing their details, locking them out, or acting as them
- Whether a user can walk out with financial records, Social Security numbers, or health information
- Fully manual, expert-overseen testing from start to finish
- Guidance on the possible ways to close each gap, plus up to 4 hours of calls with your technical team
- Our own step-by-step retest checklist, so your team can confirm for themselves that a fix worked
- Full compliance mapping and an executive summary for your board or carrier
- We never do the fixing ourselves — we show your team the possible paths to close each gap, and we can refer you to people who do that work
Typically two to four weeks. Backed by our money-back guarantee below. Your Automated fee (if you ran one) credits toward this, and you can add a retest for $5,995 — up to three within a year of signing.
Automated Security Audit
A fast, expert-reviewed check of everything a stranger can reach before anyone logs in. An affordable first look that deliberately stops at your login screen.
- Privacy leaks on your checkout and payment pages — where tracking tools quietly hand customers’ private details to advertisers. The FTC has brought enforcement actions and levied fines over exactly this kind of leak.
- Whether pages and files that are supposed to require a login can be opened by someone with no account at all — we test from the outside, never with one of your logins
- Your sign-up and account-creation flows, and how someone could abuse them to get in
- Passwords and access keys accidentally left exposed in your website’s code, where anyone could find them
- Your public website and email security — including whether scammers could impersonate your company
- Every issue rated by how serious it is, in plain English
- A one-hour call with a cybersecurity expert to walk you through what we found, and a dated summary of what was and wasn’t tested
- Anything that requires logging in. We only test what an outsider with no account can reach — this audit cannot tell you what a logged-in user, customer, or employee can reach.
- The “who can see what” testing where the 70,000-record leaks live — that’s the Fully Managed audit
- Guidance on how to close what we find, up to 4 hours of calls with your technical team, or our retest checklist — those come with the Fully Managed audit
Results in about a week. Public surfaces only — it stops at your login screen. Your fee counts toward the Fully Managed audit if you upgrade within 12 months.
Custom Platform Assessment
For companies running more than one product, or several platforms that need testing together. We scope everything you run, test it as one, and hand your team one prioritized list — highest-risk system first, with the possible paths to close each gap.
- Multiple products or platforms assessed together, not as separate one-off audits
- A scope built around your business — sequenced so the highest-risk system goes first
- A prioritized action list: which gaps to close first, the possible paths for closing each one, and our retest checklist so your team can confirm its own fixes worked
- Working sessions with your technical leads across every product in scope
- One combined view of risk across every product you run — for your board or carrier
- We never do the fixing ourselves — the list is built for your team, or a partner we can refer you to, to work through
Scoped with you on a short discovery call, then quoted as a fixed price. Guarantee terms, if any, are agreed in writing as part of that scope.
A security firm you can actually vet.
For a job this sensitive, who does the work matters as much as what they find. Here’s exactly who you’re handing the keys to.
You get the founders — not a junior
Both founders do the testing themselves, from your first call to your final report. Your account is never handed to a junior or a subcontractor.
Authorized and insured
Every engagement is authorized in writing, and we carry professional liability insurance — so bringing us in protects you, it doesn’t expose you.
We sign a BAA
Giving a security firm access to systems full of health and personal data is a real decision. We’re glad to sign a Business Associate Agreement before any testing begins.
Your data stays in the US
All test-login access and any client data stays in the United States, under strict controls — and we prove problems without ever pulling a real client’s record.
What each package includes.
The difference isn’t how hard we work — it’s how far in we test. The Automated audit stops at your login screen. Only the Fully Managed audit goes past it, where the serious leaks live.
| What we test | Automated — $7,995 | Fully Managed — $59,950 | Custom Platform — quoted |
|---|---|---|---|
| Tests everything behind your login (the “who can see what” testing) | |||
| Tests what a stranger can reach without logging in (pages, sign-up forms, public files) | |||
| Privacy leaks on checkout & payment pages | |||
| Leaked passwords & access keys in your site’s code | |||
| Can a free user make themselves an administrator? | |||
| Can one customer open another customer’s records? | |||
| Can a user delete your data, or harm another user? | |||
| Can a user steal financial, Social Security, or health information? | |||
| One-hour consult with a cybersecurity expert | |||
| Fully manual, expert-overseen testing | |||
| Guidance on possible ways to close each gap | Custom plan | ||
| Calls with your technical team | Up to 4 hours | Scoped | |
| Our retest checklist, so your team can verify their own fixes | |||
| Multiple products assessed together | |||
| Compliance mapping (HIPAA, SOC 2, and more) | Public-surface snapshot | Full mapping + exec summary | Across every product |
| Typical turnaround | ~1 week | 2–4 weeks | Scoped with you |
| 80% money-back guarantee | By agreement | ||
| Optional retest ($5,995, up to 3 within a year) | Priced in your scope |
Put the price in perspective.
Enter how many people’s records your software holds. Using industry-average breach costs, here’s a rough sense of what’s at stake — right next to the audit that helps prevent it.
Estimated exposure if breached
$3.8M – $5.0M
Roughly 63× the cost of the full audit that helps prevent it.
A rough, conservative estimate anchored to IBM’s 2025 Cost of a Data Breach figure of about $160 per record (all-in: response, notification, and lost business). Per-record costs fall for very large breaches, so this is most accurate up to ~100,000 records. For comparison, real legal settlements alone for breaches this size have run six to seven figures — a ~39,000-record health breach recently settled for $1.1M.
You only pay in full if we find something serious.
We put our own fee on the line that your logged-in access has gaps. Run the Fully Managed audit and if we find nothing serious, you get 80% of your money back — the other 20% covers the expert time it took to prove it. In this industry, a clean result is the exception.
Applies to the Fully Managed audit only. “Serious” means any confirmed High or Critical issue, scored on the standard industry severity scale — the exact threshold is agreed in writing before we begin. If the result is clean, we simply waive your final payment and refund anything you’ve paid above the 20%; you don’t have to pay in full first. Findings we rate Medium or below don’t, on their own, affect the guarantee. It does depend on you giving us the agreed access, so we can actually complete the audit.
A short, safe kickoff.
Most audits take two to four weeks from start to final report, depending on the size of your system.
- A couple of test logins we can use — so we never touch real client information
- A quick okay in writing that we’re allowed to test your system
- Optional: a look at how your software is built, which lets us dig even deeper
Frequently asked.
What’s the difference between the Automated and Fully Managed audit?
The Automated audit tests your public surfaces only — everything a stranger can reach before anyone logs in, including your checkout pages, sign-up flows, exposed passwords and keys, and public website security. It deliberately stops at your login screen. The Fully Managed audit goes past that screen and tests everything behind your login: whether a free user can make themselves an administrator, whether one customer can open another’s records, whether someone can delete your data or walk out with Social Security numbers and health information.
How does the money-back guarantee work?
It applies to the Fully Managed audit: if we test the full system and find nothing serious — no confirmed High or Critical issue on the standard industry severity scale — you keep 80% of your fee. You don’t have to pay in full first: we simply waive your final payment and refund anything you’ve paid above the 20%. The 20% covers the expert time it took to prove the result. If we do find something serious, you pay in full and get the findings and the possible paths to close them. The exact threshold is agreed in writing before we start, and the guarantee depends on you giving us the access we agreed on.
Which package should I choose?
If you handle regulated client data — Social Security numbers, health details, bank info — choose the Fully Managed audit; it’s the only one that tests what a logged-in user can reach, which is where the serious breaches happen. The Automated audit is a smart, affordable first look at your public surfaces, and its fee counts toward the full audit if you upgrade. If you run several products or platforms, the Custom Platform Assessment covers them together with one prioritized plan.
Do you fix the problems you find?
No — and we’re upfront about that. We show your team the possible paths to close each gap and spend up to four hours walking them through every finding, so they fully understand the problem and their options. We also hand over our own step-by-step retest checklist so your team can confirm for themselves that a fix actually worked. We never do the fixing ourselves, and we can’t guarantee that someone else’s fix will resolve an issue. If you want hands-on help, we’re glad to refer you to people who do that work.
Can you re-check our system after we fix things?
Yes, on the Fully Managed and Custom engagements. A retest is $5,995 and confirms whether the specific issues we found appear resolved. You can run up to three retests at that price within twelve months of signing. The Automated audit doesn’t include retests.
We run several different products — how does that work?
That’s the Custom Platform Assessment. One audit fee covers a single platform — all the connected software your team runs as one system, like an admin portal, a client portal, and the CRM behind them. If you sell separate products to different customers, we scope them together and test everything you run as one engagement, then hand your team a prioritized list that sequences the highest-risk system first. It’s quoted per scope after a short discovery call.
Will your testing put our clients’ data at risk?
No. We prove a problem exists without ever opening a real person’s record, and we never change or delete anything in your live system. Protecting your clients’ information is the whole point — we won’t put it at risk to test it.
Why do we need this if we’ve never had a problem?
Most of these weaknesses are invisible until someone finds them — and by the time a client or regulator notices, the damage is already done. An audit finds them while they’re still quiet, private, and inexpensive to fix.
Our software is from a vendor — is it even our responsibility?
Yes — and it catches a lot of teams off guard. If a breach happens in software you license, it’s still your clients’ data, your reportable breach, and your standing with the carriers on the line; the vendor rarely carries that for you. We test what your agreement allows — usually your own accounts and settings — and help you get authorization to check the rest. Where a vendor’s core system is off-limits, we tell you plainly what we could and couldn’t test.
How long does it take?
The Automated audit takes about a week. The Fully Managed audit typically takes two to four weeks from start to final report, depending on the size of your system.
Do you need to understand how our software was built?
Not up front. We start from the outside with no inside knowledge — the same position an intruder would be in — and figure it out as we go. If you can share how it’s built, we can dig even deeper.
Is this the same as being HIPAA or SOC 2 certified?
No. Our audit shows how well your security lines up with those rules and gives you a big head start, but it isn’t the official certification itself — it works alongside it.
Will you sign an NDA?
Yes. We’re glad to work under your confidentiality agreement and agree on the ground rules before any testing begins.
Not sure which one you need?
Book a short call and we’ll help you scope the right audit for your business — in plain English.