Full Web App Audit
Automated scanners can't log in, reason about permissions, or notice that one customer can read another customer's data. A manual audit can, and it covers what enterprise buyers' security questionnaires ask about.
- Price
- $900–1,800 CAD
- Turnaround
- 3–5 business days
What's included
A hands-on review of your web application, the way an attacker would approach it.
- OWASP Top 10 review
- Login, session and permission testing
- API checks
- Header and TLS review
- Dependency audit
- Prioritized report and walkthrough call
- Email Authentication Hardening included as a same-day quick win
How it runs
Start with what's public
A free finding or a Security Snapshot. It only looks at what anyone on the internet can already see, so no access or passwords are needed.
Talk it through
A short call in plain English: what each finding means for your business, and which ones actually matter this month.
Get the fix, not just the finding
Deeper testing only happens under a written scope agreement. Fixes arrive as pull requests your developer can review, DNS records ready to paste, or takedown reports already filed.
Keep watching
Look-alike sites come back under new domains and new email senders appear. A retainer keeps someone watching after the report is done.
Often requested by
Dental, physio and med-spa clinics
Under PHIPA you're accountable for patient information. Online booking tools, forgotten staging logins and outdated plugins are where it leaks.
Pre-seed and seed SaaS
An enterprise buyer's security questionnaire can stall a deal for weeks. A leaked API key or open staging environment is far cheaper to fix now than mid-deal.
Other services
Ask about Full Web App Audit
Say what you run and when you need it. You'll get a fixed quote within the published range before any work starts.