Scoped, fixed, and told to you up front.
Security work priced honestly. Every engagement starts with a written statement of work and a fixed figure, so the invoice at the end is the number we agreed at the start. No hourly surprises.
- One web application or website, external
- OWASP Top 10 and business-logic testing
- Authentication and access checks
- TLS, headers, and exposure review
- Prioritised report with CVSS scoring
- Authenticated multi-role testing
- Re-test included
- Web application, its API, and external infra
- Authenticated testing across user roles
- Full OWASP, PTES, and business-logic coverage
- Secrets, CORS, and configuration review
- Executive summary plus technical detail
- Remediation call with your engineers
- Re-test included to confirm fixes held
- Multiple applications and environments
- Internal network and cloud posture testing
- Programme or retainer, not just one round
- Compliance-aligned reporting for your auditors
- Named point of contact and priority scheduling
- Incident-response advisory available
- Re-tests and sign-off across the programme
Figures are indicative starting points for scoping, in euros, excluding any applicable taxes. Security work is priced to scope: the final figure depends on the size of your estate, the number of roles and environments, and the depth agreed. You receive a fixed written quote before any work begins, and we never bill above it without your sign-off. Prefer a different currency or a phased plan? We will arrange it on the scoping call.
What the figure already covers.
No line-item surprises. These are part of every engagement, not add-ons.
Written scope and NDA
A signed statement of work and confidentiality agreement before testing starts.
The full report
Executive summary and technical detail, with every finding scored and reproducible.
Remediation guidance
Clear, specific fixes and a call to walk your engineers through them.
Confidential handling
Your data and findings stay strictly between us, during and after the work.
Start with a free Site ID.
Not ready for a full engagement? Enter your domain and get an instant public posture snapshot: hosting, certificate, email security, exposed subdomains, and a grade. No login, no cost.
It is all public information, gathered in one place and scored. A useful first look before you decide what to test.
Run a free Site ID →Before you enquire.
Why isn't the exact price listed?+
Honest security pricing depends on scope. A five-page brochure site and a banking platform with fifty API endpoints are very different jobs. The figures above are realistic starting points; after a short scoping call we send a fixed written quote, and that is the number you pay.
How long does an engagement take?+
A Site Check is typically a few days. A Business Assessment usually runs one to two weeks including the report. Enterprise programmes are scheduled around your estate and change windows. We agree the timeline in writing before we start.
Is a re-test really included?+
On the Business Assessment and Enterprise engagements, yes. Once your team has applied the fixes, we return and verify each issue we asked you to close, then sign it off. A finding is not done until it is confirmed closed.
Will testing disrupt our live systems?+
Our default is non-destructive testing, agreed in the rules of engagement before we begin. Where a test carries any risk to a production system, we flag it, schedule it, and get your explicit sign-off first. Nothing happens outside the agreed scope.
Do you sign an NDA?+
Always, and before any technical detail is exchanged. Confidentiality is written into every engagement. What we learn about your systems stays strictly between us.
We are outside Seychelles. Can you still help?+
Yes. Most testing is performed remotely, so we work with clients across the Indian Ocean region and beyond. On-site work can be arranged where an engagement calls for it.
Get a fixed quote, not a guess.
Tell us what you want tested. We will scope it on a short call and send a written figure you can take to your board.