Review

Security before the headline.

Five days. A report you can stand on. For SaaS founders, AI builders, and service businesses putting real data through a model or a site.

Price

Application security review

$500

AI risk assessment

$1,500

Who this is for

  • You added a chatbot to a site that handles client files.
  • You run a multi-tenant app and have never had isolation reviewed.
  • A partner, board, or client asked "are we actually secure?"
  • You are about to put PHI, financials, or congregational data near an LLM.

What I look at

Depends on the tier.

$500Application security

Multi-tenant isolation. OAuth flows. API surface. Authorization gaps. The class of bugs that makes headlines.

$1,500AI risk

Prompt injection. Data leaving through model responses. Unsafe tool wiring. Training-data and retention questions. Guardrails that exist on the slide and not in the code.

Both include a CISSP lens on the boring layer: headers, TLS, dependencies, data handling.

What you get

  • Written report.
  • Findings ranked by severity and exploitability.
  • Fix checklist in order.
  • MITRE ATT&CK mapping when it applies.
  • A 30-minute walkthrough call.

What you do not get

  • A fear pitch.
  • A 90-page PDF nobody reads.
  • A rebuild sold as the only fix.

If the honest answer is "patch these five things," that is the answer.

Timeline

  1. Day 1access, scope, threat sketch.
  2. Days 2 to 4review.
  3. Day 5report and walkthrough.

How to start

Send the URL or the repo context. We agree on tier before I begin.