Review
Security before the headline.
Five days. A report you can stand on. For SaaS founders, AI builders, and service businesses putting real data through a model or a site.
Price
Application security review
$500
AI risk assessment
$1,500
Who this is for
- You added a chatbot to a site that handles client files.
- You run a multi-tenant app and have never had isolation reviewed.
- A partner, board, or client asked "are we actually secure?"
- You are about to put PHI, financials, or congregational data near an LLM.
What I look at
Depends on the tier.
$500Application security
Multi-tenant isolation. OAuth flows. API surface. Authorization gaps. The class of bugs that makes headlines.
$1,500AI risk
Prompt injection. Data leaving through model responses. Unsafe tool wiring. Training-data and retention questions. Guardrails that exist on the slide and not in the code.
Both include a CISSP lens on the boring layer: headers, TLS, dependencies, data handling.
What you get
- Written report.
- Findings ranked by severity and exploitability.
- Fix checklist in order.
- MITRE ATT&CK mapping when it applies.
- A 30-minute walkthrough call.
What you do not get
- A fear pitch.
- A 90-page PDF nobody reads.
- A rebuild sold as the only fix.
If the honest answer is "patch these five things," that is the answer.
Timeline
- Day 1access, scope, threat sketch.
- Days 2 to 4review.
- Day 5report and walkthrough.
How to start
Send the URL or the repo context. We agree on tier before I begin.