Skip to content

Service

We fix the findings, and you re-scan to check that we did

A scan tells you what is wrong. That is only useful if somebody then changes the code, and the findings that matter most — a missing ownership check on an endpoint, a webhook that trusts anything that reaches it — are the ones least safe to guess at. We make the changes, explain each one, and hand you back something you can verify yourself rather than take on trust.

Get help fixing this

A person reads it and replies, usually within two working days.

What it costs

Quoted per engagement after we have read the findings, as a fixed price for a named set. There is no hourly rate and no rate card, because the work is not proportional to time: a missing ownership predicate can be a one-line change that took an hour to be sure about.

Who it suits

Three situations this is for

  • You have a scan with findings you do not want to guess at

    Access-control and payment findings are the two categories where a plausible-looking fix can leave the hole open. If you are not sure your change closed it, that uncertainty is the reason to hand it over.

  • You know what to do and have no time to do it

    Twelve medium findings across four services is a week you were going to spend on the product. The work is not hard; it is just work.

  • Somebody is waiting on an answer about security

    A customer's procurement questionnaire, an investor's diligence list, a client asking before go-live. We fix what is fixable and write down what was out of scope.

How it goes

The engagement, step by step

Written out because the thing people actually want to know before sending an enquiry is what happens next, and how easy it is to stop.
  1. You send us the scan

    Starting from a finding in the app attaches the project, the scan and the finding automatically. Starting from this page is fine too — we will ask which project it is.

    Nothing is billed for looking.

  2. We read it and quote a scope

    Usually within two working days. The quote names the findings we will fix, the ones we will not and why, and a fixed price for the set. If a finding turns out to need a change to how your product works rather than to your code, we say so at this point rather than after invoicing.

    The price is for the set of findings, not for time spent.

  3. We do the work against a branch

    Read-only access is enough for the scan, so remediation needs write access to a branch — granted for the engagement and revoked at the end. We never push to your default branch and never merge our own work.

  4. You re-scan and merge

    Run a scan against the branch before you merge it. If a finding we said we fixed is still reported, that is on us to resolve, not on you to argue about.

    A fix nobody verified is a fix nobody should trust — including ours.

What you end up with

  • A pull request per finding, or one branch grouped by area — your choice, and we ask before starting
  • A plain-language note on each change: what was wrong, what we did, and what to watch for
  • A re-scan of the same project so you can see which findings disappeared
  • A written list of anything we recommended against fixing, and why

Boundaries

What this does not include

Better to find the edge here than after an invoice.
  • We do not rewrite your application. If a finding can only be fixed by changing the architecture, we tell you that and stop, rather than starting a rebuild inside a remediation.
  • We do not take responsibility for findings we did not quote for, including ones a later scan turns up in code we never touched.
  • We do not merge our own work or deploy it. You keep both of those.
  • Fixing every finding does not make your application secure, and we will not write a letter saying it does.

Questions

About security remediation

Do you need write access to my repository?

Yes, for this service only, and only to a branch. Scanning is read-only; changing code is not. Access is granted for the engagement and you revoke it at the end — we will remind you to.

What if you cannot fix something?

We say so before quoting, and it stays out of the quote. The usual reason is that the finding is about a product decision rather than a coding mistake — who should be able to see a given record is a question about your business, and we would only be guessing.

Can you fix findings from a scanner that is not yours?

Usually. Send us the report. We may want to run our own scan alongside it, because we need the evidence a finding is based on rather than only its title, and not every tool includes it.

Send an enquiry

Get help fixing this

Enough detail that we can give you a real answer rather than ask for a call to find out what you meant.
No obligation, no automatic charge

Sending this does not commit you to anything and does not start any billing. You will get a confirmation with a reference straight away, and a reply from a person after that.

Incluye el prefijo del país, por ejemplo +34.

Opcional.

Opcional. Nos ayuda a revisar tu infraestructura previa.

Qué tienes, qué necesitas y los plazos previstos. Unas pocas frases son suficientes.

Opcional.

Un especialista lee cada solicitud. Recibirás una confirmación con número de referencia de inmediato y una respuesta técnica personalizada. No hay cargo automático.