Service
We fix the findings, and you re-scan to check that we did
A scan tells you what is wrong. That is only useful if somebody then changes the code, and the findings that matter most — a missing ownership check on an endpoint, a webhook that trusts anything that reaches it — are the ones least safe to guess at. We make the changes, explain each one, and hand you back something you can verify yourself rather than take on trust.
A person reads it and replies, usually within two working days.
What it costs
Who it suits
Three situations this is for
You have a scan with findings you do not want to guess at
Access-control and payment findings are the two categories where a plausible-looking fix can leave the hole open. If you are not sure your change closed it, that uncertainty is the reason to hand it over.
You know what to do and have no time to do it
Twelve medium findings across four services is a week you were going to spend on the product. The work is not hard; it is just work.
Somebody is waiting on an answer about security
A customer's procurement questionnaire, an investor's diligence list, a client asking before go-live. We fix what is fixable and write down what was out of scope.
How it goes
The engagement, step by step
You send us the scan
Starting from a finding in the app attaches the project, the scan and the finding automatically. Starting from this page is fine too — we will ask which project it is.
Nothing is billed for looking.
We read it and quote a scope
Usually within two working days. The quote names the findings we will fix, the ones we will not and why, and a fixed price for the set. If a finding turns out to need a change to how your product works rather than to your code, we say so at this point rather than after invoicing.
The price is for the set of findings, not for time spent.
We do the work against a branch
Read-only access is enough for the scan, so remediation needs write access to a branch — granted for the engagement and revoked at the end. We never push to your default branch and never merge our own work.
You re-scan and merge
Run a scan against the branch before you merge it. If a finding we said we fixed is still reported, that is on us to resolve, not on you to argue about.
A fix nobody verified is a fix nobody should trust — including ours.
What you end up with
- A pull request per finding, or one branch grouped by area — your choice, and we ask before starting
- A plain-language note on each change: what was wrong, what we did, and what to watch for
- A re-scan of the same project so you can see which findings disappeared
- A written list of anything we recommended against fixing, and why
Boundaries
What this does not include
- We do not rewrite your application. If a finding can only be fixed by changing the architecture, we tell you that and stop, rather than starting a rebuild inside a remediation.
- We do not take responsibility for findings we did not quote for, including ones a later scan turns up in code we never touched.
- We do not merge our own work or deploy it. You keep both of those.
- Fixing every finding does not make your application secure, and we will not write a letter saying it does.
Questions
About security remediation
Do you need write access to my repository?
Yes, for this service only, and only to a branch. Scanning is read-only; changing code is not. Access is granted for the engagement and you revoke it at the end — we will remind you to.
What if you cannot fix something?
We say so before quoting, and it stays out of the quote. The usual reason is that the finding is about a product decision rather than a coding mistake — who should be able to see a given record is a question about your business, and we would only be guessing.
Can you fix findings from a scanner that is not yours?
Usually. Send us the report. We may want to run our own scan alongside it, because we need the evidence a finding is based on rather than only its title, and not every tool includes it.
Send an enquiry
Get help fixing this
Sending this does not commit you to anything and does not start any billing. You will get a confirmation with a reference straight away, and a reply from a person after that.