AppCheck€500 flat1 week turnaroundCertificate valid 360 days

Web app security audits, by a team that gives a damn.

We're security engineers who break into apps for a living. We go through yours the way an attacker would — logins, permissions, APIs, admin panels — and tell you straight what is exposed, what to fix first, and what can wait. Then you get a 0-100 score, a prioritised fix list, and a verifiable certificate.

No agents to install, no firewall changes, no kickoff call.

AppCheck reportFPSEC-A12B4C7-9F3E2
0
AppCheck score
Fair
app.example.com
audited 14 Mar 2026

Top findings

120+ checks · 10 areas
  • ✓TLS 1.2+ enforcedPass
  • ✓HSTS header presentPass
  • !Content-Security-PolicyWarning
  • ✓Session cookie HttpOnlyPass
  • ✕MFA enforcementFail
  • ✕Exposed .env backupsFail
FPSEC certificate
app.example.com · score 68 · valid 360 days
What we need from you

A URL, a test account, and — if you can — the code.

A URL gets you the outside. A test account gets you the flows your users actually touch. Source access gets you the bugs that never make it to production.

Required
01

URL

The app you want audited — production or staging, anything reachable over HTTPS. Nothing to install, nothing to whitelist: this is all the sweep needs to start.

Required
02

App access

A test account (or API key) with permissions to exercise the authenticated flows: login, password reset, member areas, admin panels. This is what separates an audit from a scan.

Optional
03

Source code

Optional but recommended. A read-only clone of the repo lets us read what a scanner never sees — auth logic, business rules, input validation — and point at the exact file and line.

What AppCheck covers

Ten coverage areas. One score.

Same matrix every time, every result read by an engineer. A 78 in your app means what a 78 means anywhere else — which is the point when a buyer asks.

TLS & certificates

Protocol version, chain trust, expiry, HSTS, OCSP stapling, and downgrade resistance.

Security headers

CSP, X-Frame-Options, HSTS, Referrer-Policy, Permissions-Policy, COOP/COEP.

Cookies & sessions

Secure, HttpOnly, SameSite, scope, and rotation behaviour across your auth flow.

Authentication & MFA

MFA availability, password policy, lockout, credential stuffing exposure (HIBP).

Exposed endpoints

Admin panels, debug pages, .git, .env backups, swagger, phpinfo, and more.

OWASP Top 10 & injection

Active probes for SQL injection, XSS, SSRF, OS command injection, IDOR / BOLA, and broken access control.

Dependency risk

Known CVEs, outdated packages, suspicious post-install scripts, license flags.

DNS & email

SPF, DKIM, DMARC, CAA, DNSSEC, MX hygiene to protect your domains from spoofing.

API security

JWT handling, rate limiting, CORS posture, schema validation, BOLA heuristics.

Source-code review

When you share the repo, the security team reviews auth, input validation, crypto, and secrets handling.

Why teams use AppCheck

People who know what they're looking at.

Anyone can run a scanner. Working out what's actually exploitable in your app — and what to fix before Friday — is the part that takes years. That's what you're paying for.

Nothing gets skipped

The same ten areas get covered every time — TLS, headers, cookies, auth, exposed endpoints, OWASP, dependencies, DNS, and API. Tools that never get bored, run by engineers who don't cut corners.

A human reads every result

Scanners bury you in noise. Our engineers re-test findings by hand, bin the false positives, and tell you which ones actually threaten your business.

One number your buyers understand

A 0-100 score with grades that map to remediation effort — the thing you paste into a security questionnaire instead of writing another essay.

Works on any app you host

SaaS product, marketing site, dashboard, admin console, public API. If it's reachable on the internet, we can audit it.

Fixes your engineers can ship today

Every failure comes with the exact header, flag, config line, or code path — plus the standard it violates, for the auditor who asks.

Proof you can show customers

A tamper-evident FPSEC certificate, valid for 360 days, with 2 free rescans to keep it current as you ship.

How it works

From URL to certificate in 1 week.

Four steps. No kickoff calls, no procurement dance, no three-week wait.

  1. 01

    Hand over the target

    Send the URL, a test account that can exercise real user flows, and a Git URL if you want code-level findings. Scope is confirmed the same business day.

  2. 02

    The sweep runs

    The tools go over all ten areas in minutes — TLS, headers, cookies, auth, exposed endpoints, OWASP, dependencies, DNS, and API.

  3. 03

    The team verifies

    Our engineers re-test what matters, bin the noise, and write it up in plain language with the fix attached.

  4. 04

    Score & certificate

    Score, prioritised fix list, and your FPSEC certificate — usually inside 1 week.

Scorecard

What your score actually means.

Calibrated so the number means the same thing to you, your buyer, and your auditor.

BandScoreMeaningSuggested action
Strong80-100You'd pass a security review today.Put the certificate on your trust page, renew at 360 days.
Fair60-79You'll pass, with follow-up questions you'd rather not get.Clear the fails, then spend a free rescan on a fresh certificate.
At risk0-59Anyone scanning your domain can see the gaps — so can a buyer.Fix before your next release; spend a rescan as each fix ships.

Send us a URL. We'll do the rest.

Score, fix list, and certificate back in 1 week — €500 flat, invoiced on delivery.