AppCheck — automated + manual security audit

Web app security audits, by a team that gives a damn.

Our security team reviews your app end-to-end. In days, not weeks, you get a 0-100 score, a fix list, and an FPSEC certificate you can share.

Sample AppCheck report
0
AppCheck score
Fair
app.example.com
audited 14 Mar 2026

Top findings

120+ checks · 10 areas
  • TLS 1.2+ enforcedPass
  • HSTS header presentPass
  • !Content-Security-PolicyWarning
  • Session cookie HttpOnlyPass
  • MFA enforcementFail
  • Exposed .env backupsFail
FPSEC certificate
app.example.com · score 68 · valid 360 days
What we need from you

Three things, in order of depth.

The more access you give us, the more useful the report. A URL is the minimum. A read-only repo unlocks the deepest review.

Required
01

URL

We need your production or staging URL — anything reachable over HTTPS.

Required
02

App access

A read-only test account (or API key) so we can exercise the authenticated flows: login, password reset, member areas, admin panels.

Optional
03

Source code

Optional but recommended. A read-only clone of the repo lets the security team review the parts a scanner can't see — auth logic, business rules, input validation.

What AppCheck covers

Ten coverage areas. One score.

Every AppCheck runs the same coverage matrix — so a 78 in one app means the same thing as a 78 in another.

TLS & certificates

Protocol version, chain trust, expiry, HSTS, OCSP stapling, and downgrade resistance.

Security headers

CSP, X-Frame-Options, HSTS, Referrer-Policy, Permissions-Policy, COOP/COEP.

Cookies & sessions

Secure, HttpOnly, SameSite, scope, and rotation behaviour across your auth flow.

Authentication & MFA

MFA availability, password policy, lockout, credential stuffing exposure (HIBP).

Exposed endpoints

Admin panels, debug pages, .git, .env backups, swagger, phpinfo, and more.

OWASP Top 10

Probes for SQLi, XSS, SSRF, command injection, IDOR/BOLA, and broken access control.

Dependency risk

Known CVEs, outdated packages, suspicious post-install scripts, license flags.

DNS & email

SPF, DKIM, DMARC, CAA, DNSSEC, MX hygiene to protect your domains from spoofing.

API security

JWT handling, rate limiting, CORS posture, schema validation, BOLA heuristics.

Source-code review

When you share the repo, the security team reviews auth, input validation, crypto, and secrets handling.

Why teams use AppCheck

Audit-grade results without the audit-grade price.

AppCheck is the fastest way to validate your external security posture between pen tests — and the easiest way to prove it to the people who ask.

Score, not surprises

A clear 0-100 score with grade bands (Strong / Fair / At risk) that maps to remediation effort, not raw CVE counts.

A team that knows your stack

Our security team reviews your app end-to-end — supported by AI-native automation, but with a human verifying every finding and writing the report in plain language.

Certificate your posture

Share a tamper-evident FPSEC certificate valid for 360 days — with 2 free rescans and re-issued certificates within 3 months.

Source-aware when you allow it

Share a read-only repo clone and the team reviews auth, input validation, secrets, and crypto in the actual code, not just the running surface.

Actionable fixes

Every failing check comes with the exact header, flag, config change, or code path you need to fix, with links to the relevant standard.

Made for SaaS

Designed for hosted multi-tenant apps: auth flows, public APIs, marketing sites, and admin consoles.

How it works

From access granted to certificate in days, not weeks.

Send us the URL, a test account, and (optionally) a repo. We do the rest.

  1. 01

    Grant access

    Send the URL, a read-only test account, and a Git URL for the source (optional). We confirm scope the same business day.

  2. 02

    We audit

    The security team runs the audit with AI-native automation in support — 120+ checks across TLS, headers, cookies, auth, exposed endpoints, OWASP, dependencies, DNS, API, and your source.

  3. 03

    We verify

    Every finding is reviewed by a human, business context is added, and the report is written in plain language.

  4. 04

    Score & certificate

    You receive the 0-100 score, the prioritised fix list, the team's narrative, and the FPSEC certificate — usually within 1-2 business days.

Scorecard

What your score actually means.

AppCheck grades use calibrated bands that align to common procurement and compliance thresholds.

BandScoreMeaningSuggested action
Strong80-100Posture meets modern SaaS expectations.Embed the certificate in your trust centre; renew after 360 days.
Fair60-79Generally OK with gaps; expect follow-up questions in procurement.Fix all 'fail' findings, then use one of your 2 free rescans for a fresh certificate.
At risk0-59Material weaknesses visible to anyone scanning your domain.Block releases; use your free rescans as you ship each fix.

Ready for your AppCheck?

Send us the URL, app access, and (if you can) your source. We confirm the same day, deliver the score and certificate in days, not weeks. €500 per audit.