How it works

From URL to certificate in 1 week.

No kickoff call, no agents to install, no firewall changes, no three-week wait for a PDF. Send us a URL and a test account; our engineers put the best testing tools we have on your app, then go through the results by hand. You get a score, a fix list, and a certificate you can show customers.

Process

Every AppCheck follows the same path.

Hand over a target, run the sweep, verify by hand, publish the certificate. Same path every time, so this quarter's score sits honestly next to last quarter's.

01

Hand over the target

You send us the URL of the app, a test account (or API key) that can exercise real user flows, and — if you want code-level findings — a Git URL for the source code.

We verify the scope, confirm the test account has the permissions we need, and sign a short DPA if you need one. Usually the same business day.

  • Targets verified via DNS TXT record
  • Test account scoped to the audit — never production admin
  • Read-only repo clone, deleted after the audit
  • DPA available on request
02

The sweep runs

The tools go over all ten areas — TLS, headers, cookies, auth, exposed endpoints, OWASP, dependencies, DNS, and API — against the live app, in minutes rather than days.

The sweep is read-only. The only writes are optional DNS TXT records used to verify ownership, which means no agents to install, no firewall changes, and no maintenance window to book.

  • 120+ checks across ten coverage areas
  • Runs against production or staging without an agent
  • Findings captured, never replayed against your system
  • Dependency and DNS data collected alongside the app surface
03

The team verifies

Everything the sweep returns is read by a security engineer. Findings are re-tested by hand, false positives are discarded, and severity is judged against what your app actually does.

If you shared source, this is where auth logic, input validation, secrets, and crypto get reviewed in the code itself — with file paths and line numbers in the report.

  • Every finding re-tested before it reaches your report
  • Severity ranked against your context, not a generic CVSS list
  • File paths and line numbers when source is available
  • Security team available for follow-up questions by email
04

Score, certificate, and share

The team finalises the 0-100 score, the band (Strong, Fair, At risk), and a ranked fix list. On approval, AppCheck mints an FPSEC certificate tied to your domain, score, and a timestamp.

Embed it in your trust centre, share it in deal rooms, or wire it to your compliance pipeline.

  • Tamper-evident public certificate URL
  • Optional PDF export for SOC 2 evidence
  • Embed badges in multiple formats
  • 2 free rescans and re-issued certificates within 3 months
FAQ

Common questions, answered plainly.

If you have a question that isn't here, we'd love to hear from you.

Is this automated, or do people actually look at my app?

Both, and that's the point. Tools do the sweep — ten areas, run in minutes, repeated identically every time. Our engineers do the rest: re-testing findings by hand, binning the false positives, and judging severity against your app's context. A scanner hands you 400 findings and wishes you luck. We hand you the twelve that matter, and how to fix them.

What access do you need?

At minimum, the URL of your app (production or staging): that's enough for the automated sweep to start. For a useful audit, add a test account with permissions to exercise real user flows. For code-level findings, share a read-only Git URL.

Is AppCheck safe to run against production?

Yes. The sweep is read-only and uses safe payload libraries. The only writes are optional DNS TXT records used to verify target ownership. All review is performed against the captured data, never against your live system.

How long does an audit take?

The sweep runs in minutes; the review is where the time goes, and it's where the value is. Most audits land within a week of confirming scope. Source-assisted audits can take a little longer depending on repo size.

What's the difference between AppCheck and a penetration test?

AppCheck covers the same ten areas every time and can be re-run as often as you ship. A pen test goes deeper over a longer window, at ten times the price. Most teams do both: a pen test once a year, AppCheck in between so your certificate stays current and regressions don't pile up.

How is the score calculated?

Each check has a severity weight and a pass/warn/fail outcome. Weights are calibrated against OWASP and CVSS, and the result is normalized to 0-100. The team can adjust a weight when your context justifies it, and says so in the report.

What happens to the source code after the audit?

We clone a read-only copy, run the static checks and manual review, then delete the clone within 30 days of certificate delivery. We don't share source code with anyone outside the review desk.

Send us the URL.

We come back within one business day with a confirmation, and the sweep starts straight after. Score and certificate in 1 week. €500 per audit, all-inclusive.