How it works

From access granted to certificate in four steps.

Send us the URL, a read-only test account, and (ideally) a repo. We do the rest — automated checks, manual review, source review, score, certificate. No agents, no firewall changes, no waiting a week for a PDF.

Process

Every AppCheck follows the same path.

Authorize a target, run the check groups, score the result, and publish the certificate.

01

Grant access

You send us the URL of the app, a read-only test account (or API key), and — if you can — a Git URL for the source code.

We verify the scope, confirm the test account has limited permissions, and sign a short DPA if you need one.

  • Targets verified via DNS TXT record
  • Read-only accounts only — never service / admin
  • Read-only repo clone, deleted after the audit
  • DPA available on request
02

We audit

The security team runs the audit end-to-end with AI-native automation in support — covering TLS, headers, cookies, auth, exposed endpoints, OWASP, dependencies, DNS, API, and (if source provided) the actual code.

The audit is read-only. The only writes are optional DNS TXT records used to verify ownership.

  • AI-native automation in support of the team
  • All payloads redacted before they reach the report
  • Findings include file paths and line numbers when source is available
  • Security team available for follow-up questions by email
03

Score, certificate, and share

The team finalises the 0-100 score, the band (Strong, Fair, At risk), and a ranked fix list. On approval, AppCheck mints an FPSEC certificate tied to your domain, score, and a timestamp.

Embed it in your trust centre, share it in deal rooms, or wire it to your compliance pipeline.

  • Tamper-evident public certificate URL
  • Optional PDF export for SOC 2 evidence
  • Embed badges in multiple formats
  • 2 free rescans and re-issued certificates within 3 months
FAQ

Common questions, answered plainly.

If you have a question that isn't here, we'd love to hear from you.

What access do you need?

At minimum: the URL of your app (production or staging). For a useful audit: a read-only test account. For the deepest audit: a read-only Git URL so the team can review the actual code.

Is AppCheck safe to run against production?

Yes. The audit is read-only and uses safe payload libraries. The only writes are optional DNS TXT records used to verify target ownership. All review is performed against the captured data, never against your live system.

How long does an audit take?

Most audits are delivered within 1-2 business days of confirmation. Source-assisted audits can take a little longer depending on repo size.

What's the difference between AppCheck and a penetration test?

AppCheck is reproducible and re-runnable, with a fixed coverage matrix. A pen test is a deeper, human-led exercise over a longer window. We recommend both — AppCheck fills the gap between pen tests.

How is the score calculated?

Each check has a severity weight and a pass/warn/fail outcome. Weights are calibrated against OWASP and CVSS, and the result is normalized to 0-100.

What happens to the source code after the audit?

We clone a read-only copy, run the static checks and manual review, then delete the clone within 30 days of certificate delivery. We don't share source code with anyone outside the review desk.

Ready to start?

Send us your domain and we'll come back within one business day with a confirmation and scan window. €500 per audit, all-inclusive.