€500 per audit.
One domain, one flat price, no procurement dance. Our engineers, the best testing tools we can get our hands on, and your score plus certificate back in 1 week. No subscriptions, no seat counts, no surprise invoice.
Single audit
One full AppCheck against one domain. Our engineers work through all ten areas, verify every finding themselves, and you walk away with the scorecard, the prioritised fix list, and an FPSEC certificate valid for 360 days — plus 2 free rescans and re-issued certificates inside 3 months.
- Full coverage across 10 areas (120+ checks)
- Our engineers on the public surface and the authenticated flows your test account unlocks
- Every finding re-tested and signed off by a security engineer
- Detailed fix list mapped to standards
- FPSEC certificate valid for 360 days
- 2 free rescans & re-issued certificates within 3 months
- PDF export for SOC 2 evidence
Continuous
For teams who ship constantly: AppCheck on a schedule, alerts the moment something regresses, and a certificate that never goes stale.
- Scheduled AppCheck runs (daily / weekly / per release)
- Webhook + email + Slack alerts on regressions
- Score history, so a slide shows up as a trend instead of a surprise
- Quarterly rescans & certificates included by default
- On-prem scanner option
- A named engineer you can email directly
Every audit includes the full matrix.
No tiered gates, no upsells. Single audits and continuous work get the same ten areas, the same engineers, and the same score.
- All 10 coverage areas — TLS, headers, cookies, auth, exposed endpoints, OWASP Top 10, dependencies, DNS, API, source-code review
- A security engineer's review, backed by the best testing tools we can get our hands on
- Dependency CVE scan across JavaScript, Python, JVM, Go, Ruby, and Rust stacks
- Authenticated mode: we sign in with your test credentials and walk the real user flows
- Detailed fix list mapped to OWASP / CVSS / RFC references
- FPSEC certificate valid for 360 days with tamper-evident public URL
- 2 free rescans and re-issued certificates within 3 months of delivery
- PDF export for SOC 2, ISO 27001, or vendor security reviews
Pricing questions, answered.
Is the price really flat at €500?
Yes. One AppCheck against one domain is €500, full stop. Continuous engagements are quoted based on scan volume.
How fast is an audit?
The sweep takes minutes; the review is where the time goes. Your scorecard, fix list, and certificate land within a week of confirming scope — we'd rather take the extra days than hand you a finding we haven't verified.
What counts as one audit?
One domain plus its primary subdomains in scope (e.g. app.example.com and api.example.com together count as one). Separate products or environments are separate audits.
How long is the certificate valid?
Each certificate is valid for 360 days from issue. After that, you can order a fresh audit at the same flat price.
How many free rescans do I get?
Every audit includes 2 free rescans (with a fresh certificate) within 3 months of the original delivery. Rescans beyond that — or after the 3-month window — are billed at the standard audit rate.
Can I expense this?
Yes. We send a proper invoice with VAT details, and Continuous customers get a DPA on request.
What if my audit needs custom checks?
Custom checks for proprietary APIs or internal standards are available on Continuous engagements. Single audits use the standard 120+ check matrix.
Point us at one domain.
Send us the URL, app access, and (if you can) your source. We confirm scope the same day and the sweep starts straight after — score and certificate in 1 week.