Product

AppCheck — the flagship FPSEC audit product.

AppCheck is an end-to-end audit for SaaS platforms and web apps. We need your URL, a read-only test account, and (ideally) a clone of your source. Our security team audits across ten coverage areas with AI-native automation in support, and you get a 0-100 score, a prioritised fix list, and an FPSEC certificate you can share.

Coverage matrix

Ten coverage areas. One source of truth.

Every AppCheck runs the same coverage matrix so a 78 means the same thing across apps, teams, and industries.

01

TLS & certificates

Verify that encryption in transit is actually doing its job — modern protocols, valid chains, and policy headers.

  • TLS 1.2+ enforced; TLS 1.3 advertised where supported
  • Full certificate chain trust and hostname match
  • Certificate expiry window with renewal reminders
  • HSTS header present with sane max-age and includeSubDomains
  • OCSP stapling enabled; CRL fallback acceptable
  • Cipher suite review against Mozilla 'intermediate' baseline
02

Security headers

Defense-in-depth headers that block the most common browser-borne attacks.

  • Content-Security-Policy present and not using unsafe-inline / unsafe-eval
  • X-Frame-Options / CSP frame-ancestors prevents clickjacking
  • X-Content-Type-Options: nosniff
  • Referrer-Policy set to a privacy-preserving value
  • Permissions-Policy restricting sensitive APIs
  • Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy
03

Cookies & sessions

Session handling failures are a top cause of account takeover — AppCheck inspects them at the cookie level.

  • Secure flag set on every cookie transmitted over HTTPS
  • HttpOnly on session and auth cookies
  • SameSite attribute set (Strict or Lax)
  • Cookie scope (Domain / Path) reviewed for over-broadness
  • Session identifier rotation on login / privilege change
  • Cookie prefixes (__Host-, __Secure-) where applicable
04

Authentication & MFA

How users prove who they are — and how well your systems defend against bad actors trying to break in.

  • MFA available; enforcement status for privileged roles
  • Password policy: length, complexity, breach awareness
  • Rate limiting / account lockout on login and MFA endpoints
  • Credential exposure check against HIBP (k-anonymity API)
  • Auth pages served over HTTPS with secure headers
  • Recovery and password-reset flow resistance to enumeration
05

Exposed endpoints

Anything that should be internal but isn't — discovered through wordlists and known fingerprints.

  • Admin panels, staging paths, and legacy routes
  • .git, .env, .DS_Store, .svn, .htaccess backups
  • phpinfo, server-status, balancer-manager pages
  • Exposed Swagger / OpenAPI / GraphQL endpoints
  • Backups, archives, and editor swap files (.bak, .swp)
  • Directory listings on static assets
06

OWASP Top 10

Active probing of the same classes of bugs that pen testers find — written up by our team with the context that scanners miss.

  • SQL injection probes (error-, time-, boolean-based)
  • Reflected and stored XSS with safe payload library
  • Server-Side Request Forgery (SSRF) surface
  • OS command injection in user inputs
  • Insecure Direct Object Reference (IDOR) / BOLA heuristics
  • Broken access control via vertical and horizontal probes
07

Dependency risk

The software you didn't write is often the software that breaks you. AppCheck fingerprints your stack and checks it against advisory databases.

  • JavaScript / npm CVE scan against GHSA + NVD
  • Python / PyPI CVE scan
  • Maven, NuGet, RubyGems, Go module advisories
  • Outdated package detection with age thresholds
  • License compliance flags (GPL, AGPL, commercial)
  • Suspicious post-install scripts in newly added deps
08

DNS & email

Your domain is the front door — make sure attackers can't forge your email or mint rogue certificates.

  • SPF record present and not overly permissive
  • DKIM record present and aligned with signing domain
  • DMARC policy present with at least p=quarantine
  • CAA records restricting issuance to approved CAs
  • DNSSEC validation where supported
  • MX hygiene (no open relays, no backup MX exposure)
09

API security

Modern SaaS is APIs all the way down. AppCheck looks at how your endpoints enforce authn, authz, and abuse prevention.

  • JWT signature verification, alg=none checks, key rotation
  • Rate limiting on public endpoints
  • CORS posture (no wildcard with credentials)
  • Schema validation of request bodies
  • Mass-assignment and over-posting patterns
  • Excessive data exposure in responses
10

Source-code review

When you share a read-only repo, the audit goes deeper: auth logic, business rules, input validation, secrets handling.

  • Hard-coded secrets, API keys, and credentials in source
  • Authorization checks on sensitive routes & resources
  • Server-side input validation; client-side trust boundary
  • Modern cryptographic primitives; no homegrown crypto
  • Security-relevant events logged with enough context
  • Dependency manifest hygiene (lockfile committed, pinned versions)
Modes

How much access can you give us?

Every audit is an end-to-end engagement by our security team with AI-native automation in support. The more access you grant, the more useful the report.

Standard

URL + test account

The default audit. You give us your URL and a read-only test account; the team audits the public surface and the authenticated flows with AI-native automation in support.

  • URL of the app (production or staging)
  • Read-only test account with a clearly-marked scope
  • No agents, no firewall changes
  • Team sign-off included — not just raw automation output
Recommended

+ Source code

Add a read-only repo clone and the audit goes deeper. The team reviews auth logic, business rules, input validation, secrets, and crypto in the actual code — not just the running surface.

  • Read-only Git access (HTTPS token or ephemeral clone)
  • Reviewers focus on auth, validation, secrets, crypto
  • Findings include file paths and line numbers
  • Diffs against the previous audit included when available
Custom

Continuous monitoring

Schedule AppCheck on every release, every day, or every week. The audit runs unattended; the team reviews the diff and signs off on the updated certificate.

  • Webhook + email alerts on regressions
  • Score history with team commentary on every change
  • Public certificate refresh on each pass
Reporting

Reports people outside security will actually read.

AppCheck produces three artifacts: a quick scorecard, a detailed fix list for engineers, and an FPSEC certificate for everyone else.

Scorecard

For Executives, sales, procurement

One number, one grade band, one certificate ID. That's it.

Detailed fix list

For Engineering & DevOps

Every failing check with the specific config change and a link to the standard it violates.

FPSEC certificate

For Customers & partners

A tamper-evident, sharable URL with timestamp, target domain, score, and pass/fail breakdown.

Ready when you are.

Send us the domain you want audited and we'll come back within one business day with a confirmation and scan window. €500 per audit, all-inclusive.