Product

AppCheck — security engineers, let loose on your app.

Send us a URL and we'll go through your app the way an attacker would — logins, permissions, APIs, admin panels, and the source code if you share it. We use the best testing tools we can get our hands on so nothing obvious slips by, but the reading, the judgement, and the write-up are ours. You get a 0-100 score, a prioritised fix list, and a verifiable certificate in 1 week.

Coverage matrix

Ten coverage areas. One source of truth.

All ten areas, every time, read by an engineer who knows what a false positive looks like. A 78 in your app means what a 78 means anywhere else — which is the point when a buyer asks.

01

TLS & certificates

Most teams stop worrying once the padlock appears. We check the protocol versions, the chain, the expiry, and whether anyone can talk your server into downgrading.

  • TLS 1.2+ enforced; TLS 1.3 advertised where supported
  • Full certificate chain trust and hostname match
  • Certificate expiry window with renewal reminders
  • HSTS header present with sane max-age and includeSubDomains
  • OCSP stapling enabled; CRL fallback acceptable
  • Cipher suite review against Mozilla 'intermediate' baseline
02

Security headers

The handful of headers that stop clickjacking, MIME sniffing, and script injection. Cheap to add, and almost always missing one.

  • Content-Security-Policy present and not using unsafe-inline / unsafe-eval
  • X-Frame-Options / CSP frame-ancestors prevents clickjacking
  • X-Content-Type-Options: nosniff
  • Referrer-Policy set to a privacy-preserving value
  • Permissions-Policy restricting sensitive APIs
  • Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy
03

Cookies & sessions

A stolen session cookie is a stolen account. We check the flags, the scope, and whether sessions rotate when privileges change.

  • Secure flag set on every cookie transmitted over HTTPS
  • HttpOnly on session and auth cookies
  • SameSite attribute set (Strict or Lax)
  • Cookie scope (Domain / Path) reviewed for over-broadness
  • Session identifier rotation on login / privilege change
  • Cookie prefixes (__Host-, __Secure-) where applicable
04

Authentication & MFA

How users prove who they are — and how hard it is to guess, stuff, or brute-force their way in. MFA, lockouts, reset flows, leaked credentials.

  • MFA available; enforcement status for privileged roles
  • Password policy: length, complexity, breach awareness
  • Rate limiting / account lockout on login and MFA endpoints
  • Credential exposure check against HIBP (k-anonymity API)
  • Auth pages served over HTTPS with secure headers
  • Recovery and password-reset flow resistance to enumeration
05

Exposed endpoints

The .env file someone backed up into the web root. The staging console still on the public internet. The .git directory you're hoping nobody finds.

  • Admin panels, staging paths, and legacy routes
  • .git, .env, .DS_Store, .svn, .htaccess backups
  • phpinfo, server-status, balancer-manager pages
  • Exposed Swagger / OpenAPI / GraphQL endpoints
  • Backups, archives, and editor swap files (.bak, .swp)
  • Directory listings on static assets
06

OWASP Top 10 & injection

The bug classes pen testers actually find — injection, XSS, SSRF, broken access control — probed for real, then written up by someone who understands your app.

  • SQL injection probes (error-, time-, boolean-based)
  • Reflected and stored XSS with safe payload library
  • Server-Side Request Forgery (SSRF) surface
  • OS command injection in user inputs
  • Insecure Direct Object Reference (IDOR) / BOLA heuristics
  • Broken access control via vertical and horizontal probes
07

Dependency risk

The code you didn't write is often the code that bites you. We fingerprint your stack and check every package against the advisory databases.

  • JavaScript / npm CVE scan against GHSA + NVD
  • Python / PyPI CVE scan
  • Maven, NuGet, RubyGems, Go module advisories
  • Outdated package detection with age thresholds
  • License compliance flags (GPL, AGPL, commercial)
  • Suspicious post-install scripts in newly added deps
08

DNS & email

Your domain is the front door. We make sure nobody can send email as you or mint a certificate in your name.

  • SPF record present and not overly permissive
  • DKIM record present and aligned with signing domain
  • DMARC policy present with at least p=quarantine
  • CAA records restricting issuance to approved CAs
  • DNSSEC validation where supported
  • MX hygiene (no open relays, no backup MX exposure)
09

API security

Modern SaaS is APIs all the way down. We check whether your endpoints actually enforce who can call them, how often, and with what payload.

  • JWT signature verification, alg=none checks, key rotation
  • Rate limiting on public endpoints
  • CORS posture (no wildcard with credentials)
  • Schema validation of request bodies
  • Mass-assignment and over-posting patterns
  • Excessive data exposure in responses
10

Source-code reviewWith source access

Share a read-only repo and we read the parts that never reach production: auth logic, business rules, input validation, hard-coded secrets.

  • Hard-coded secrets, API keys, and credentials in source
  • Authorization checks on sensitive routes & resources
  • Server-side input validation; client-side trust boundary
  • Modern cryptographic primitives; no homegrown crypto
  • Security-relevant events logged with enough context
  • Dependency manifest hygiene (lockfile committed, pinned versions)
Modes

How much access can you give us?

A URL gets you the outside. A test account gets you the flows your users actually touch. Source access gets you the bugs that never make it to production.

Standard

URL + test account

The default audit. Our engineers cover your public surface, then use your test account to walk the real flows — login, password reset, permissions — the way a user does and an attacker would.

  • URL of the app (production or staging)
  • Test account with permissions scoped to the audit
  • No agents, no firewall changes
  • Every finding verified by a person — not raw scanner output
Recommended

+ Source code

Hand over a read-only repo and we read the code your users never see: auth logic, input validation, hard-coded secrets, homegrown crypto. Findings come with file paths and line numbers your engineers can act on.

  • Read-only Git access (HTTPS token or ephemeral clone)
  • Reviewers focus on auth, validation, secrets, crypto
  • Findings include file paths and line numbers
  • Diffs against the previous audit included when available
Custom

Continuous monitoring

Make it a habit — every release, every week, or every day. The tools watch for regressions, our engineers review what changed, and your certificate stays current.

  • Webhook + email alerts on regressions
  • Score history with team commentary on every change
  • Public certificate refresh on each pass
Reporting

Reports people outside security will actually read.

Three artifacts for three audiences: a scorecard for whoever signs off, a fix list for the people who deploy, and a certificate for the people who ask.

Scorecard

For Executives, sales, procurement

One number, one grade band, one certificate ID. That's it.

Detailed fix list

For Engineering & DevOps

Every failure with the exact config change, and the standard it violates — so nobody has to interpret anything.

FPSEC certificate

For Customers & partners

A tamper-evident URL with the timestamp, domain, score, and pass/fail breakdown — the link that goes in the deal room.

Point us at your app.

Send the domain and we'll confirm scope the same business day. Score, fix list, and certificate back in 1 week — €500 flat, nothing hidden.