AppCheck — security engineers, let loose on your app.
Send us a URL and we'll go through your app the way an attacker would — logins, permissions, APIs, admin panels, and the source code if you share it. We use the best testing tools we can get our hands on so nothing obvious slips by, but the reading, the judgement, and the write-up are ours. You get a 0-100 score, a prioritised fix list, and a verifiable certificate in 1 week.
Ten coverage areas. One source of truth.
All ten areas, every time, read by an engineer who knows what a false positive looks like. A 78 in your app means what a 78 means anywhere else — which is the point when a buyer asks.
01TLS & certificates
Most teams stop worrying once the padlock appears. We check the protocol versions, the chain, the expiry, and whether anyone can talk your server into downgrading.
6 checks
TLS & certificates
Most teams stop worrying once the padlock appears. We check the protocol versions, the chain, the expiry, and whether anyone can talk your server into downgrading.
- TLS 1.2+ enforced; TLS 1.3 advertised where supported
- Full certificate chain trust and hostname match
- Certificate expiry window with renewal reminders
- HSTS header present with sane max-age and includeSubDomains
- OCSP stapling enabled; CRL fallback acceptable
- Cipher suite review against Mozilla 'intermediate' baseline
02Security headers
The handful of headers that stop clickjacking, MIME sniffing, and script injection. Cheap to add, and almost always missing one.
6 checks
Security headers
The handful of headers that stop clickjacking, MIME sniffing, and script injection. Cheap to add, and almost always missing one.
- Content-Security-Policy present and not using unsafe-inline / unsafe-eval
- X-Frame-Options / CSP frame-ancestors prevents clickjacking
- X-Content-Type-Options: nosniff
- Referrer-Policy set to a privacy-preserving value
- Permissions-Policy restricting sensitive APIs
- Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy
04Authentication & MFA
How users prove who they are — and how hard it is to guess, stuff, or brute-force their way in. MFA, lockouts, reset flows, leaked credentials.
6 checks
Authentication & MFA
How users prove who they are — and how hard it is to guess, stuff, or brute-force their way in. MFA, lockouts, reset flows, leaked credentials.
- MFA available; enforcement status for privileged roles
- Password policy: length, complexity, breach awareness
- Rate limiting / account lockout on login and MFA endpoints
- Credential exposure check against HIBP (k-anonymity API)
- Auth pages served over HTTPS with secure headers
- Recovery and password-reset flow resistance to enumeration
05Exposed endpoints
The .env file someone backed up into the web root. The staging console still on the public internet. The .git directory you're hoping nobody finds.
6 checks
Exposed endpoints
The .env file someone backed up into the web root. The staging console still on the public internet. The .git directory you're hoping nobody finds.
- Admin panels, staging paths, and legacy routes
- .git, .env, .DS_Store, .svn, .htaccess backups
- phpinfo, server-status, balancer-manager pages
- Exposed Swagger / OpenAPI / GraphQL endpoints
- Backups, archives, and editor swap files (.bak, .swp)
- Directory listings on static assets
06OWASP Top 10 & injection
The bug classes pen testers actually find — injection, XSS, SSRF, broken access control — probed for real, then written up by someone who understands your app.
6 checks
OWASP Top 10 & injection
The bug classes pen testers actually find — injection, XSS, SSRF, broken access control — probed for real, then written up by someone who understands your app.
- SQL injection probes (error-, time-, boolean-based)
- Reflected and stored XSS with safe payload library
- Server-Side Request Forgery (SSRF) surface
- OS command injection in user inputs
- Insecure Direct Object Reference (IDOR) / BOLA heuristics
- Broken access control via vertical and horizontal probes
07Dependency risk
The code you didn't write is often the code that bites you. We fingerprint your stack and check every package against the advisory databases.
6 checks
Dependency risk
The code you didn't write is often the code that bites you. We fingerprint your stack and check every package against the advisory databases.
- JavaScript / npm CVE scan against GHSA + NVD
- Python / PyPI CVE scan
- Maven, NuGet, RubyGems, Go module advisories
- Outdated package detection with age thresholds
- License compliance flags (GPL, AGPL, commercial)
- Suspicious post-install scripts in newly added deps
08DNS & email
Your domain is the front door. We make sure nobody can send email as you or mint a certificate in your name.
6 checks
DNS & email
Your domain is the front door. We make sure nobody can send email as you or mint a certificate in your name.
- SPF record present and not overly permissive
- DKIM record present and aligned with signing domain
- DMARC policy present with at least p=quarantine
- CAA records restricting issuance to approved CAs
- DNSSEC validation where supported
- MX hygiene (no open relays, no backup MX exposure)
09API security
Modern SaaS is APIs all the way down. We check whether your endpoints actually enforce who can call them, how often, and with what payload.
6 checks
API security
Modern SaaS is APIs all the way down. We check whether your endpoints actually enforce who can call them, how often, and with what payload.
- JWT signature verification, alg=none checks, key rotation
- Rate limiting on public endpoints
- CORS posture (no wildcard with credentials)
- Schema validation of request bodies
- Mass-assignment and over-posting patterns
- Excessive data exposure in responses
10Source-code reviewWith source access
Share a read-only repo and we read the parts that never reach production: auth logic, business rules, input validation, hard-coded secrets.
6 checks
Source-code reviewWith source access
Share a read-only repo and we read the parts that never reach production: auth logic, business rules, input validation, hard-coded secrets.
- Hard-coded secrets, API keys, and credentials in source
- Authorization checks on sensitive routes & resources
- Server-side input validation; client-side trust boundary
- Modern cryptographic primitives; no homegrown crypto
- Security-relevant events logged with enough context
- Dependency manifest hygiene (lockfile committed, pinned versions)
How much access can you give us?
A URL gets you the outside. A test account gets you the flows your users actually touch. Source access gets you the bugs that never make it to production.
URL + test account
The default audit. Our engineers cover your public surface, then use your test account to walk the real flows — login, password reset, permissions — the way a user does and an attacker would.
- URL of the app (production or staging)
- Test account with permissions scoped to the audit
- No agents, no firewall changes
- Every finding verified by a person — not raw scanner output
+ Source code
Hand over a read-only repo and we read the code your users never see: auth logic, input validation, hard-coded secrets, homegrown crypto. Findings come with file paths and line numbers your engineers can act on.
- Read-only Git access (HTTPS token or ephemeral clone)
- Reviewers focus on auth, validation, secrets, crypto
- Findings include file paths and line numbers
- Diffs against the previous audit included when available
Continuous monitoring
Make it a habit — every release, every week, or every day. The tools watch for regressions, our engineers review what changed, and your certificate stays current.
- Webhook + email alerts on regressions
- Score history with team commentary on every change
- Public certificate refresh on each pass
Reports people outside security will actually read.
Three artifacts for three audiences: a scorecard for whoever signs off, a fix list for the people who deploy, and a certificate for the people who ask.
Scorecard
One number, one grade band, one certificate ID. That's it.
Detailed fix list
Every failure with the exact config change, and the standard it violates — so nobody has to interpret anything.
FPSEC certificate
A tamper-evident URL with the timestamp, domain, score, and pass/fail breakdown — the link that goes in the deal room.
Point us at your app.
Send the domain and we'll confirm scope the same business day. Score, fix list, and certificate back in 1 week — €500 flat, nothing hidden.