FREE
External Exposure Snapshot
What an attacker sees from outside, in plain language.
A bounded, read-only look at one domain from the outside, run by our Scout agent and reviewed by a practitioner. No exploitation, no forms submitted, no surprises. Free, ungated, and the natural first step before a baseline.
What is included
- Certificate and TLS posture
- security headers and cookie flags
- exposed services and obvious version disclosure
- one-page plain-language summary with next steps
- practitioner review before anything is sent.
Typical triggers
Any first conversation; an insurance renewal on the horizon; the question "what would an attacker see?"
Built for
Any organization with a public web presence
ONE TIME
Web Application Security Review + Fix Sprint
Find the weaknesses, fix them with you, prove it to your auditor.
A manual, authenticated review of one application or API against OWASP WSTG/ASVS, accelerated by our Triage agent and led end to end by a named practitioner. Unlike a report-and-retest pentest, it includes a remediation sprint with your developers, a retest, and an attestation letter your auditor, insurer or customer can rely on.
What is included
- Authenticated manual review of one app or API
- developer-ready findings with reproduction steps and CVSS
- remediation sprint of up to two working days with your team (WAF rules, configuration, code guidance)
- one retest
- executive summary
- attestation letter formatted for SOC 2 auditors, insurers and customer questionnaires
- evidence exported to Jira or your Vanta/Drata workspace.
Typical triggers
SOC 2 or customer security questionnaire; PCI DSS 4.0.1; "deal blocked" by a security review; PIPEDA or Law 25 readiness.
Built for
Software and SaaS teams with 1-10 public applications and no in-house AppSec lead
Start tiers
| Tier | Starts within | Price |
Standard Testing starts within 10 business days of signed authorization. |
10 business days |
List |
Priority Testing starts within 5 business days; same deliverables. |
5 business days |
+15% |
Urgent Testing starts within 48 hours for a blocked deal or audit; same deliverables. |
2 business days |
+35% |
ONE TIME
Vulnerability Baseline + Insurance-Readiness Evidence Pack
Pass your renewal without surprises.
Authorized external and internal scan review with manual triage, a control-gap check against the 13 baseline controls insurers and regulators reference, and an evidence pack that answers the questionnaire before your broker asks. Built for organizations whose renewal, not their curiosity, is the deadline.
What is included
- Authorized scan review (up to 45 assets)
- manual triage and prioritized exposure list
- control-gap check against the 13 baseline controls and your insurer's questionnaire
- MFA / EDR / backup evidence pack
- remediation tracker
- retest of critical items
- one-page attestation summary.
Typical triggers
Cyber-insurance application or renewal; a broker referral; post-incident hardening; a vendor-risk review from a larger customer.
Built for
Regulated small businesses and professional services (accounting, legal, engineering, clinics, brokerages)
Start tiers
| Tier | Starts within | Price |
Standard Starts within 10 business days. |
10 business days |
List |
Priority Starts within 5 business days for a dated renewal. |
5 business days |
+15% |
ONE TIME
WAF Tuning Sprint
Fewer false positives, cleaner rules, a decision record for every exception.
A defined scope of rules and blocked traffic, worked through with our Warden agent and signed off by a practitioner: every exception gets a scope, evidence, an expiry and a rollback. Before-and-after noise metrics show the difference. Delivered on your WAF (cloud or appliance) — you keep ownership of production changes.
What is included
- False-positive investigation with a decision record per exception (rule, scope, evidence, expiry, rollback)
- rule and policy tuning
- logging and visibility improvements
- before/after noise metrics
- handover runbook
- optional quarterly re-tune.
Typical triggers
Legitimate traffic being blocked; alert fatigue; a new WAF deployment or migration; an insurer or auditor asking for evidence of a managed edge.
Built for
Any organization running a web application firewall (cloud WAF, CDN WAF or appliance)
Start tiers
| Tier | Starts within | Price |
Standard Sprint starts within 10 business days. |
10 business days |
List |
Priority Sprint starts within 5 business days; same deliverables. |
5 business days |
+15% |
ONE TIME
Compliance Readiness Pack
Audit-ready evidence for one framework and one business boundary.
Gap register, evidence plan, draft procedures and control mapping for the framework your customer, regulator or auditor named — SOC 2, ISO 27001, CyberSecure Canada, Ontario's O. Reg. 51/26 maturity assessment, Law 25 or PIPEDA. Our Ledger agent maps evidence to controls; a practitioner interprets and signs. A readiness assessment, explicitly not a certification.
What is included
- Gap register against one framework
- evidence plan and draft procedures
- control mapping with framework version
- auditor or certification-body hand-off
- readiness summary for leadership.
Typical triggers
An audit date; a regulatory deadline; an enterprise contract clause; a certification requirement in a supply chain.
Built for
Software teams facing SOC 2; regulated SMBs; public-sector bodies with dated obligations
ONE TIME
Municipal + Public-Sector Web Security Review
Citizen-facing services reviewed, fixed and documented for council.
The Web Application Security Review + Fix Sprint scoped to citizen-facing portals, forms and third-party integrations, mapped to MFIPPA and PHIPA obligations and to O. Reg. 51/26 expectations, with a council- or board-ready summary and procurement-friendly documentation sized under invitational thresholds.
What is included
- Everything in the Web Application Security Review + Fix Sprint
- mapping to MFIPPA / PHIPA and O. Reg. 51/26
- council- or board-ready summary
- insurance certificate, security schedule and references packaged for procurement
- optional maturity-assessment support.
Typical triggers
Maturity assessment due July 1, 2027; municipal privacy-impact and breach obligations from January 1, 2027; insurer requirements; a group-purchasing re-tender.
Built for
Municipalities, hospitals, colleges, school boards and agencies in Ontario
Start tiers
| Tier | Starts within | Price |
Standard Starts within 10 business days. |
10 business days |
List |
Priority Starts within 5 business days. |
5 business days |
+15% |
MONTHLY
WAF + Vulnerability Retainer
Someone owns your edge and your exposure every month.
Business-hours co-management of your WAF and monthly vulnerability review: tuning, exception decisions, scan review, unlimited retests of previously reported findings, one advisory session and a quarterly plain-language report. Priced per application and per WAF, not per gigabyte. For clients who need 24/7 response, we add a disclosed partner SOC on top.
What is included
- Monthly WAF rule review and tuning with decision records
- monthly vulnerability scan review and prioritization
- unlimited retests of previously reported findings
- one advisory session per month
- quarterly report and roadmap for leadership
- defined response windows during business hours
- optional disclosed 24/7 partner priced per user.
Typical triggers
After any review or sprint; an insurer asking for continuous management; the question "who is watching this?"
Built for
Any client after a first engagement; MSPs on behalf of their clients
Start tiers
| Tier | Starts within | Price |
Core $1,500 per month: one application, one WAF, monthly review and retests. |
On request |
List |
Plus $2,500 per month: up to three applications, one WAF, monthly review, quarterly roadmap. |
On request |
List |
Scale $3,500 per month: up to six applications, two WAFs, two advisory sessions, quarterly report to leadership. |
On request |
List |
CREDITS
Security Sprint Credits
Capacity on call, without a retainer.
Prepaid half-day credits redeemable across tuning, review, retest, questionnaire support or advisory, with a 12-month rollover. Billed once on use with an idempotent ledger so a credit is never charged twice.
What is included
- 10 half-day credits
- redeemable across any service line
- 12-month rollover
- monthly statement of credits used and remaining.
Typical triggers
Clients who want a practitioner available without committing to a monthly program.
Built for
Existing clients; partners
PARTNER
Partner Price List (MSPs and development agencies)
Keep your client. Add our depth under your brand.
Our reviews, baselines, tuning sprints and readiness packs at a fixed partner discount with co-branded or white-labelled reports, no minimums, monthly billing in arrears, a non-poaching clause and a conflict screen. You lead the client relationship; we are the execution arm.
What is included
- Offers 1-4 at a fixed partner discount
- co-branded or white-labelled reports
- no minimums
- monthly billing in arrears
- non-poaching clause
- conflict screen on every engagement
- referral-only option at a written, capped percentage of first-year fees.
Typical triggers
A partner's client asks for a pentest, SOC 2 evidence or WAF tuning.
Built for
MSPs, IT service firms and development agencies