Services

The ladder: free snapshot to co-managed retainer.

Every step is fixed-scope with a published starting price in CAD. Every paid step ends in a retest and an attestation, because the deliverable is proof, not a PDF. Priority and urgent tiers exist for real deadlines; the standard tier is priced for planning ahead.

FREE

External Exposure Snapshot

What an attacker sees from outside, in plain language.

A bounded, read-only look at one domain from the outside, run by our Scout agent and reviewed by a practitioner. No exploitation, no forms submitted, no surprises. Free, ungated, and the natural first step before a baseline.

What is included

  • Certificate and TLS posture
  • security headers and cookie flags
  • exposed services and obvious version disclosure
  • one-page plain-language summary with next steps
  • practitioner review before anything is sent.

Typical triggers

Any first conversation; an insurance renewal on the horizon; the question "what would an attacker see?"

Built for

Any organization with a public web presence

ONE TIME

Web Application Security Review + Fix Sprint

Find the weaknesses, fix them with you, prove it to your auditor.

from $4,900
Ask about this

A manual, authenticated review of one application or API against OWASP WSTG/ASVS, accelerated by our Triage agent and led end to end by a named practitioner. Unlike a report-and-retest pentest, it includes a remediation sprint with your developers, a retest, and an attestation letter your auditor, insurer or customer can rely on.

What is included

  • Authenticated manual review of one app or API
  • developer-ready findings with reproduction steps and CVSS
  • remediation sprint of up to two working days with your team (WAF rules, configuration, code guidance)
  • one retest
  • executive summary
  • attestation letter formatted for SOC 2 auditors, insurers and customer questionnaires
  • evidence exported to Jira or your Vanta/Drata workspace.

Typical triggers

SOC 2 or customer security questionnaire; PCI DSS 4.0.1; "deal blocked" by a security review; PIPEDA or Law 25 readiness.

Built for

Software and SaaS teams with 1-10 public applications and no in-house AppSec lead

Start tiers

TierStarts withinPrice
Standard
Testing starts within 10 business days of signed authorization.
10 business days List
Priority
Testing starts within 5 business days; same deliverables.
5 business days +15%
Urgent
Testing starts within 48 hours for a blocked deal or audit; same deliverables.
2 business days +35%
ONE TIME

Vulnerability Baseline + Insurance-Readiness Evidence Pack

Pass your renewal without surprises.

from $2,400
Ask about this

Authorized external and internal scan review with manual triage, a control-gap check against the 13 baseline controls insurers and regulators reference, and an evidence pack that answers the questionnaire before your broker asks. Built for organizations whose renewal, not their curiosity, is the deadline.

What is included

  • Authorized scan review (up to 45 assets)
  • manual triage and prioritized exposure list
  • control-gap check against the 13 baseline controls and your insurer's questionnaire
  • MFA / EDR / backup evidence pack
  • remediation tracker
  • retest of critical items
  • one-page attestation summary.

Typical triggers

Cyber-insurance application or renewal; a broker referral; post-incident hardening; a vendor-risk review from a larger customer.

Built for

Regulated small businesses and professional services (accounting, legal, engineering, clinics, brokerages)

Start tiers

TierStarts withinPrice
Standard
Starts within 10 business days.
10 business days List
Priority
Starts within 5 business days for a dated renewal.
5 business days +15%
ONE TIME

WAF Tuning Sprint

Fewer false positives, cleaner rules, a decision record for every exception.

from $3,500
Ask about this

A defined scope of rules and blocked traffic, worked through with our Warden agent and signed off by a practitioner: every exception gets a scope, evidence, an expiry and a rollback. Before-and-after noise metrics show the difference. Delivered on your WAF (cloud or appliance) — you keep ownership of production changes.

What is included

  • False-positive investigation with a decision record per exception (rule, scope, evidence, expiry, rollback)
  • rule and policy tuning
  • logging and visibility improvements
  • before/after noise metrics
  • handover runbook
  • optional quarterly re-tune.

Typical triggers

Legitimate traffic being blocked; alert fatigue; a new WAF deployment or migration; an insurer or auditor asking for evidence of a managed edge.

Built for

Any organization running a web application firewall (cloud WAF, CDN WAF or appliance)

Start tiers

TierStarts withinPrice
Standard
Sprint starts within 10 business days.
10 business days List
Priority
Sprint starts within 5 business days; same deliverables.
5 business days +15%
ONE TIME

Compliance Readiness Pack

Audit-ready evidence for one framework and one business boundary.

from $4,500
Ask about this

Gap register, evidence plan, draft procedures and control mapping for the framework your customer, regulator or auditor named — SOC 2, ISO 27001, CyberSecure Canada, Ontario's O. Reg. 51/26 maturity assessment, Law 25 or PIPEDA. Our Ledger agent maps evidence to controls; a practitioner interprets and signs. A readiness assessment, explicitly not a certification.

What is included

  • Gap register against one framework
  • evidence plan and draft procedures
  • control mapping with framework version
  • auditor or certification-body hand-off
  • readiness summary for leadership.

Typical triggers

An audit date; a regulatory deadline; an enterprise contract clause; a certification requirement in a supply chain.

Built for

Software teams facing SOC 2; regulated SMBs; public-sector bodies with dated obligations

ONE TIME

Municipal + Public-Sector Web Security Review

Citizen-facing services reviewed, fixed and documented for council.

from $6,500
Ask about this

The Web Application Security Review + Fix Sprint scoped to citizen-facing portals, forms and third-party integrations, mapped to MFIPPA and PHIPA obligations and to O. Reg. 51/26 expectations, with a council- or board-ready summary and procurement-friendly documentation sized under invitational thresholds.

What is included

  • Everything in the Web Application Security Review + Fix Sprint
  • mapping to MFIPPA / PHIPA and O. Reg. 51/26
  • council- or board-ready summary
  • insurance certificate, security schedule and references packaged for procurement
  • optional maturity-assessment support.

Typical triggers

Maturity assessment due July 1, 2027; municipal privacy-impact and breach obligations from January 1, 2027; insurer requirements; a group-purchasing re-tender.

Built for

Municipalities, hospitals, colleges, school boards and agencies in Ontario

Start tiers

TierStarts withinPrice
Standard
Starts within 10 business days.
10 business days List
Priority
Starts within 5 business days.
5 business days +15%
MONTHLY

WAF + Vulnerability Retainer

Someone owns your edge and your exposure every month.

$1,500 - $3,500 per month
Ask about this

Business-hours co-management of your WAF and monthly vulnerability review: tuning, exception decisions, scan review, unlimited retests of previously reported findings, one advisory session and a quarterly plain-language report. Priced per application and per WAF, not per gigabyte. For clients who need 24/7 response, we add a disclosed partner SOC on top.

What is included

  • Monthly WAF rule review and tuning with decision records
  • monthly vulnerability scan review and prioritization
  • unlimited retests of previously reported findings
  • one advisory session per month
  • quarterly report and roadmap for leadership
  • defined response windows during business hours
  • optional disclosed 24/7 partner priced per user.

Typical triggers

After any review or sprint; an insurer asking for continuous management; the question "who is watching this?"

Built for

Any client after a first engagement; MSPs on behalf of their clients

Start tiers

TierStarts withinPrice
Core
$1,500 per month: one application, one WAF, monthly review and retests.
On request List
Plus
$2,500 per month: up to three applications, one WAF, monthly review, quarterly roadmap.
On request List
Scale
$3,500 per month: up to six applications, two WAFs, two advisory sessions, quarterly report to leadership.
On request List
CREDITS

Security Sprint Credits

Capacity on call, without a retainer.

10 credits from $5,500
Ask about this

Prepaid half-day credits redeemable across tuning, review, retest, questionnaire support or advisory, with a 12-month rollover. Billed once on use with an idempotent ledger so a credit is never charged twice.

What is included

  • 10 half-day credits
  • redeemable across any service line
  • 12-month rollover
  • monthly statement of credits used and remaining.

Typical triggers

Clients who want a practitioner available without committing to a monthly program.

Built for

Existing clients; partners

PARTNER

Partner Price List (MSPs and development agencies)

Keep your client. Add our depth under your brand.

15-20% off list
Ask about this

Our reviews, baselines, tuning sprints and readiness packs at a fixed partner discount with co-branded or white-labelled reports, no minimums, monthly billing in arrears, a non-poaching clause and a conflict screen. You lead the client relationship; we are the execution arm.

What is included

  • Offers 1-4 at a fixed partner discount
  • co-branded or white-labelled reports
  • no minimums
  • monthly billing in arrears
  • non-poaching clause
  • conflict screen on every engagement
  • referral-only option at a written, capped percentage of first-year fees.

Typical triggers

A partner's client asks for a pentest, SOC 2 evidence or WAF tuning.

Built for

MSPs, IT service firms and development agencies

What we deliberately do not sell

Managed SIEM or log platforms

We tune the control you already own — your WAF — and review your scans. Log platforms and 24/7 monitoring come from a disclosed partner when you need them.

Certifications

Readiness packs prepare you for SOC 2, ISO 27001, CyberSecure Canada or O. Reg. 51/26 assessments. The certificate is issued by the auditor or certification body, never by us.

Incident response during an active breach

We do not start work while an incident is active. We will point you to a response firm and pick up the hardening afterwards.