Web app, mobile app, API, and infrastructure audits. Findings ranked by exploitability and impact, with concrete code-level fixes. Optional follow-up to implement the fixes.
Five steps you can follow.
Scoping call (free, 30 min)
What needs reviewing, why, and what 'good' looks like for you. Output: written scope + fixed price.
Discovery (3–5 days)
Architecture review, threat model, environment access setup, automated tooling baseline.
Hands-on audit (1–3 weeks)
Manual review where it counts. Automated tools for breadth. Daily findings log shared with you.
Report + readout (1 week)
Written report with findings + 90-min live walkthrough so your team understands every fix.
Optional remediation sprint
We patch the criticals/highs ourselves on a fixed-price basis.
What's in every engagement.
- 01
Scoping & threat model
We define what's in scope, what's out, and what attackers actually care about for your business. STRIDE-based threat model included.
- 02
Web application audit
OWASP Top 10 coverage: injection, auth, session, IDOR, XSS, CSRF, deserialization, secrets, business logic flaws.
- 03
Mobile app audit
Static + dynamic analysis. Insecure storage, certificate pinning, jailbreak/root detection, deep link abuse, IPC vulnerabilities.
- 04
API security
Auth bypass, rate limiting, mass-assignment, broken object-level authorization (BOLA), excessive data exposure, JWT mistakes.
- 05
Dependency triage
SCA across all packages. CVE assessment in context — most CVEs are noise; we tell you which ones actually matter for you.
- 06
Infrastructure review
Cloud config (Cloudflare, GCP, AWS), IAM, secrets management, network exposure, backup integrity, log retention.
- 07
Report with severity + fix
Each finding: reproduction steps, severity (CVSS), business impact, and the actual code or config change that fixes it.
- 08
Optional remediation sprint
We can implement the fixes ourselves — fixed-price follow-up so things actually get patched.
Three ways in.
Starting numbers are visible. The final fixed price is locked after a free discovery call.
| Tier | For | Includes | Price | |
|---|---|---|---|---|
| Focused audit | Single web app or API |
| from $3,500 | Book a call → |
| Standard audit | Web + API + dependencies |
| from $8,000 | Book a call → |
| Comprehensive audit + remediation | Audit + we fix the critical findings |
| from $18,000 | Book a call → |
Before we start
How much does a website security audit cost?
How long does a security audit take?
Are you certified penetration testers?
Do you need access to our source code?
Will you sign our NDA?
Real-time logistics control tower
Lup — AI human-simulation desktop
KYC onboarding pipeline
Website and app security audits in Jordan — OWASP-aligned, with concrete remediation, not a 200-page PDF.
Web app, mobile app, API, and infrastructure audits. Findings ranked by exploitability and impact, with concrete code-level fixes. Optional follow-up to implement the fixes.