Security Audits

Website and app security audits in Jordan — OWASP-aligned, with concrete remediation, not a 200-page PDF.

Web app, mobile app, API, and infrastructure audits. Findings ranked by exploitability and impact, with concrete code-level fixes. Optional follow-up to implement the fixes.

Request an AuditWhatsApp
How it works

Five steps you can follow.

01

Scoping call (free, 30 min)

What needs reviewing, why, and what 'good' looks like for you. Output: written scope + fixed price.

02

Discovery (3–5 days)

Architecture review, threat model, environment access setup, automated tooling baseline.

03

Hands-on audit (1–3 weeks)

Manual review where it counts. Automated tools for breadth. Daily findings log shared with you.

04

Report + readout (1 week)

Written report with findings + 90-min live walkthrough so your team understands every fix.

05

Optional remediation sprint

We patch the criticals/highs ourselves on a fixed-price basis.

Scope

What's in every engagement.

  1. 01

    Scoping & threat model

    We define what's in scope, what's out, and what attackers actually care about for your business. STRIDE-based threat model included.

  2. 02

    Web application audit

    OWASP Top 10 coverage: injection, auth, session, IDOR, XSS, CSRF, deserialization, secrets, business logic flaws.

  3. 03

    Mobile app audit

    Static + dynamic analysis. Insecure storage, certificate pinning, jailbreak/root detection, deep link abuse, IPC vulnerabilities.

  4. 04

    API security

    Auth bypass, rate limiting, mass-assignment, broken object-level authorization (BOLA), excessive data exposure, JWT mistakes.

  5. 05

    Dependency triage

    SCA across all packages. CVE assessment in context — most CVEs are noise; we tell you which ones actually matter for you.

  6. 06

    Infrastructure review

    Cloud config (Cloudflare, GCP, AWS), IAM, secrets management, network exposure, backup integrity, log retention.

  7. 07

    Report with severity + fix

    Each finding: reproduction steps, severity (CVSS), business impact, and the actual code or config change that fixes it.

  8. 08

    Optional remediation sprint

    We can implement the fixes ourselves — fixed-price follow-up so things actually get patched.

Pricing

Three ways in.

Starting numbers are visible. The final fixed price is locked after a free discovery call.

TierForIncludesPrice
Focused auditSingle web app or API
  • · Manual + automated review
  • · OWASP Top 10 coverage
from $3,500Book a call
Standard auditWeb + API + dependencies
  • · Threat model included
  • · Infra config review
from $8,000Book a call
Comprehensive audit + remediationAudit + we fix the critical findings
  • · Web + Mobile + API + infra
  • · Full threat model
from $18,000Book a call
FAQ

Before we start

How much does a website security audit cost?
Focused audit (single web app or API): from $3,500. Standard audit (web + API + dependencies): from $8,000. Comprehensive audit + remediation: from $18,000.
How long does a security audit take?
Focused audit: 1–2 weeks. Standard audit: 3 weeks. Comprehensive audit: 4–6 weeks. Free 30-minute scoping call before any commitment.
Are you certified penetration testers?
We work alongside certified pentesters when needed. The studio specialises in *fixable* findings — not just discovery — and reports written in language your engineers can act on.
Do you need access to our source code?
White-box (with source) catches significantly more vulnerabilities than black-box. Strongly preferred, especially for web and API audits.
Will you sign our NDA?
Yes. Mutual NDAs are standard before any code access. We can sign yours or use ours.

Website and app security audits in Jordan — OWASP-aligned, with concrete remediation, not a 200-page PDF.

Web app, mobile app, API, and infrastructure audits. Findings ranked by exploitability and impact, with concrete code-level fixes. Optional follow-up to implement the fixes.

Request an AuditWhatsApp