The security letter that unblocks your enterprise deal
A fixed-price, independent security test of your live app, verified by a human tester, delivered in 5 business days with a signed attestation letter you can attach to a customer’s security questionnaire. Built for SaaS founders who shipped fast with AI and now have a security review standing between them and a signed contract.
Not sure what a review will flag on your app? See the five findings that stall enterprise security reviews, and how to pass.
You are in the right place if
An enterprise customer sent a security questionnaire
The deal is moving until the vendor review asks about independent security testing. A blank answer stalls it; a $5,000 to $8,000 pentest quote and a six-week wait stalls it longer.
Your auditor or compliance platform wants testing evidence
SOC 2 reviews and compliance platforms routinely expect recent independent testing of the application. You need a credible, dated artifact, not a marketing badge.
You built fast with AI and you are the one on the hook
The app works and customers are on it. What you cannot produce is independent evidence that one customer cannot read another customer's data. That is precisely what we test and attest.
What you get
The signed attestation letter
A one-page, signed letter stating what was tested, how, when, and the outcome, written to be attached to a vendor security questionnaire or shared with a customer's security reviewer. It names its scope and methodology plainly, which is exactly why reviewers accept it.
The full technical report
Every confirmed finding with evidence (the exact request and a screenshot of what came back), severity graded by real impact, and a plain-English fix for each. No false-positive dump: a human tester verifies the findings before you see them.
A re-test, included
Fix what we found, and we test again at no charge. The letter then states that issues were remediated and re-verified, which is the sentence a security reviewer is actually looking for.
The price
Founding-customer price: $990 for the first five customers, in exchange for a testimonial and permission to name your company as a customer. Mention it on the scoping call.
Our guarantee
If your customer’s security team rejects the letter, you get a full refund. The letter is honest about scope and methodology, which is why it gets accepted; if it does not do its one job for you, you should not pay for it.
How it works
- A 15-minute scoping call (or email thread): your app URL, the roles and test accounts you provide, and your deadline.
- We test your live, deployed app for 2 to 3 days: the automated battery plus an authenticated pass that signs in with your test accounts and attempts real cross-account access, then a human tester verifies every finding that matters.
- You get the report and the letter within 5 business days of scoping. Fix anything found, and the included re-test updates the letter to remediated and re-verified.
The full testing approach, including how findings are confirmed with evidence and graded, is documented on our methodology page. Every letter can be authenticity-checked online by the person you hand it to.
Scope, stated plainly
What we test
- Anonymous database exposure: whether your backend answers to someone with no login at all
- Cross-account access: whether one signed-in user can read another user's private data, tested with two real accounts
- Authentication and session handling: expiry, missing checks on privileged actions, role boundaries you define
- Secrets and keys shipped to the browser
- Transport, headers, CORS, and the exposure surface an outside attacker actually reaches
What we do not
- Your cloud infrastructure, internal network, or employee devices
- Source-code review of private repositories and your dependency tree
- Social engineering, phishing, or physical testing
- Denial-of-service or load testing
- Accredited compliance certification (we attest to our own independent testing; we are not an accredited audit body, and the letter says so)
The letter carries this scope statement verbatim. A security reviewer trusts an artifact that says what it did not cover; an artifact that implies everything was covered gets questioned. For the reviewer on the other side: every testing class is mapped to OWASP Top 10 and WSTG test IDs with CVSS 3.1 scoring on the coverage page.
Questions a careful buyer asks
Is this a penetration test?
No, and the letter never claims to be one. It is an independent application security test: automated dynamic testing of your live app plus a human verifier's pass. Many vendor reviews accept exactly this artifact; some enterprise programs require an accredited manual penetration test by name, and if yours does, we will tell you on the scoping call rather than sell you the wrong thing.
What if my customer's security team rejects the letter?
Full refund. We would rather eat the fee than have you stuck, and every rejection teaches us which reviewers need what. That guarantee is in writing on the letter's cover email.
Why not just run my platform's built-in security scan?
Because it is the builder grading its own homework, and a security reviewer knows it. Platform scans are static checks at generation time. We independently test the running app from the outside, signed out and signed in, and we put our name on the result.
What do you need from me?
Your app's URL, two test accounts (so we can prove whether one user can reach another's data), and written authorization to test, which we send you as a one-page form. Nothing installs into your codebase.
How current does the letter stay?
The letter is dated, and reviewers care about recency. The optional Continuous Verification plan ($99/month) re-tests monthly and refreshes the letter quarterly, so the answer to “when was your last test?” is always “within the last 90 days.”
Have a questionnaire deadline this week? Say so in the email and we will scope same-day.