Skip to content

one off

Build Review.

An independent read on what your developers actually delivered.

Your agency says it is done and secure. They are also the only people who can tell you whether that is true.

£2,500one off

Book a call
  1. Day 0Scope call, written authorisation signedStep 1
  2. Day 1 to 3Testing against your live or staging applicationStep 2
  3. Day 7Both reports delivered, walkthrough callStep 3
  4. Within 30 daysRe-test of anything they fixedStep 4

What gets checked

Customer separation

Can one of your customers reach another customer's records

Payment gates

Can an account that has not paid reach paid features

HMRC integration

Fraud prevention headers, token storage, agent authority

Injection and uploads

What reaches your database or disk unescaped

Sessions and auth

Password reset, lockout, how long a token stays alive

What leaks

Stack traces, versions and internal paths in error pages

What lands on your desk

A report you can read

Plain English, ordered by what it would cost if left alone.

A fix list they can act on

Separate technical document, severity ranked, with reproduction steps.

A re-test, included

We confirm their fixes are real. Within 30 days, no extra charge.

What it does not include

Written down so it cannot become an argument later.

  • Denial of service or load testing
  • Anything you do not own: your host, your CDN, your payment processor
  • Social engineering or phishing your staff
  • Fixing the code. We check, they build. That separation is the product

How it is tested

Published methodology is what an auditor looks for when accepting a report. Neither ISO 27001 nor SOC 2 names a specific scheme.

  • OWASP Testing GuideWeb application coverage
  • PTESPenetration Testing Execution Standard
  • NIST SP 800-115Technical assessment methodology

Nothing is touched without written authorisation naming the target, the techniques and the dates. Non destructive by default.

Questions people actually ask

How long does a Build Review take?

Two weeks from written authorisation to final report in most cases. Testing itself is two to three days. The rest is writing it up properly, because a report nobody can act on is worthless.

Do you need access to our source code?

It helps but it is not required. Most of the value comes from testing the running application the way a real attacker would, with a normal account. If you can give us read access to the repository, the architecture and secrets review gets much sharper.

Will this disrupt our live service?

No. Testing is non destructive by default. We prove a problem exists and stop there. No load testing, no denial of service, no deleting data. If a check carries any risk at all, we agree it with you first or we run it against staging.

What if you find nothing?

You get a report saying so, with the evidence of what was tested and how. That is a real result and it is worth having in writing when a customer asks. It has not happened yet.

Is a penetration test required for ISO 27001?

Not literally. ISO 27001 never uses the words. In practice you will not pass a credible certification audit without evidence of technical vulnerability testing under Annex A 8.8, and auditors converge on at least annually. The same is true of SOC 2.

Why can you not fix the problems too?

Because then we would be checking our own work, which is the exact problem you hired us to solve. Your developers fix. We re-test, free, within 30 days.

Why this is not already covered.

HMRC's terms require you to test for security vulnerabilities before going live, including regular penetration testing. At production approval HMRC reads your sandbox logs to confirm your fraud prevention headers. Nobody checks the rest.

BEFORE HMRC LETS YOUR SOFTWARE GO LIVEHMRC REQUIRESHMRC CHECKSYour API calls are formed correctlyYesYour fraud prevention headers are sent, and accurateYesYou tested for security vulnerabilities before go liveNoYou do regular penetration testingNoYour security controls still workNoSOURCE: HMRC DEVELOPER HUB TERMS OF USE, AND THE MTD PRODUCTION APPROVAL PROCESS

A review tells you where you stood on one day

Every time they ship, it gets checked before it goes live. Release Check, £450 per month.