one off
Build Review.
An independent read on what your developers actually delivered.
Your agency says it is done and secure. They are also the only people who can tell you whether that is true.
£2,500one off
Book a call- Day 0Scope call, written authorisation signedStep 1
- Day 1 to 3Testing against your live or staging applicationStep 2
- Day 7Both reports delivered, walkthrough callStep 3
- Within 30 daysRe-test of anything they fixedStep 4
What gets checked
Customer separation
Can one of your customers reach another customer's records
Payment gates
Can an account that has not paid reach paid features
HMRC integration
Fraud prevention headers, token storage, agent authority
Injection and uploads
What reaches your database or disk unescaped
Sessions and auth
Password reset, lockout, how long a token stays alive
What leaks
Stack traces, versions and internal paths in error pages
What lands on your desk
A report you can read
Plain English, ordered by what it would cost if left alone.
A fix list they can act on
Separate technical document, severity ranked, with reproduction steps.
A re-test, included
We confirm their fixes are real. Within 30 days, no extra charge.
What it does not include
Written down so it cannot become an argument later.
- Denial of service or load testing
- Anything you do not own: your host, your CDN, your payment processor
- Social engineering or phishing your staff
- Fixing the code. We check, they build. That separation is the product
How it is tested
Published methodology is what an auditor looks for when accepting a report. Neither ISO 27001 nor SOC 2 names a specific scheme.
- OWASP Testing GuideWeb application coverage
- PTESPenetration Testing Execution Standard
- NIST SP 800-115Technical assessment methodology
Nothing is touched without written authorisation naming the target, the techniques and the dates. Non destructive by default.
Questions people actually ask
How long does a Build Review take?
Two weeks from written authorisation to final report in most cases. Testing itself is two to three days. The rest is writing it up properly, because a report nobody can act on is worthless.
Do you need access to our source code?
It helps but it is not required. Most of the value comes from testing the running application the way a real attacker would, with a normal account. If you can give us read access to the repository, the architecture and secrets review gets much sharper.
Will this disrupt our live service?
No. Testing is non destructive by default. We prove a problem exists and stop there. No load testing, no denial of service, no deleting data. If a check carries any risk at all, we agree it with you first or we run it against staging.
What if you find nothing?
You get a report saying so, with the evidence of what was tested and how. That is a real result and it is worth having in writing when a customer asks. It has not happened yet.
Is a penetration test required for ISO 27001?
Not literally. ISO 27001 never uses the words. In practice you will not pass a credible certification audit without evidence of technical vulnerability testing under Annex A 8.8, and auditors converge on at least annually. The same is true of SOC 2.
Why can you not fix the problems too?
Because then we would be checking our own work, which is the exact problem you hired us to solve. Your developers fix. We re-test, free, within 30 days.
Why this is not already covered.
HMRC's terms require you to test for security vulnerabilities before going live, including regular penetration testing. At production approval HMRC reads your sandbox logs to confirm your fraud prevention headers. Nobody checks the rest.
A review tells you where you stood on one day
Every time they ship, it gets checked before it goes live. Release Check, £450 per month.