Skip to content

per month

Release Check.

Every time they ship, it gets checked before it goes live.

A one off review tells you where you stood on one day. Software ships every week.

£450per month

Book a call
  1. PrerequisiteA Build Review, so there is a baseline to check againstStep 1
  2. Each releaseReviewed before it goes liveStep 2
  3. MonthlySummary report you can pass onStep 3
  4. Minimum termThree months, then rolling monthlyStep 4

What gets checked

Every release reviewed

Checked before it reaches your customers, not after

Old findings re-tested

Fixes confirmed rather than assumed, every month

New endpoints checked

As they appear, before anyone else finds them

Dependency monitoring

CVEs matched against your actual stack, not a generic feed

A direct line

For urgent questions between releases

What lands on your desk

A check per release

Short, written, pass or fail with reasons.

A monthly summary

Written so you can hand it to a customer or an insurer unedited.

A same day call

Anything serious reaches you by phone, not in next month's report.

What it does not include

Written down so it cannot become an argument later.

  • Unlimited scope. Roughly half a day a month, heavier work is quoted separately
  • Emergency incident response, which is a different service
  • Writing or fixing your code

How it is tested

Published methodology is what an auditor looks for when accepting a report. Neither ISO 27001 nor SOC 2 names a specific scheme.

  • OWASP Testing GuideWeb application coverage
  • PTESPenetration Testing Execution Standard
  • NIST SP 800-115Technical assessment methodology

Nothing is touched without written authorisation naming the target, the techniques and the dates. Non destructive by default.

Questions people actually ask

Do we need a Build Review first?

Yes. Without a baseline there is nothing to check changes against, and we would be guessing at what normal looks like for your application. The review comes first, then this holds the line.

What if we ship every day?

Then we agree what counts as a release worth checking. Usually that means anything touching authentication, permissions, payments or the HMRC integration. A copy change on your marketing page does not need a security review.

Is there a minimum term?

Three months, then monthly. Long enough to be worth setting up properly, short enough that you are not trapped if it is not earning its place.

What happens if you find something serious?

You hear about it the same day, by phone, not in the monthly report. The report is for the record. Anything urgent is a call.

Can we show the monthly report to customers?

That is what it is for. It is written so you can hand it to a customer running a security review, or to an insurer, without editing it first.

Does this replace our developers' testing?

No, and it should not. They should still test their own work. This catches what people miss in code they wrote themselves, which is a known blind spot rather than a criticism of them.

This starts after the baseline exists

An independent read on what your developers actually delivered. Build Review, £2,500 one off.