per month
Release Check.
Every time they ship, it gets checked before it goes live.
A one off review tells you where you stood on one day. Software ships every week.
£450per month
Book a call- PrerequisiteA Build Review, so there is a baseline to check againstStep 1
- Each releaseReviewed before it goes liveStep 2
- MonthlySummary report you can pass onStep 3
- Minimum termThree months, then rolling monthlyStep 4
What gets checked
Every release reviewed
Checked before it reaches your customers, not after
Old findings re-tested
Fixes confirmed rather than assumed, every month
New endpoints checked
As they appear, before anyone else finds them
Dependency monitoring
CVEs matched against your actual stack, not a generic feed
A direct line
For urgent questions between releases
What lands on your desk
A check per release
Short, written, pass or fail with reasons.
A monthly summary
Written so you can hand it to a customer or an insurer unedited.
A same day call
Anything serious reaches you by phone, not in next month's report.
What it does not include
Written down so it cannot become an argument later.
- Unlimited scope. Roughly half a day a month, heavier work is quoted separately
- Emergency incident response, which is a different service
- Writing or fixing your code
How it is tested
Published methodology is what an auditor looks for when accepting a report. Neither ISO 27001 nor SOC 2 names a specific scheme.
- OWASP Testing GuideWeb application coverage
- PTESPenetration Testing Execution Standard
- NIST SP 800-115Technical assessment methodology
Nothing is touched without written authorisation naming the target, the techniques and the dates. Non destructive by default.
Questions people actually ask
Do we need a Build Review first?
Yes. Without a baseline there is nothing to check changes against, and we would be guessing at what normal looks like for your application. The review comes first, then this holds the line.
What if we ship every day?
Then we agree what counts as a release worth checking. Usually that means anything touching authentication, permissions, payments or the HMRC integration. A copy change on your marketing page does not need a security review.
Is there a minimum term?
Three months, then monthly. Long enough to be worth setting up properly, short enough that you are not trapped if it is not earning its place.
What happens if you find something serious?
You hear about it the same day, by phone, not in the monthly report. The report is for the record. Anything urgent is a call.
Can we show the monthly report to customers?
That is what it is for. It is written so you can hand it to a customer running a security review, or to an insurer, without editing it first.
Does this replace our developers' testing?
No, and it should not. They should still test their own work. This catches what people miss in code they wrote themselves, which is a known blind spot rather than a criticism of them.
This starts after the baseline exists
An independent read on what your developers actually delivered. Build Review, £2,500 one off.