IT Solution.
Audit · from $360 · non-destructive

You find out what is wrong. And in what order to fix it.

I go through the code, the server configuration and what is visible from outside. The output is a document, not a scanner dump: every finding says what it affects, what it risks and how to fix it. Your operation will not notice the audit happening.

  • Fixed price agreed up front
  • Every finding verified by hand
  • Nothing deleted, no password guessing

When an audit is worth it.

People usually order one in one of four situations.

Before launch

A new application or shop just before it goes live. The cheapest moment — fixes happen while there is no customer data inside yet.

You inherited the site

The supplier left, or you took over a project or a company. Nobody knows what is inside, who holds the access, or whether anything gets updated.

A customer is asking

A large client or an insurer wants proof it is handled. A report with structure and a retest is exactly the document they expect from you.

Something feels off

Odd logins, mail landing in spam, warnings from the hosting provider. The audit says whether it is a problem or just noise.

What gets examined.

The scope is agreed in advance and included — no "that wasn't in the brief".

Website and application

  • Authentication, roles and permissions — who reaches what, and whether it can be bypassed.
  • Forms and file uploads — what can be sent and what the server does with it.
  • The API and its endpoints, including the forgotten ones.
  • Database access and what can be done with it.
  • nginx and PHP configuration, TLS, security headers.
  • What is publicly reachable by accident — config files, backups, source code.
  • Backups: do they exist, are they off the server, and has anyone tried a restore?

Cloud (AWS, Azure)

  • Identities and roles — who holds which rights and how many they actually need.
  • Multi-factor authentication and key management.
  • Networking and what of it sticks out into the internet.
  • Logging and the audit trail — can you tell afterwards what happened?
  • Backups and the recovery scenario, including how long it would take.

The cloud part is handled by Jan Jurko, who works with me on security. You still deal with me.

How it runs.

  1. 1

    A call, fifteen minutes

    You say what you have and what worries you. I say whether an audit covers it and what it would cost. If it does not make sense, I say so straight away — cheaper for both of us.

  2. 2

    Access and scope

    We agree what gets examined and you give me read access. I do not need an administrator account or your people's passwords.

  3. 3

    The audit itself, usually 3–5 working days

    I read the code, the configuration and the database schema and compare them with what the site answers from outside. A finding that fails verification never reaches the report.

  4. 4

    The report and half an hour over it

    You get the document with a one-page summary for whoever decides. We go through it together so you know what it means — rather than deciphering a table.

  5. 5

    Fixes and a retest

    I can do the fixes, or you hand the report to your own supplier. When it is done, I go through what we fixed once more — the retest is included.

What is in the output.

The report always has the same structure, so it still makes sense a year later when somebody else reads it.

How a finding looks in the report
P1 · HIGH RISK                              #07

FINDING    When editing their profile, a user can send
           their own role — the server accepts the whole
           form payload, including fields that do not
           belong there.

IMPACT     Anyone with an ordinary account promotes
           themselves to administrator and reaches the
           data of every client.

FIX        Accept only explicitly allowed fields on the
           server. Roles change separately and only from
           an account entitled to do so.

RETEST     Open — to be verified once the fix is live.

The document contains

  • A summary for whoever decides — no jargon, one page.
  • Findings ordered P0 to P3: what burns today, what within a month, what is cosmetic.
  • For each: what it affects, what it risks, how to fix it. Specifically.
  • What falls under GDPR and what you would have to report if data leaked.
  • A list of what is, on the contrary, in good shape.

How findings are verified

  • Against the code — is it really written that way?
  • Against the live response — does it behave that way in production?
  • What fails either check does not go in. Better fewer findings than a list that is half false.
  • Non-destructive: nothing is deleted, no passwords are brute-forced, nothing found is exploited.

That is why I do not call it a penetration test. A pen test actively breaks in; different discipline, different price. On websites and business applications an audit of code and configuration finds more in practice — and breaks nothing.

Price.

A fixed amount agreed in advance. I am not VAT registered; prices are final.

Website or application

from $360

one-off, retest included

  • Site on a common CMS$360
  • Custom application, API, portalby scope

I quote after a fifteen-minute call — I need to know how big it is.

Cloud environment

by scope

AWS or Azure

  • Identity, network, logging, recovery

Scope differs by orders of magnitude with the number of accounts and services. You get an estimate after the first call.

Fixes

$32 / hour

always after your approval

  • Hour estimate comes with the report

You can do the fixes yourself or hand them to your own supplier — the report is written so that works.

Not sure whether you need an audit? Run the free website diagnostic — it shows whether there is anything to deal with. It does not cover security, but it is a cheaper first step than a call. Czech only for now.

Leave a number, I will call.

Fifteen minutes on the phone is enough for me to say whether an audit makes sense and what it would cost. I call on working days, usually the same day.

Call me back

A number is enough. Nothing else to fill in.

I will use the number only to call you — how I handle personal data.

Or call me directly: +420 530 330 757 or +420 774 509 038. A compromised site gets dealt with immediately — what that looks like.