Before launch
A new application or shop just before it goes live. The cheapest moment — fixes happen while there is no customer data inside yet.
I go through the code, the server configuration and what is visible from outside. The output is a document, not a scanner dump: every finding says what it affects, what it risks and how to fix it. Your operation will not notice the audit happening.
People usually order one in one of four situations.
A new application or shop just before it goes live. The cheapest moment — fixes happen while there is no customer data inside yet.
The supplier left, or you took over a project or a company. Nobody knows what is inside, who holds the access, or whether anything gets updated.
A large client or an insurer wants proof it is handled. A report with structure and a retest is exactly the document they expect from you.
Odd logins, mail landing in spam, warnings from the hosting provider. The audit says whether it is a problem or just noise.
The scope is agreed in advance and included — no "that wasn't in the brief".
The cloud part is handled by Jan Jurko, who works with me on security. You still deal with me.
You say what you have and what worries you. I say whether an audit covers it and what it would cost. If it does not make sense, I say so straight away — cheaper for both of us.
We agree what gets examined and you give me read access. I do not need an administrator account or your people's passwords.
I read the code, the configuration and the database schema and compare them with what the site answers from outside. A finding that fails verification never reaches the report.
You get the document with a one-page summary for whoever decides. We go through it together so you know what it means — rather than deciphering a table.
I can do the fixes, or you hand the report to your own supplier. When it is done, I go through what we fixed once more — the retest is included.
The report always has the same structure, so it still makes sense a year later when somebody else reads it.
P1 · HIGH RISK #07
FINDING When editing their profile, a user can send
their own role — the server accepts the whole
form payload, including fields that do not
belong there.
IMPACT Anyone with an ordinary account promotes
themselves to administrator and reaches the
data of every client.
FIX Accept only explicitly allowed fields on the
server. Roles change separately and only from
an account entitled to do so.
RETEST Open — to be verified once the fix is live.
That is why I do not call it a penetration test. A pen test actively breaks in; different discipline, different price. On websites and business applications an audit of code and configuration finds more in practice — and breaks nothing.
A fixed amount agreed in advance. I am not VAT registered; prices are final.
from $360
one-off, retest included
I quote after a fifteen-minute call — I need to know how big it is.
by scope
AWS or Azure
Scope differs by orders of magnitude with the number of accounts and services. You get an estimate after the first call.
$32 / hour
always after your approval
You can do the fixes yourself or hand them to your own supplier — the report is written so that works.
Not sure whether you need an audit? Run the free website diagnostic — it shows whether there is anything to deal with. It does not cover security, but it is a cheaper first step than a call. Czech only for now.
Fifteen minutes on the phone is enough for me to say whether an audit makes sense and what it would cost. I call on working days, usually the same day.
I call from +420 530 330 757 or +420 774 509 038, so you know who is ringing.
Or call me directly: +420 530 330 757 or +420 774 509 038. A compromised site gets dealt with immediately — what that looks like.