@shv_founder ↗
Services / Web application security audit Moscow · Worldwide

Web application security audit

We test the web on OWASP and business logic: sessions, access, IDOR, injections — severity report, PoC, fix plan.

Why it matters

A breach always costs more than an audit. If you run payments, accounts, or personal data, downtime, reputation damage, and fines hit harder than checking the app before release or scale.

What we do

In this engagement:

  • Scope and threat model — what actually gets attacked in your product, not a generic checklist
  • Manual review + automation — scanners catch the baseline; we dig into logic and edge cases
  • Roles, sessions, IDOR — who can reach what and where access control fails
  • Report with PoC and severity — reproducible findings and a clear fix order
  • Retest after fixes — we verify holes are closed, not just ticketed

How we work

We align on scope and access → test (auth, API, cabinet, integrations) → deliver a report with PoC and priorities → you fix → we retest. Format: written report plus a short walkthrough call. Timeline is set after scoping — it follows attack surface size, not a generic market average.

FAQ

How long does the audit take and what drives the timeline?

Timeline follows attack surface: roles, APIs, cabinets, integrations, and whether a staging environment exists. After a short intake we lock scope and a report date — no vague “a couple of weeks for everything”.

How is pricing set and what’s included?

Price follows scope and depth: what we test, which roles and environments, and whether retest is included. Baseline: threat model, manual plus automated analysis, severity-ranked report with PoC, and fix guidance; retest is a separate step after your patches. We quote a firm range after intake — not a blind rate card.

Next / Your project

Send URL and roles — we’ll scope the audit.