Fixed-Scope Assessment
One-off web app, API, or smart contract audit with a defined boundary.
- Kickoff call + written rules of engagement
- Manual testing with reproducible PoCs
- Executive + technical report
- One free retest within 30 days
How we work
Fixed scope, fixed price, fixed timeline. No day-rate ambiguity. No scope creep. No surprise invoices.
See what a report looks like — sample PDFOne-off web app, API, or smart contract audit with a defined boundary.
Teams shipping frequently who need ongoing adversarial coverage.
Companies running invite-only programs who want a signal-heavy researcher.
Codebases you want reviewed the way attackers read code.
Your scope does not fit any of the above — hybrid audits, red-team exercises, emergency triage, compliance-driven audits.
Timeline
Every engagement follows the same reliable cadence. You always know what happens next.
Data handling
Every engagement starts with signed Rules of Engagement and NDA. Nothing happens without paper.
Reports delivered as PGP-encrypted files or through your preferred secure channel (1Password, Bitwarden, Signal).
We collect only what is necessary for the assessment. Any collected evidence is deleted on engagement close.
Findings coordinated with you first. Public disclosure — if any — only after fixes land and with your approval.
Send it over. Proposal back within 48 hours with fixed price and a suggested timeline.