Services
Fixed scope, fixed deliverable, price agreed before work starts. You should know what you are getting before you ask, so the scope and the output are on this page rather than in a call.
Findings come as diffs, not descriptions, and every one explains why a competent developer would have written it that way in the first place. Reports that read as accusations get ignored; reports that read as patches get merged.
Rather than ask you to take that on trust, there isa complete sample finding — reproduction, impact, root cause, the fix as a diff, and the rule that stops it coming back. It is written on a bug you can check out and reproduce yourself.
Lead engagements
Horizontal access control and payments — where the severe bugs areMulti-tenant isolation audit
Every endpoint tested across tenant boundaries — same role, different organisation. The failure mode scanners are blind to and most pentests never reach.
- Receive
- Findings report — reproduction steps, severity, and the fix as a diff. One retest.
- Timeline
- 5 business days, plus one retest within 30 days
- From
- USD 5,000
Payment integration security review
Signature verification and whether the comparison is constant-time, replay protection, idempotency claimed atomically under concurrent delivery, settlement races, credential handling.
- Receive
- Findings report plus a reconciliation gap analysis. One retest.
- Timeline
- 4 business days, plus one retest within 30 days
- From
- USD 5,000
The floor above covers a single application or integration. Final price depends on endpoint count, number of roles, and how many providers are in scope — and it is fixed in writing before any work begins. Quoting by the hour would only reward me for taking longer.
Also available
Scoped and priced against your codebaseI take build work as well as review work — the same engineering, on the parts where getting it wrong is expensive. If you have a payment integration, a multi-tenant data layer or an auth system to build rather than audit, that is in scope.
- Security-critical build workPayment integrations, multi-tenant data layers, authentication and authorization systems — built rather than reviewed. For teams who would rather have the tenant scoping enforced at the data layer the first time than find it missing in an audit later.
- Secure code reviewA time-boxed review of a defined scope, with findings written as diffs rather than descriptions. Every finding explains why a competent developer would have written it that way.
- Threat modeling workshopA half-day session with your engineering team on a feature before it ships. Trust boundaries, data flows, a STRIDE pass, and a prioritised list of what to fix first.
- CI security pipeline setupSemgrep tuned to your stack, secret and dependency scanning, a pipeline that fails on real issues and stays quiet otherwise — plus a rules repo you own. A finding is a snapshot; a rule is a ratchet.
- Pre-launch security assessmentFixed-scope assessment before a product or major feature goes live. Combines the code review and threat model into a go/no-go with a prioritised fix list.
How an engagement runs
- Scope call. Thirty minutes. What the application does, how many tenants and roles exist, which integrations are in scope. You get a fixed price and a start date.
- Access. Read access to the repository and two accounts per role per tenant, which is what makes horizontal testing possible at all.
- Testing. Daily note on what has been covered. Anything critical is reported the hour it is found rather than held for the report.
- Report. Findings with reproduction steps, severity, and the fix as a diff against your code.
- Retest. One pass over the original findings within thirty days, confirming each fix holds and did not move the problem somewhere else.
paulmk2143@gmail.com