Why pay you when Claude or ChatGPT will scan my site for free?
Run one first — genuinely. A model reading your site will spot missing headers, an old library and a stray .env, and it is right often enough to be worth the ten seconds. Then notice what you are holding: a list you cannot check. It cannot log in as two different users to see whether one can read the other's invoices, because it is reading your pages, not exercising your application. It cannot tell you whether a finding is real, because it did not try it — it inferred it, and it will describe something that is not there with exactly the same confidence it describes something that is. And when your customer's security team asks who tested this and what they found, there is nobody to name and nothing to sign. Everything we sell starts where that list stops: we test the half it could not reach, prove what is actually there, and put a signature on the result.
How can this be $50 when everyone else starts at $5,000?
Because it is not the same engagement, and we will not pretend it is. The $50 Verified Exposure Check is one focused pass over your public surface plus one authenticated spot-check, every hit reproduced by hand, delivered in 48 hours with a signed letter. A $15,000 consultancy engagement is two testers for two weeks with a full threat model. Both are honest work; they answer different questions. What we refuse to do is charge $5,000 for the first one — and most companies who need the first one have never been offered it at a price they can approve.
Is this legal? Do you need permission?
Yes, and yes — it is the whole basis of the engagement. Testing a system without written authorisation from its owner is a crime in most countries. We send you a scope and authorisation letter naming the exact systems, the window and the emergency contacts, and you sign it before anything begins. If you are on shared or managed hosting, some providers also want notice; we draft that message for you.
Will the testing break my site or slow it down?
Testing is non-destructive by default and rate-limited to stay well under the load your site already handles. We agree the window in advance, avoid your busiest hours, and give you a direct contact that stops the test immediately, any hour, no reason needed. In eight years the honest answer is that the risk is small but not zero, which is why we prefer to test staging when you have one and why the window is always yours to choose.
Do you need our source code?
No. Everything on this page is black-box or grey-box — we work from the outside, the way an attacker does, with test accounts you create for us. If you do give us code access the test goes deeper and finds more, and we will tell you when that is worth doing.
What if you find nothing?
On the Verified Exposure Check, you are refunded and you keep the report. On the larger engagements it has never happened — a full authenticated pass over a real application always surfaces something, even if it is only hardening work. Either way you finish with a dated document saying an independent party tested this and here is what they found, which is exactly what the customer or auditor asking you for one wants.