Founding-client pricing 50% off — 25 of 25 places left Book yours →
FD Solutions Security testing

Application & web security testing

You built the app.Nobody has evertried to break it.

Anything can generate you a list of maybes. We log in, reproduce each finding by hand, and hand you a report your engineers can work from and your clients will accept as evidence — signed by a named US company. Fixed price agreed in writing before anything starts.

  • Signed scope and authorisation before a single packet is sent
  • Every finding reproduced by hand — no raw scanner or AI output
  • Retest after you fix, included in the price

Or just pick your situation below — it takes one click.

Reports accepted in merchant onboarding review at

  • Stripe
  • Airwallex
  • Mercury
What this does and does not mean →

The 60-second version

What we do

We try to break into your web app, mobile app or API — with your written permission — and write down everything that worked.

What you get

A report you can act on and forward: what is broken, how bad it is, what it costs you, and exactly how to fix it. Plus a free retest once you have.

What it costs

$50 for a first look, $450 for a proper audit of one application, $1,450 for app plus API plus mobile. Fixed, agreed before we start.

Why not the cheap option

A $200/month scanner emails you a list of maybes no auditor accepts. Every finding here is confirmed by a person first.

Why not the expensive one

A consultancy does the same work well for $5,000–$35,000 with a month's wait. If that fits your budget, hire one. This is for everyone it does not.

How long

48 hours for the first look. Five to ten working days for the bigger engagements.

One click

Not sure which one you need?

Pick the sentence that sounds most like your week.

We would suggest

Full Assessment — $1,450 $2,900

You need a document that will survive being read by somebody else's security team, with a coverage statement and a completion letter you can forward. That is the Full Assessment.

We would suggest

Application Audit — $450 $900

The value is in testing the logged-in application properly before real users arrive — roles, sessions, access control. That is the Application Audit.

We would suggest

Verified Exposure Check — $50 $100

Start cheap and find out. The Verified Exposure Check tells you in 48 hours what you have actually got — including the logged-in half a scan never sees — and the fee comes off a bigger engagement if there is a problem.

We would suggest

Verified Exposure Check — $50 $100

Knowing something might be wrong is not the same as knowing what to fix first. The Verified Exposure Check proves what is actually there, discards what is not, and gives you a ranked list your developer can work straight from.

Do this first

Write to us now, not later

Do not order anything from this page. Write to us now, say that in the first line, and we will reply within hours. Working out how they got in comes before deciding what to buy.

We would suggest

Security Partner — $4,000 $8,000

A point-in-time test goes stale the next time you deploy. The Security Partner retainer tests every quarter, retests without limit, and answers the questionnaires for you.

Fixed prices, published

Four engagements.
Pick one, or ask and we will.

Founding-client pricing — 50% off. The first 25 engagements are half price. We are building the case-study library and putting the report format in front of real auditors, and founding clients get the discount for the feedback. 25 of 25 places left.

Verified Exposure Check

What is actually exploitable — and can I prove it to whoever asked?

$50 $100 one site or app

You save $50

Delivery48 hours
  • One authenticated spot-check: we log in as a real user and try to reach another account's data — the test nothing you run unattended will do for you
  • Every finding reproduced by hand, with the exact request that proves it. Nothing reaches your report unless we made it happen twice
  • A signed attestation letter from a named US company, on letterhead and dated — the document a client, insurer or app store accepts. No model can sign one
  • Full external surface: TLS, headers, cookies, exposed files, known CVEs in your stack, leaked keys, DNS and mail records
3 more included
  • 8–12 page report, plus copy-paste fixes for your actual stack — the config line to change, not “consider hardening your headers”
  • Ask the person who did the testing anything about the report, in writing, for 30 days — answered by them, not by an account manager and not by a chatbot
  • One free re-check within 30 days, to confirm your fix actually worked — rather than taking your word for it

One spot-check, not a full multi-role review: testing every role and every business rule is the Application Audit.

If we find nothing rated Medium or above, you get the fee back and keep the report and the letter.

Book this or ask on WhatsApp

Full Assessment

Can we hand this to a client, an auditor or an investor?

$1,450 $2,900 app + API + one mobile platform

You save $1,450

Delivery10 working days
  • Everything in the Application Audit
  • Your REST/GraphQL API tested against the OWASP API Top 10, authorisation checked endpoint by endpoint and role by role
  • One mobile app (iOS or Android) against OWASP MASVS — storage, certificate pinning, hardcoded secrets, tampering
  • Business-logic testing: pricing, quotas, refunds, invitations, anything where the rules matter more than the code
4 more included
  • Vulnerability chaining — two medium findings that combine into one critical, which is what an actual attacker does
  • Cloud and infrastructure review of the hosting that serves it
  • Machine-readable export (CSV/JSON) straight into Jira or Linear
  • Two retests, and a signed completion letter you can forward to a client without handing over exploit detail

Second mobile platform priced as an add-on.

Written finding-by-finding walkthrough for your engineers, and their follow-up questions answered by the tester.

Book this or ask on WhatsApp

Security Partner

Who is watching this the other 51 weeks of the year?

$4,000 $8,000 per year

You save $4,000

DeliveryContinuous
  • A Full Assessment every quarter across your whole estate
  • Unlimited retests — a finding is not closed until we have confirmed the fix
  • Continuous external monitoring: new subdomains, expiring certificates, exposed services, new CVEs in your stack
  • We fill in your clients' security questionnaires and vendor assessments for you
4 more included
  • Pre-release review of major features before they ship
  • A named engineer who already knows your system, reachable directly
  • Incident support: if something happens, you are not starting from an empty inbox at 2am
  • Annual summary letter for auditors, insurers and enterprise buyers

Scoped to one product estate. Multiple business units quoted separately.

Cancel with 30 days' notice. No annual lock-in.

Book this or ask on WhatsApp

Bigger or more complicated than these? Prices track user roles and privilege boundaries, not page count. Tell us the roles and you get a real number, not a range.

What arrives

A report you can act on —
and forward to whoever asked.

01

Executive summary

02

Coverage statement

03

Attack narrative

04

Findings register

05

Remediation plan

06

Retest appendix

07

Machine-readable export

08

Completion letter

A scanner gives you a list of maybes. This gives you a decision — what to fix first, what it costs you to leave, and something to put in front of the person who asked.

Where this sits

Four ways to buy this.
Three of them stop before the hard part.

How an AI scan, automated scanners, FD Solutions and traditional consultancies compare
  An AI or LLM scanFree – $20 / month Automated scanner$69–$499 / month FD Solutions$50–$4,000 Traditional consultancy$5,000–$35,000
Can log in and test as a real user No Sometimes Yes Yes
Reaches business logic and access control No No Yes Yes
Findings verified by a person No No Yes Yes
Proof the finding is real Described, not shown Raw output Reproduced by hand Yes
False positives you pay a developer to chase Many, stated confidently Many None — cleared first Few
Finds what it was not asked to look for No No Yes Yes
Report a client, auditor or insurer accepts No No Yes Yes
Signed by a liable legal entity No No Yes Yes
Retest after you fix Ask it again Rescan only Included Usually charged
Reach whoever did the testing No No Yes Sometimes
Priced before you commit Yes Yes Yes Quote only
Speed of the first answer Instant Instant 48 hours 2–4 weeks
Cost to run it once Free Trial, then monthly From $50 From $5,000

Comparison prices are published 2026 list prices, checked September 2026. Where those numbers come from →

Already accepted

Our reports have already passed processor review

Clients have submitted reports we wrote as part of merchant onboarding and underwriting review. Those applications were approved.

Stripe

Merchant onboarding review

Airwallex

Merchant onboarding review

Mercury

Merchant onboarding review

This describes outcomes for our clients, not an endorsement. None of these companies has assessed or certified FD Solutions, none is a partner, and we do not display their logos. An onboarding decision belongs to the processor and depends on the business, the model and the paperwork — a security report is one input among several. Anyone promising you an approval is selling you something they do not control.

What the report maps to

Written for the questionnaires you actually get

Your report is structured so the person who asked for it can find what they need without calling you. These are the frameworks it maps to, section by section.

SOC 2

CC4.1, CC7.1

Evidence of independent testing and of remediation

ISO 27001:2022

A.8.8, A.8.29

Technical vulnerability management and secure testing

PCI DSS

Req. 11.3

Annual penetration test. (Quarterly ASV scanning is separate — we are not an ASV, and we say so.)

GDPR

Art. 32(1)(d)

Regular testing of technical measures

HIPAA

§164.308(a)(8)

Periodic technical evaluation

OWASP ASVS / MASVS

L1–L2

The verification level we test to, stated in the report

NIST SP 800-115

Whole

The methodology auditors expect a tester to reference

Cyber insurance

Renewal forms

The questions insurers ask before they quote

We test and report against these frameworks. We are not an auditor, not a certification body and not a PCI Approved Scanning Vendor, and none of these organisations endorses us — a vendor who implies otherwise is telling you something about how they will report on your systems.

Who asks people for this document

Enterprise procurement

The vendor security assessment that arrives attached to a contract you are about to win.

Cyber insurers

Underwriting and renewal questionnaires, which now ask when you last tested and by whom.

SOC 2 and ISO auditors

Evidence for the controls covering technical vulnerability management.

Payment processors and banks

Merchant onboarding and periodic review of businesses that handle card data. Reports we wrote have already been through this at Stripe, Airwallex and Mercury.

App store reviewers

Security grounds for rejection, and what you send back with the next build.

Investors

Technical due diligence, where an untested product is a diligence finding of its own.

Checkout is where the money is

Payment and platform integrations we test

Checkout is where the money is, so it is where we look hardest: webhook signature verification, price and amount tampering, currency handling, refund and void logic, idempotency, and whether your server trusts anything the browser told it about the total.

Global gateways

  • Stripe
  • PayPal
  • Adyen
  • Checkout.com
  • Braintree
  • Square
  • Authorize.Net
  • Mollie

MENA gateways

  • Paymob
  • Fawry
  • PayTabs
  • Tap
  • HyperPay
  • Geidea
  • Telr
  • Kashier
  • Amazon Payment Services

Commerce platforms

  • Shopify
  • WooCommerce
  • Magento
  • Salla
  • Zid
  • OpenCart
  • PrestaShop
  • Custom builds

These are integrations we test inside our clients' applications. None of these companies is a partner, sponsor or endorser of FD Solutions, and we do not display their logos, because doing so would imply a relationship that does not exist.

How it works

Five steps. You know the price at step one.

01

You send it, we scope it

Day 0 — free

Send a URL and one line about what worries you. Inside one working day you get back, in writing, which engagement fits, what it costs and what it does not cover. If the honest answer is that you do not need us yet, that is what you will read — in writing, which is harder to walk back than a sentence on a call.

02

Scope and authorisation in writing

Day 1

A written scope, a fixed price, a testing window and a signed authorisation letter. Nothing on this page moves until you have that document and have agreed to it.

03

The testing window

Days 2–10

We test. Anything Critical is sent to you the hour we confirm it — you do not wait for the report to hear that your admin panel is open to the internet.

04

Report and written walkthrough

On delivery

The full report, plus a finding-by-finding walkthrough in writing: what it is, the request that proves it, and the exact change that closes it. Your engineers reply with questions and the person who found it answers them — so the fixes get made rather than filed.

05

Retest and close

After your fixes

You fix, we verify, the report is reissued showing each finding closed and dated. That version is the one worth sending onward.

What we commit to

Trying us is meant to be low risk.

Fixed price, agreed before we start

The number in your scope document is the number on the invoice. It moves only if you change the scope, and then only with your written agreement.

A clean check is free

If the $50 Verified Exposure Check turns up nothing rated Medium or above, we refund it and you keep the report and the signed letter. We would rather lose the fee than sell you alarm about nothing — which is the opposite of what a tool that has to justify its subscription does.

The retest is in the price

A finding is not closed because you say it is fixed. It is closed because we tested it again. That retest is included, not an invoice you get later.

You are dealing with a real company

FD Solutions LLC, a Wyoming limited liability company with a filing number you can check on the Secretary of State's register, a signed NDA and a contract. Not an anonymous account on a marketplace.

Registered US entity

Wyoming LLC with a filing number you can check on the Secretary of State's public register before you send a penny.

Contract and NDA

A signed scope, an authorisation letter and an NDA — before scoping, not after the invoice.

Non-destructive testing

Rate-limited, windowed, and stoppable by one message at any point in the engagement.

Standards-based

OWASP WSTG, ASVS, MASVS and API Top 10, PTES and NIST SP 800-115 — named in your report, by section.

Before you write

The questions everyone asks.

Why pay you when Claude or ChatGPT will scan my site for free?
Run one first — genuinely. A model reading your site will spot missing headers, an old library and a stray .env, and it is right often enough to be worth the ten seconds. Then notice what you are holding: a list you cannot check. It cannot log in as two different users to see whether one can read the other's invoices, because it is reading your pages, not exercising your application. It cannot tell you whether a finding is real, because it did not try it — it inferred it, and it will describe something that is not there with exactly the same confidence it describes something that is. And when your customer's security team asks who tested this and what they found, there is nobody to name and nothing to sign. Everything we sell starts where that list stops: we test the half it could not reach, prove what is actually there, and put a signature on the result.
How can this be $50 when everyone else starts at $5,000?
Because it is not the same engagement, and we will not pretend it is. The $50 Verified Exposure Check is one focused pass over your public surface plus one authenticated spot-check, every hit reproduced by hand, delivered in 48 hours with a signed letter. A $15,000 consultancy engagement is two testers for two weeks with a full threat model. Both are honest work; they answer different questions. What we refuse to do is charge $5,000 for the first one — and most companies who need the first one have never been offered it at a price they can approve.
Is this legal? Do you need permission?
Yes, and yes — it is the whole basis of the engagement. Testing a system without written authorisation from its owner is a crime in most countries. We send you a scope and authorisation letter naming the exact systems, the window and the emergency contacts, and you sign it before anything begins. If you are on shared or managed hosting, some providers also want notice; we draft that message for you.
Will the testing break my site or slow it down?
Testing is non-destructive by default and rate-limited to stay well under the load your site already handles. We agree the window in advance, avoid your busiest hours, and give you a direct contact that stops the test immediately, any hour, no reason needed. In eight years the honest answer is that the risk is small but not zero, which is why we prefer to test staging when you have one and why the window is always yours to choose.
Do you need our source code?
No. Everything on this page is black-box or grey-box — we work from the outside, the way an attacker does, with test accounts you create for us. If you do give us code access the test goes deeper and finds more, and we will tell you when that is worth doing.
What if you find nothing?
On the Verified Exposure Check, you are refunded and you keep the report. On the larger engagements it has never happened — a full authenticated pass over a real application always surfaces something, even if it is only hardening work. Either way you finish with a dated document saying an independent party tested this and here is what they found, which is exactly what the customer or auditor asking you for one wants.

Trust, but check

Do not take our word for any of this

We have no testimonials on this page yet, and we are not going to invent any. Here is what you can check for yourself instead, right now, before you send us anything.

The company is real and you can look it up

FD Solutions LLC is a Wyoming limited liability company, filing ID 2024-001572946. Search that number on the Wyoming Secretary of State's public business register and you will find the entity, its status and its formation date.

Wyoming business search →

This site runs the controls we sell

Content-Security-Policy of default-src 'none'. HSTS with preload. No JavaScript, no third-party scripts before consent, no cookies you did not agree to. Check the response headers yourself — that is a two-second job and it tells you more than any badge.

Our security policy →

We publish a security.txt, and a refusal to be tested

A machine-readable disclosure policy at /.well-known/security.txt, and a published position that no authorisation to test this site is granted to anyone. We ask our clients for written authorisation; we hold ourselves to the same rule.

security.txt →

The terms are published before you buy

Contract terms, privacy policy, refund policy and our full rules of engagement are all readable now, without talking to anyone. Nothing about the deal is revealed only after you have committed.

Rules of engagement →

Your data is handled to stated numbers

Evidence destroyed 30 days after the report is accepted. Reports kept 12 months, then deleted. Deletion on request within 5 working days, confirmed in writing. Numbers, not adjectives.

How your data is handled →

You can see the work before you buy it

Two complete worked findings are published — the evidence, the severity reasoning and the fix — so you can judge the quality of the reporting rather than trusting a description of it.

Two worked findings →

Confidentiality & legal

What happens to what we learn about you

Buying a penetration test means handing someone a map of exactly how to get in, and then trusting them with it. That is the real risk of this purchase — not the price — and it deserves specifics rather than a padlock icon.

A mutual NDA before you tell us anything

Signed at first contact, not at invoice — so the conversation where you describe what worries you is already covered. It binds both directions and it does not expire with the engagement. If your own NDA is easier for your legal team, send it and we will sign yours instead.

Your systems never go into an AI service

No part of your application, your evidence, your credentials or your report is pasted into a chatbot, an assistant or any hosted model — ours or anyone's. The irony of a security vendor leaking your architecture into a third party's training data is not lost on us. Tooling runs locally, under our control.

If we are the ones who leak it

You are told within 24 hours of us knowing, in writing, with what was exposed, when, and what we have done — before we have finished investigating, not after. You get that in the contract, because a vendor who only promises to notify you when the news is complete is promising to notify you late.

Where your data actually is

FD Solutions LLC is a Wyoming limited liability company. Work is performed remotely from Cairo, Egypt, on encrypted machines we control — not on a subcontractor's laptop and not in a third-party findings portal. We state the geography plainly because your vendor assessment will ask, and because you should not discover it after signing.

We test only what you authorise, in writing

A signed authorisation letter naming exact hosts, a window and stop contacts is the legal basis for the whole engagement — for you and for us. Without your signature on it, testing your systems would be a crime, and we do not start without it. It is published in full before you enquire.

A real contract, in a real jurisdiction

Filing number 2024-001572946 on the Wyoming Secretary of State's public register, checkable before you send a penny. The engagement runs under written terms governed by Wyoming law, with a court that has jurisdiction over us — which is the thing a marketplace freelancer cannot offer you at any price.

The full terms, the privacy policy and the rules of engagement are published, not sent on request. Rules of engagement → · How your data is handled →

Start here

Three questions.
You get a price the same day.

No sales sequence, no discovery deck — one reply from the engineer who would run the test, with the engagement that fits, the price and the earliest window. If you do not need us yet, that is what the reply says.

  • Answered within one business day — within hours if you are under attack now
  • NDA signed before scoping, as standard
  • Nothing is tested until you have signed the scope and authorisation
Stripe

Card payments are processed by Stripe Checkout. Card details go straight to Stripe and never touch our servers.

Bank transfer also available, invoiced from the US entity.

Or email fadi@fd-sol.com · +20 106 869 4544

A URL or an app store link, and one line about what worries you. That is genuinely enough — we ask the rest by email.

Add more detail (optional — speeds up the quote)
No newsletterOne reply, from an engineer Your data
WhatsApp Get a price