Paid security reviews

I break apps. Before someone else does.

I spend my free time taking apart other people’s apps and reporting what I find. A review is the same process, pointed at your app while it is still your call how it ends. Fixed prices, checkout in a minute, and you talk to the person doing the work.

Pricing

Most popular

Full review

$899per app

Your whole app: client, traffic, and backend. One price, everything included.

  • One app — iOS, Android, or web/SaaS
  • Traffic analysis and client teardown with my own tooling
  • API and backend endpoints in scope
  • Auth and authorization logic: IDOR, sessions, rate limits
  • Every finding manually verified — no raw scanner output
  • Report with reproduction steps, plus a 30-minute debrief call
  • One free re-test after you ship the fixes
  • Delivered within 10 working days
Book the review

Company

from $2,900custom scope

Multiple apps, a larger attack surface, or compliance needs.

  • Scope defined together in a call
  • Multiple apps and platforms
  • NDA and compliance paperwork covered
  • Report suitable for customers and auditors
  • Ongoing re-tests as fixes land
Book a scoping call

You must own the app or be authorized to have it tested. Scope is confirmed before any testing starts — if your app is out of scope for the tier, you get a full refund.

  1. 01

    Book and share your app

    Pick a tier and drop your store page or URL at checkout — or grab a slot in my calendar if you need a custom scope. Not live yet? Leave it empty, we sort out access over email.

  2. 02

    I confirm scope within 24 hours

    A short sanity check that the tier fits your app. If it does not, you get a straight answer and a full refund.

  3. 03

    Report lands in your inbox

    Verified findings, reproduction steps, and fixes. Tell me when you have shipped them and I re-test for free.

What if you find nothing?
You still get the full report: what was tested, how, and why it held up. A documented clean pass is worth having.
Do you need my source code?
No. I test black-box, the same way I approach my public research — and the same way an actual attacker would.
How does the indie price work?
Honor system. If you are building alone and paying out of your own pocket, flip the switch — I will not ask for proof. Same review, same report, same re-test.
Can we sign an NDA?
Happily. Findings from paid reviews are never published without your consent either way — that is part of my disclosure policy.

Not sure which tier fits? Grab 30 minutes with me and I will tell you straight — including when the answer is that you do not need a review yet.

Same rules as my public research

The reviews run under the same constraints I hold to when nobody is paying: my own devices, my own accounts, one request to prove a boundary is broken, nothing destructive, secrets redacted. The one difference is publication. Findings from a paid review are yours, and nothing about them leaves my inbox without your consent.

Read how I test and my disclosure policy