Line 04 · Vulnerability assessment
Find the holes before someone else does — verified by hand, not just scanned.
A scanner spits out a list, half of it wrong. A real assessment adds the part that matters: a person who removes the false positives, confirms what's genuinely exploitable, scores it, and hands you a fix plan in priority order. Fixed price, with a free retest of every fix.
Offers
Three assessments, each fixed-price, each with a free retest
Every engagement runs under a signed authorization naming the exact systems in scope. Assessing systems without that isn't a service — so it's the one thing there's no flexibility on.
External Vulnerability Assessment
$1,500 + HST
7 business days · signed authorization first · free retest within 30 days
- Everything your business exposes to the internet, assessed the way an outside attacker would look at it
- Service and version discovery, TLS and email-authentication checks, known-vulnerability identification
- False positives removed by hand — you get confirmed findings, not a raw scanner dump
- Every finding with a CVSS v3.1 score, evidence, business impact, and a concrete fix
- Executive summary for you, technical detail for whoever fixes it
GuaranteeFixed price. On time or it's free. A free retest of every remediated finding within 30 days, so you learn whether the fix worked. If nothing above Low severity is found, you pay half.
Web Application Vulnerability Assessment
$2,500 + HST
10 business days · scoped per application · free retest within 30 days
- Your web app or client portal assessed against the OWASP Testing Guide
- Injection, broken access control, authentication and session flaws, misconfiguration
- Authenticated checks across user roles, to find what a logged-in user could reach
- Each finding with evidence, reproduction steps, and a developer-ready fix
GuaranteeFixed price. On time or free. Free retest within 30 days. Findings written so your developers can act on them without a second call.
Internal / Network Vulnerability Assessment
$3,000 + HST
10 business days · authorization and named scope required · free retest within 30 days
- Your internal network reviewed for exposed services, weak configuration, and missing patches
- Identity and access review: over-privileged accounts, MFA gaps, stale credentials
- A prioritized view of what an attacker who got inside could reach
- Findings scored and ordered by what actually reduces your risk
GuaranteeFixed price. On time or free. Free retest within 30 days. A prioritized plan ordered by real risk reduction, not by scanner severity alone.
For most businesses a vulnerability assessment is the right first step, and it's what these fixed-price offers deliver. Full penetration testing — active exploitation — is available by referral to a specialist partner when it's genuinely needed.
Comparable assessments from established firms commonly run well above these prices. These sit below that band deliberately: senior-level rigor, findings verified by hand, and a retest included — without the big-firm overhead.
The method
Aligned to the standards a buyer's insurer recognizes
Every assessment follows recognized guidance — the OWASP Web Security Testing Guide and NIST SP 800-115 — and scores findings with CVSS v3.1. That alignment is what makes the report credible to a client's auditor or cyber-insurer.
What every engagement includes
- A signed authorization naming the exact scope and window, and a stop contact who can halt everything in fifteen minutes.
- Manual analysis, not just tool output — the false positives are removed by a person.
- Confirmation of whether a finding is genuinely exploitable, without destructive testing.
- A report with an executive summary and a technical section, every finding with evidence and a fix.
- A walkthrough call, 14 days of written follow-up, and a free retest of the fixes.
What is never done
- No assessing of any system not named in the signed authorization.
- No denial-of-service or destructive techniques.
- No exfiltration of real data.
- No changes to your systems without written approval of that specific change.
- No compliance certification or "you are now secure" claim. An assessment reports what was found in a window, not a permanent guarantee.