What buyers, security teams and legal ask before they commit — the hunt, the price, code access, and where your data lives. Every answer ends with the next step.
You get a human-verified PoC on every finding and a signed report. The researcher is named in the contract and reachable during the test and at the readout. Right now that is Samir Abis.
Trust →Fixed scope, fixed price, report guaranteed. A bounty gives you no coverage and no timeline, and you only pay when someone finds something. You need that report for SOC 2 anyway.
See the pricing →It complements one. A scanner lists what might be there, and you verify every flag yourself. We prove what an attacker can actually do — working PoC, named researcher, signed NIS2 / ISO report a scanner cannot produce. The scanner keeps its job.
Start the free check →We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive happens without written sign-off.
Sample report →From €9,900/year for one surface, every release, billed annually — monthly also available. Both in writing before we start. No per-scan billing, ever.
Start the free check →The deep audit runs once, from €3,500, with one retest included — for NIS2, SOC 2, or the board.
Sample report →Additional app or API surface, mobile or cloud scope, and code-assisted scope (+€1,500 audit / +€5,000/year). Every increment is flat, and every number comes in writing.
Contact →Onboarding, scoping, the report, and NIS2 / ISO 27001 evidence mapping — all included. No metered hours, no surprise line items.
Trust →You pay the flat fee upfront. No validated High or Critical in the signed report for the agreed scope: you get the money back — 100 %, within 14 days of delivery. The full terms are in the contract.
The guarantee →Yes. Give us repo access; the agent reads every release's diff for data-flow issues, missing auth checks, and framework-specific misconfigs. Findings come with file:line references and a working PoC. You ship, the code is read, the logic is retested. Flat add-on, in writing.
Contact →In the EU only. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), used only after your consent. Encrypted in transit and at rest, least-privilege access, append-only logging.
Privacy →You are the controller, we are the processor — under a DPA (Art. 28 GDPR). A data-protection incident is reported to you within 24 hours.
DPA (Art. 28) →The report is signed — advanced electronic signature (eIDAS, PAdES-B-T) plus a qualified timestamp — and kept for 10 years. It is yours.
Sample report →The named researcher signs every report. Insurance: €50M per claim, without deductible (AGB §14). Before anything runs, your written authorization with rules of engagement is in force for 90 days.
Trust →Ask it directly — a named person answers, in writing, the same day.