A five-day technical security check. The scope is fixed so it can be approved without a long buying process. Send the form and the scope and price come back in writing within two business days; nothing starts until you’ve agreed both.
Day by day
- Day 1 — access and scope. A short kick-off, read-only access to the cloud accounts and code, and the list of what’s in and out of scope. Nothing we do needs write access.
- Day 2 — outside in. What the internet can reach: domains, exposed services, certificates, forgotten environments, the storage that shouldn’t be public.
- Day 3 — inside. Identity and access, cloud configuration, logging and detection: who can do what, and whether anyone would notice.
- Day 4 — recovery and AI. Backups checked against a real restore, not a green tick. AI features checked for prompt injection, data leaking through the model, and agents with more access than their job needs.
- Day 5 — the readout. Findings ranked by risk, each written as a ticket with the fix, walked through with your team.
What you walk away with
The report and the tickets are yours. Use them with us, with your own team or with anyone else — the review is useful whoever does the work.
What happens after
Most reviews end in one of three places: a Cloud Foundation to rebuild what the review found, Incident Readiness when the gap is what happens on the bad night, or a Build Sprint when the fix is software. Or none of them, if your team has it from here.
If you need someone to own security month to month — a part-time head of security — or the deal also needs policies, a risk register or board reporting, that’s our sister company, Signal & Soil.