Security and speed audit for your website
Find out what your site is leaving open before somebody else finds it, and which pages load slowly enough that people leave before they see your prices.
This is for you if any of this sounds familiar
You take payments or hold customer data
If there is a login, a form, or a checkout on your site, the thing that hurts you is not downtime. It is customer data walking out while everything on screen still looks normal.
Someone else built it and nobody has touched it since
A site that has not been updated in a year usually has holes that are public knowledge by now. Those are the ones that get hit, because finding them takes no skill at all.
Sales dropped and nobody can say why
Sometimes it is not marketing. It is a page that takes more than three seconds to load on a phone, and people leave before they ever see the product.
You want to try working with me before a bigger project
This is the cheapest thing I sell and the fastest to show a result. You get to see how I work and what my reports look like before you hand me anything larger.
Three packages. Pick the one that matches what you actually need
These are full project prices, not starting points that grow later. If anything falls outside the scope, I tell you the number before I start on it.
- OWASP Top 10 testing against your public site
- SSL, security headers, and settings that are open when they should not be
- Speed check on your main page, mobile and desktop
- PDF report in English, sorted by severity, with the fix written out for each finding
- Contract in English covering scope, delivery date, and who owns what I produce
- 60 days to ask me follow-up questions after handover
- Testing behind the login
- Me doing the fixes
- Everything in the external review
- Testing behind the login, including what each user role can reach
- Payment steps and file uploads tested
- Every page that matters, not only the home page
- Video walkthrough where I explain the findings in plain English
- Report written for two readers: you, and whoever does the fixing
- Replies inside stated working hours, written in your time zone
- Me doing the fixes
- Everything in the authenticated test
- I fix every high and critical finding myself
- Retested after the fixes so you can see they actually closed
- The three slowest pages sped up
- Any code I write comes with English comments and a README your own developer can read
- A plain list of what is left for you to handle, and why I left it
- 60 days of follow-up on everything I touched
Not included in any package, and I am telling you before you pay
- Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
- A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
- Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
- Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
- Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.
How it works, from first message to launch
Send me the link
The URL on its own is enough to start. For the authenticated test I also need a throwaway test account.
Permission and scope in writing
Before I touch anything I need written confirmation from you that the site is yours. You also get a short contract in English covering scope, the delivery date, and who owns what I produce.
I test it
My own tools do the first pass, then I go through by hand for the things tools do not catch. You never get raw scanner output handed to you as a report.
Report, walkthrough, then 60 days of questions
You get the PDF, and from the authenticated test up, a video where I talk through it. After handover you can keep asking me questions for 60 days.
Questions people ask about this service
Will the testing take my site down?
No. By default I test in a way that does not disturb live traffic. If there is a check that could affect the system, I ask permission first and schedule it for your quietest hour.
Do I have to give you passwords?
Not for the external review. For the authenticated test I ask you to create a fresh test account instead of sharing a real one, and you can delete it the moment I am finished.
I am not technical. Will I understand the report?
Yes. It is written in two parts. The first is for you: what the risk is and what to deal with first. The second is for whoever does the fixing, with the technical detail. From the authenticated test up there is also a video where I talk you through it.
Can my own developer do the fixes instead of you?
Yes, and the report is written so they can. It is all in English, and I do not hold anything back to keep you tied to me. If you would rather I did the work, that is the third package.
Are you a certified security firm?
No. I am one developer working alone, with no company behind me and no security certificate on the wall. What I can show you instead is the code. The tools I test with, raidkit and raidscan, are public on GitHub, and I will send you a sample report before you pay anything.
What are your hours and how fast do you reply?
I am in Thailand, GMT+7. I answer within one business day and the reply window goes in the contract converted to your time zone, so there is nothing to guess at. Everything runs in writing, and no call is required at any point.
Often booked together
Send me the link and I will look at it first
I do a quick pass for free and tell you which level your site actually needs.
Reply within one business day, in writing. No call needed.