Found problems? We can fix them.
A pentest report is only useful if someone acts on it. If you've run a scan and don't have the in-house bandwidth to remediate the findings — or you want a security-aware developer to review the fixes — we can help.
What we do
Security remediation
You have a GetCodeAudit report with findings. We work through them one at a time: implement the fix, run targeted tests to confirm it's resolved, push to your repo. Findings are billed per item; complexity varies wildly so we quote per finding after looking at the report.
Pre-launch hardening
You're about to ship a new app and want a security pair-of-eyes before it goes live. We review your code, run a scan, fix what we find, and put basic monitoring in place. Typical engagement: 1–2 weeks, fixed scope.
Custom development
Beyond security — we also build full-stack PHP, Node.js, React Native, and React applications. If you have a project that doesn't fit a security-only engagement, we can take that on too.
How it works
- Email us with your scan order number (from the confirmation email) and what you'd like help with. If you don't have a scan yet, send a description of what you're building.
- We respond within one business day with a scope and quote. We work in INR or USD.
- 50% upfront, 50% on delivery. For smaller engagements (under ₹50,000) we sometimes do 100% on delivery — depends on the work.
- We work async over email + screen-share calls. Code goes to your repo, not ours.
What we charge
Roughly:
- Per-finding remediation: ₹2,000 – ₹15,000 per finding depending on complexity.
- Pre-launch hardening package: ₹40,000 – ₹1,50,000 fixed-scope.
- Hourly custom development: ₹2,500 – ₹4,000 / hour depending on stack.
Bigger engagements get bulk discounts. We're a small team so we only take on as much as we can do well — there's sometimes a 1–2 week wait to start.
What we don't do
- SaaS retainers or ongoing managed services. One-time engagements only.
- Manual penetration testing as a standalone service. Our scanner is the entry point.
- Compliance audits (SOC 2, ISO 27001, PCI-DSS). We can prepare you for an audit but we aren't auditors.
- Work for clients we believe are doing harm (we reserve the right to decline anything that crosses our line).