Audits · pen testing · CI/CD security

Security built into your development process — not bolted on after

DevSecOps audits, penetration testing, and CI/CD security pipelines for SaaS founders and development teams

The reality

Most SaaS products ship with security vulnerabilities the team doesn't know about

Vulnerable dependencies quietly accumulate with every npm install

API keys accidentally committed to Git sit exposed in history forever

Cloud misconfigurations leave AWS accounts open to attack

Services

Four ways to harden your product

Point-in-time audits, hands-on penetration testing, a security pipeline that runs on every push, or ongoing retainer support — pick what fits your stage.

Security Audit

A systematic review of your codebase, dependencies, and cloud infrastructure. You receive a prioritised written report with exact fixes — delivered in 5 working days.

Includes

  • Dependency scanning (Snyk)
  • Secret detection (Gitleaks)
  • Web app scanning (OWASP ZAP + Burp Suite)
  • AWS infrastructure review (Prowler)
  • Security headers check

Pricing

  • Starter£500

    Dependencies + secrets + headers

  • Standard£950

    Starter + web app scanning

  • Full£1,750

    Standard + AWS infrastructure

Book a scoping call

Penetration Testing

Manual web application penetration testing covering OWASP Top 10. Authentication testing, session management, IDOR vulnerabilities, API security, and injection points — with a written report suitable for compliance evidence.

Includes

  • Burp Suite manual testing
  • OWASP ZAP automated scanning
  • Authentication and session testing
  • IDOR and access control testing
  • Written report with severity ratings and remediation steps

Pricing

  • Web app pen testfrom £800

    Application-focused engagement

  • Infrastructure reviewfrom £1,200

    Cloud & network surface

  • Combined packagefrom £2,000

    App + infrastructure

Book a scoping call

CI/CD Security Pipeline

GitHub Actions security pipeline set up in 3 days — secret scanning, dependency checking, code analysis, and container scanning on every push. Runs forever once set up.

Includes

  • Gitleaks secret scanning
  • Snyk dependency scanning
  • CodeQL static analysis
  • OWASP ZAP DAST
  • Trivy container scanning
  • Checkov IaC scanning
  • Branch protection rules

Pricing

  • Security Pipeline£600

    Core scanning

  • Full DevSecOps£1,200

    Complete coverage

Book a scoping call

Monthly Retainer

Ongoing security support after your audit or pipeline is live — continuous scanning, pipeline maintenance, triage of new findings, and a monthly security posture report so nothing quietly drifts.

Includes

  • Ongoing dependency and secret scans
  • CI/CD pipeline monitoring and maintenance
  • Triage and prioritisation of new findings
  • Monthly security posture report
  • Email support for security questions
  • Pipeline updates as tools and policies change

Pricing

  • Monthly Retainer£450/month

    Ongoing maintenance

Book a scoping call

Credentials

Qualifications and experience

  • CompTIA CySA+ (CS0-003) — Cybersecurity Analyst
  • CompTIA Security+ (SY0-701)
  • ISC2 Certified in Cybersecurity (CC)
  • Microsoft Azure Fundamentals (AZ-900)
  • Cyber Agoge DevSecOps and AI Security Bootcamp

Skills

Tools and practices used on real engagements

Security tooling

SnykOWASP ZAPTrivyCheckovGitleaks / secret scanningCodeQLnpm auditOWASP Top 10GitLab PR security scanningtfsecSecure API design

Cloud & infrastructure

AWS (ECS, ECR, Lambda, API Gateway, VPC, IAM, Cognito, RDS, DynamoDB, SNS, SQS, GuardDuty, ALB, S3, CloudFront)Terraform IaCDockerAzure (AZ-900)IAM least privilegeAWS WAF

CI/CD & DevOps

GitHub ActionsGitLab CITeamCityOctopus DeployBranch protection & PR review workflowsBitbucketGit

FAQ

Common questions

Do I need to give you access to my codebase?

For dependency and code scanning yes — read-only access to your GitHub repository is sufficient. For web application testing I only need the URL of your staging or production environment.

How long does an audit take?

Security audits are delivered within 5 working days. CI/CD pipeline setup takes 3 days. Penetration testing typically takes 3–5 days depending on application size.

Is my code kept confidential?

All client code and findings are treated as strictly confidential. I sign an NDA before any engagement on request. No code or findings are ever shared with third parties.

What if I need ongoing support after the audit?

Monthly retainer options are available from £450/month covering ongoing scanning, pipeline maintenance, and a monthly security posture report.

No commitment

Free dependency scan — no strings attached

Send me your GitHub repository URL and I'll run Snyk against your dependencies and send you the report within 24 hours. No commitment required.

Get your free scan

Ready to talk? Book a free 20-minute scoping call

Tell me where you are in the build — I'll recommend the right engagement.

Book a scoping call