Security and Development Studio · working remotely with clients everywhere

Protect whatyou've built.Grow what's next.

We test software the way attackers do, and we build software that's ready for them. Websites, stores, web apps and mobile apps, for businesses that would rather not find out the hard way.

  • Real breach remediation, alongside government cyber authorities
  • Every finding comes with a fix
  • Reports you can read without a translator

Secure

We break it so they can't.

Come to us when
a client or investor sends a security questionnaire, something looks wrong, or you've never had it checked.
You leave with
every finding written in plain language, ranked by what it would cost you, paired with its fix, and re-tested for free once it's done.
See security services

Build

Security in the design, not bolted on.

Come to us when
you're launching a store, a site, an MVP or a mobile app, or the one you have has outgrown itself.
You leave with
working software you saw every week, shipped with a Kodewall Security Pass, so it doesn't need a pentest afterwards.
See what we build

RetainThe footing both doors stand on

Kodewall Care

Monthly updates, monitoring, backups that are actually tested, and a quarterly mini-audit.

Fractional Tech & Security Lead

Two to four days a month of senior delivery and security leadership, without the hire.

See retainers
We break it so they can't.

Every service is a brick in the same wall.

Three courses: security, development, and the retainers that keep both standing. You don't need to know which brick you need. Start from what's actually happening, and the route lights up.

Start from where you are:
SecureAudit, test, respond
BuildSecure from the first commit
RetainKeep it standing

Kodewall Security Pass

Every build ships with an OWASP Top-10 review, a dependency scan, an auth and session check, and a fix list before go-live.

Included with every build. No exceptions.

We don't publish prices. Each brick is scoped on a short call and quoted in writing, with what's included and what isn't.

Fix, don't just find.

What the scanner says, and what we say.

Five real findings from one store, with the names filed off. A scanner ranks them by CVSS score. We rank them by what they would cost you, and pair each one with the fix. Flip between the two.

01was 04
A shopper can set their own price at checkout, and the store will accept it.
Revenue on every single order. This is the one to fix today.
Recalculate every total on the server and reject any mismatch. One afternoon.
02was 03
Anyone can read any customer’s order by changing one number in the address bar.
Every customer record, and a breach you would have to disclose.
Check that the logged-in user owns the order on every lookup. Half a day.
03was 02
Your back office is one leaked password away from anyone on the internet.
Everything: products, prices, customer data, payouts.
IP allow-list the admin panel and turn on MFA for every staff account. One hour.
04was 05
One password-reset link opens an account as many times as an attacker likes.
Account takeover, mostly of your highest-spending customers.
Expire tokens on first use and after 15 minutes. Two lines of code.
05was 01
An old script library on the marketing pages. Real, worth updating, not an emergency.
Low. It only runs on pages with no login and no checkout.
Update the library in the theme during the next release.

Ranked by what it would cost you. The scanner’s number one is our number five, and the bug that lets shoppers set their own price is at the top, where it belongs.

Every report has the same four parts, in the same order. Methodology: OWASP Top 10, ASVS, MASVS for mobile, PTES for engagement structure. One free re-test with every VAPT.

Executive summary

One page. What's exposed, what it would cost, what to do first.

Risk matrix

Every finding plotted by likelihood and business impact, not just severity.

Findings, each with a fix

Evidence, reproduction steps, and the specific change that closes it.

Re-test log

What was fixed, what was verified, and what's still open.

Battle-tested.

Work we can talk about, without naming names.

Three case files, sanitised for publication. Names, figures and industries are blacked out here and shared on a call once we know who's asking.

Client
(a D2C brand)
Sector
Platform
High-revenue online store, orders/day
Duration
days, engagement to closure
CLOSED

A live breach, a first analysis that missed the root cause, and an attacker who still had a way back in.

The situation

The store had been compromised and was still trading. An earlier investigation had cleaned up the visible damage but stopped there; the way in was still open.

What we did

Led the remediation end to end, working with the government cyber authorities. Traced the attack past where the first pass had stopped, found the systemic weakness underneath it, and managed the fix programme through to closure.

What changed

Full closure, verified by re-test. The platform stayed up for the whole engagement. The client now has monitoring, hardened access and a written incident plan they didn’t have before.

Kodewall Labs · case file 01 · breach remediation · sanitised for publication
Small, senior, accountable.

What working with us looks like.

Six steps, in the same order whether we're testing your software or building it. Here's how they fall across the calendar, and how much of your time each one takes.

Discover

A short call about what you run, what would hurt if it broke, and what a client or investor is asking for.

30 minutes on a callWeek 1 · 30 min call
Scope

A written scope, a signed authorisation letter, and a fixed quote. Testing starts only once both are signed.

One signatureWeek 1 · scope + authorisation
Test

Manual testing with real attacker techniques against the agreed scope. We tell you immediately if we find something you should fix today.

Nothing, unless something is urgentWeeks 2–3 · manual testing
Review

A walkthrough of every finding, in plain language, ranked by what it would cost you rather than by scanner score.

One hour, with whoever fixes thingsWeek 4 · findings walkthrough
Launch

The report lands: executive summary, risk matrix, each finding with its fix. One free re-test once the fixes are in.

Fix the findings, or hire us toWeek 4 · report + free re-test
Care

Optional. Monitoring, updates and a quarterly mini-audit so the next report is shorter than this one.

OptionalAfter launch · mini-audits

A typical VAPT: four weeks from first call to report, and about two hours of your time.

Straight answers.

Questions we get on the first call.

Kodewall Labs is a security and development studio. One team, two practices: we test websites, stores, web apps, mobile apps and APIs the way attackers do, and we build them so they’re ready for attackers. Every finding comes with a fix, every build ships with a Security Pass, and every report is written in plain language.

index · 12 questions · pick a group
not on the list? Ask it in one sentence.

Fill in the blanks below and we reply within one working day.

Go to the form

The studioWho we are, where we are, what it costs.

What does Kodewall Labs do?

Kodewall Labs is a security and development studio that works with clients remotely, wherever they are. It has two practices run by one team. Secure: security health checks, VAPT (vulnerability assessment and penetration testing) for web, mobile and API, e-commerce security audits for Shopify and WooCommerce, and incident response. Build: websites, Shopify and WooCommerce stores, custom web apps and mobile apps, each shipped with a Kodewall Security Pass. Retainers (Kodewall Care and a Fractional Tech and Security Lead) keep both standing.

How much do Kodewall Labs services cost?

Kodewall does not publish prices. Each service is scoped on a short call and quoted in writing, with what is included and what is not. Builds come with a fixed price and a fixed feature list; the Remediation Sprint is priced by scope after a short review of the report; Incident Response is available on retainer or a day rate.

SecureHealth checks, VAPT, store audits, incidents.

What is a Security Health Check and how long does it take?

A Security Health Check is a one-week, light-touch assessment of your external attack surface: every domain, subdomain and exposed service, plus a configuration review of TLS, headers, DNS, mail authentication and admin exposure. You get the top findings ranked by business impact, each paired with a fix, a one-page summary you can hand to a client, investor or board, and a 45-minute walkthrough call. It is paid upfront and most clients start here.

What does a VAPT from Kodewall Labs include?

A VAPT covers web apps, mobile apps and APIs and follows OWASP Top 10, OWASP ASVS, OWASP MASVS (for mobile) and PTES for engagement structure. It is scoped in writing with a signed authorisation letter before any testing. Testing is manual, not just scanner output, and includes authenticated and unauthenticated testing and business-logic flaws such as pricing, permissions, account takeover and payment flows. The report has four parts: an executive summary, a risk matrix, findings each with a fix, and a re-test log. One free re-test is included. A typical VAPT takes about four weeks from first call to report and around two hours of your time.

How are findings ranked in a Kodewall report?

By what each finding would cost your business, not by CVSS score alone. A scanner might rank an outdated script library on a marketing page as critical and a price-manipulation bug in checkout as medium; Kodewall ranks the checkout bug first because it affects revenue on every order. Every finding is written in plain language and paired with the specific change that closes it.

Do you work with Shopify and WooCommerce stores?

Yes. The E-commerce Security Audit reviews checkout and payment flow, price and discount manipulation, every installed app and what it can read, admin, staff and API access, and account takeover and fraud vectors, with a remediation plan prioritised by revenue at risk. Kodewall also builds and rebuilds Shopify and WooCommerce stores, with a security baseline and a Security Pass before go-live.

We think we have been hacked. What should we do?

Write to [email protected] and Kodewall will call back the same day. The Incident Response and Hardening service investigates what happened, contains it, runs the remediation programme end to end, coordinates with CERT-In, banks and payment providers where required, and then hardens access, backups, monitoring and dependencies so the same route is closed for good. The first call is free and immediate.

BuildWhat every build ships with, and how long it takes.

What is the Kodewall Security Pass?

Every build Kodewall ships, whether a website, store, web app or mobile app, goes through the Kodewall Security Pass before go-live: an OWASP Top-10 review, a dependency scan, an authentication and session check, and a fix list. It is included with every build, no exceptions, so the build does not need a separate penetration test afterwards.

How long does a build take, and how much of my time does it need?

A typical store or web app takes about eight weeks from first call to launch: a 30-minute discovery call, a written scope with a fixed price and design direction agreed before any code, weekly 30-minute check-ins where you see working software, a staging walkthrough where you can try to break it, the Security Pass, and then go-live. Launch Sites include 30 days of support after launch, and Kodewall Care is available after that.

Can you fix the findings from another company's pentest report?

Yes. The Remediation Sprint takes any audit or penetration test report, ours or someone else's, triages the findings into a sprint plan, makes the fixes in your codebase or infrastructure with pull requests you can review, re-tests every finding until it is closed, and produces a closure report you can send back to whoever asked for the audit.

RetainCare and leadership after launch.

What is Kodewall Care?

Kodewall Care is a monthly retainer for anything Kodewall has built or tested: platform, dependency and plugin updates every month, uptime and security monitoring with alerts, backups that are tested rather than just taken, a quarterly mini-audit of the external attack surface, and priority support with a named contact.

What is a Fractional Tech and Security Lead?

Two to four days a month of senior delivery and security leadership for a company growing faster than its team, on site or remote. The lead owns the security roadmap and vendor security reviews, oversees agencies, freelancers and in-house developers, represents you in customer and investor security discussions, and sends a monthly written summary of risks, decisions and next steps.

Kodewall Labs · first-call questions · answered in plain languageStill a question? Tell us in one sentence
Plain language.

Tell us in one sentence.

Fill in the sentence and submit. We reply within one working day with clear next steps or a scoping call. Direct engineer response, no sales pitch.

Hi Kodewall, I'm from . We run and we need . Here's the situation: Reach me at .

Sends directly to [email protected]. Encrypted transmission, we reply within one working day.

Live incident? [email protected], same-day reply.

Sent.

Thank you! Your message has been sent directly to our team. We'll reply to your email within one working day.