Security Health Check
A one-week, light-touch assessment of your external attack surface: what an attacker can see and reach from outside, how your services are configured, and the handful of findings that actually matter, in order of what they would cost you.
Who it's for. E-commerce brands, SaaS founders, and anyone who has never had an assessment and wants a clear starting point. Paid upfront; most clients start here.
- External attack surface map of every domain, subdomain and exposed service
- Configuration review: TLS, headers, DNS, mail authentication, admin exposure
- Top findings ranked by business impact, each with a fix
- A one-page summary you can hand to a client, an investor or your board
- A 45-minute walkthrough call
VAPT: web, mobile and API
A full vulnerability assessment and manual penetration test of your web app, mobile app or API, following OWASP and PTES methodology. Automated scanning finds the obvious; the manual work finds the logic flaws that scanners never will.
Who it's for. SaaS and startup teams who need a report to pass a customer or investor security questionnaire, and any business that wants to know what a determined attacker would actually find.
- Scoped in writing, with a signed authorisation letter before any testing
- Authenticated and unauthenticated testing against OWASP Top-10, ASVS and MASVS
- Business-logic testing: pricing, permissions, account takeover, payment flows
- Executive summary, risk matrix, findings with fixes, re-test log
- One free re-test once fixes are in
E-commerce Security Audit
A store-specific audit for Shopify and WooCommerce: payment flow, third-party app permissions, admin and staff access, fraud vectors, and where customer data leaks. Written for the person who owns the store, not the person who built it.
Who it's for. D2C brands on Shopify or WooCommerce who have never had the store itself assessed, and brands whose payment provider or marketplace is asking questions.
- Checkout and payment flow review, including price and discount manipulation
- Every installed app, what it can read and what it actually needs
- Admin, staff and API access review, including old accounts and shared logins
- Account takeover and fraud vectors
- Remediation plan, prioritised by revenue at risk
Incident Response and Hardening
When something has already gone wrong, or nearly did. We investigate what happened, contain it, manage the remediation programme end to end, and coordinate with the authorities where required. Then we harden the platform so the same route is closed for good.
Who it's for. Businesses that have been breached, have seen something they can't explain, or have been warned by a partner, a bank or a customer.
- Investigation and containment, with a timeline of what the attacker did
- Coordination with CERT-In, banks and payment providers where needed
- Remediation programme run by us, with your team or ours doing the fixes
- Hardening across access, backups, monitoring and dependencies
- Available on retainer or a day rate; a first call is free and immediate
Launch Site
A fast, credible website for a professional firm or a growing business: static or on a CMS, up to eight pages, mobile-first, with the SEO basics done and the hardening finished before it goes live.
Who it's for. SMBs, clinics, firms and founders who need a site that looks like they mean it and won't be defaced or hijacked the week after launch.
- Up to eight pages, designed and built, mobile-first
- Static build or hardened WordPress / CMS, your choice
- SEO basics: structure, metadata, speed, sitemap
- SSL, security headers, admin hardening and backups
- Kodewall Security Pass and 30 days of support after launch
Store Build or Rebuild
A Shopify or WooCommerce store built, or rebuilt, for speed, conversion and a security baseline you can stand behind before your first order. Theme customisation, app stack, checkout and integrations included.
Who it's for. Brands launching a store, and brands whose current store has grown into a tangle of apps, slow pages and unknown access.
- Theme customisation or a fresh build on Shopify or WooCommerce
- App stack selected for what it needs, not what it asks for
- Checkout, speed and conversion optimisation
- Payment, shipping and marketing integrations
- Security baseline and Kodewall Security Pass before go-live
Custom Web App
A scoped MVP, internal tool or customer portal with authentication, database and an admin panel, built with security in the design and reviewed before launch. Scoped tightly so it ships.
Who it's for. Founders who need a first version, and operations teams who need a tool that replaces a spreadsheet and a prayer.
- Written scope with a fixed price and a fixed feature list
- Authentication, roles and permissions done properly
- Database, admin panel and the integrations you actually need
- Kodewall Security Pass before launch
- Handover with documentation, or we keep running it under Care
Mobile App
A cross-platform iOS and Android app with its backend, taken through store submission, with a security review against OWASP MASVS before release.
Who it's for. Products that need to live in a customer's pocket, and businesses whose field teams need a tool that works offline.
- Cross-platform build for iOS and Android from one codebase
- Backend, authentication and push notifications
- App Store and Play Store submission handled
- Security review against OWASP MASVS before release
- Post-launch support and updates under Care
Remediation Sprint
We fix the findings from any audit, ours or someone else's, and re-test until they're closed. A fixed-scope sprint that turns a report into a solved problem.
Who it's for. Anyone holding a pentest report and no engineers with time to act on it. This is where our two practices meet.
- Findings triaged and grouped into a sprint plan
- Fixes made in your codebase or infrastructure, with pull requests you can review
- Re-test of every finding until it's closed
- A closure report you can send back to whoever asked for the audit
- Priced by scope after a short review of the report
Kodewall Care
Monthly maintenance for anything we've built or tested: updates, monitoring, backups, a quarterly mini-audit, and priority support when something goes wrong.
Who it's for. Businesses that want their site, store or app looked after by the people who understand how it could be attacked.
- Platform, dependency and plugin updates every month
- Uptime and security monitoring with alerts
- Backups tested, not just taken
- Quarterly mini-audit of the external attack surface
- Priority support with a named contact
Fractional Tech and Security Lead
Two to four days a month of senior delivery and security leadership for a company growing faster than its team. Architecture decisions, vendor and agency oversight, security posture, and the hard conversations with customers' security teams.
Who it's for. Founders who need a senior technical head in the room but aren't ready to hire one full time.
- A fixed number of days each month, on site or remote
- Ownership of the security roadmap and vendor security reviews
- Oversight of agencies, freelancers and in-house developers
- Represents you in customer and investor security discussions
- Monthly written summary of risks, decisions and next steps
We don't publish prices. Each brick is scoped on a short call and quoted in writing, with what's included and what isn't.