# Kodewall Labs > Kodewall Labs is a Security and Development Studio working remotely with clients anywhere. One team, two practices: we test software the way attackers do (security health checks, VAPT for web, mobile and API, e-commerce security audits for Shopify and WooCommerce, incident response), and we build software that is ready for them (websites, Shopify and WooCommerce stores, custom web apps, mobile apps), every build shipped with a Kodewall Security Pass. Every finding comes with a fix, and every report is written in plain language and ranked by business cost rather than scanner score. - Website: https://www.kodewalllabs.com/ - Enquiries and quotes: hello@kodewalllabs.com (reply within one working day) - Live security incidents: security@kodewalllabs.com (same-day reply) - Location: remote-first; serves clients anywhere - Tagline: Protect what you've built. Grow what's next. - Methodologies: OWASP Top 10, OWASP ASVS, OWASP MASVS (mobile), PTES - Build stack: Shopify, WooCommerce, WordPress, React, Node.js, Laravel, Flutter - Pricing: not published; each service is scoped on a short call and quoted in writing ## Services ### Secure (audit, test, respond) - **Security Health Check**: A one-week, light-touch assessment of your external attack surface: what an attacker can see and reach from outside, how your services are configured, and the handful of findings that actually matter, ranked by what they would cost you. Includes an attack-surface map, configuration review, a one-page summary and a 45-minute walkthrough. - **VAPT: web, mobile and API penetration testing**: A full vulnerability assessment and manual penetration test of your web app, mobile app or API following OWASP Top 10, ASVS, MASVS and PTES methodology. Authenticated and unauthenticated testing, business-logic testing, executive summary, risk matrix, findings with fixes, re-test log, and one free re-test. - **E-commerce Security Audit (Shopify and WooCommerce)**: A store-specific security audit for Shopify and WooCommerce: checkout and payment flow, price and discount manipulation, third-party app permissions, admin and staff access, account takeover and fraud vectors, with a remediation plan prioritised by revenue at risk. - **Incident Response and Hardening**: Investigation and containment of a breach, a remediation programme managed end to end, coordination with CERT-In, banks and payment providers where needed, and hardening across access, backups, monitoring and dependencies. First call is free and immediate. ### Build (secure from the first commit) - **Launch Site**: A fast, credible website for a professional firm or growing business: static or hardened CMS, up to eight pages, mobile-first, with SEO basics, SSL, security headers, admin hardening, backups, a Kodewall Security Pass and 30 days of post-launch support. - **Shopify or WooCommerce Store Build or Rebuild**: A Shopify or WooCommerce store built or rebuilt for speed, conversion and a security baseline: theme customisation, app stack, checkout, payment, shipping and marketing integrations, with a Kodewall Security Pass before go-live. - **Custom Web App**: A scoped MVP, internal tool or customer portal with authentication, roles and permissions, database, admin panel and integrations, built with security in the design and reviewed before launch. Fixed price, fixed feature list. - **Mobile App (iOS and Android)**: A cross-platform iOS and Android app with backend, authentication and push notifications, taken through App Store and Play Store submission, with a security review against OWASP MASVS before release. - **Remediation Sprint**: A fixed-scope sprint that fixes the findings from any penetration test or audit report, ours or someone else's, with reviewable pull requests, re-testing until every finding is closed, and a closure report. ### Retain (keep it standing) - **Kodewall Care (monthly maintenance retainer)**: Monthly maintenance for anything Kodewall has built or tested: platform, dependency and plugin updates, uptime and security monitoring, tested backups, a quarterly mini-audit of the external attack surface, and priority support with a named contact. - **Fractional Tech and Security Lead**: Two to four days a month of senior delivery and security leadership: architecture decisions, security roadmap, vendor and agency oversight, and representation in customer and investor security discussions, with a monthly written summary. - **Kodewall Security Pass**: Included with every build: an OWASP Top-10 review, a dependency scan, an authentication and session check, and a fix list before go-live, so the build does not need a separate penetration test afterwards. ## Who it is for D2C and e-commerce brands on Shopify or WooCommerce, SaaS and startup teams facing customer or investor security questionnaires, SMBs, clinics and professional firms that need a credible hardened website, founders who need an MVP or a fractional technical and security lead, and any business that has been breached or warned by a partner, bank or customer. ## How engagements run Six steps in the same order for tests and builds: Discover (30-minute call), Scope (written scope, signed authorisation, fixed quote), Test or Build, Review (plain-language walkthrough), Launch (report with free re-test, or Security Pass and go-live), Care (optional retainer). A typical VAPT takes about four weeks and two hours of the client's time; a typical store or web app takes about eight weeks with a 30-minute weekly check-in. ## Reports Every report has four parts: an executive summary, a risk matrix (likelihood × business impact), findings each paired with a specific fix, and a re-test log. One free re-test is included with every VAPT. ## Optional - Full detail: https://www.kodewalllabs.com/llms-full.txt - Sitemap: https://www.kodewalllabs.com/sitemap.xml - Security contact (RFC 9116): https://www.kodewalllabs.com/.well-known/security.txt