Services · Piqua, Ohio

The Work.

Four engagements. Each one is fixed in scope, fixed in fee, and written down before we touch anything. Below is exactly what you get, how long it takes, and what it costs — no sales sequence to sit through first.

Request a scope

01 · The Four Engagements

In Full, With Prices

01 — Offensive

Penetration Test

From $7,400per engagement

We test your web app, API, and network the way an attacker would — by hand, not just with a scanner. Every finding is chained to real impact, and a retest is baked in once you've patched.

  • External & internal network testing
  • Web application & authenticated user testing
  • REST / GraphQL API abuse and authorization checks
  • Manual exploitation of chained issues
  • Findings ranked by exploitability, not CVSS alone
  • One free retest of fixed items
1–2 weeks testing Retest included Engineer + exec report
02 — Review

Security Audit

From $4,600per engagement

A structured review of your cloud config, access controls, and how code ships. We rank findings by what an attacker would reach first — the right engagement before you add headcount or open a new environment.

  • AWS / GCP / Azure configuration review
  • IAM & access-sprawl assessment
  • Secrets handling and logging review
  • CI/CD and deployment pipeline checks
  • Prioritised, mapped remediation list
1 week Config + access focus No production disruption
03 — Compliance

SOC 2 Readiness

From $11,200per engagement

A gap assessment against the Trust Services Criteria, a mapped list of what to fix, and the evidence you'll actually need in front of the auditor — so your Type I or Type II is a formality, not a scramble.

  • Trust Services Criteria gap assessment
  • Control-by-control fix list, mapped to criteria
  • Evidence checklist for Type I / Type II
  • Policy review against real practice
  • Auditor-handoff summary
3–6 weeks Type I or Type II Audit-firm neutral
04 — Compliance

HIPAA Readiness

From $5,900per engagement

A risk analysis and safeguards review for practices and health-tech handling PHI — written to survive an actual OCR question, not just to tick a box. Mapped to real safeguards you can put in place.

  • Security Rule risk analysis
  • Administrative, physical & technical safeguards review
  • PHI data-flow mapping
  • Business Associate exposure check
  • Remediation plan with owners
2–4 weeks PHI focus OCR-ready documentation

Not sure which one fits? Tell us the timeline

02 · How A Job Actually Runs

Kickoff To Retest

01

Scoping call

A free 30 minutes to understand what you're running and what's driving the date. No obligation, no deck.

02

Written scope

Targets, rules of engagement, dates, and fee — all in writing, with a signed authorization before we begin.

03

Testing window

We work the agreed targets during the agreed window, stay reachable, and flag anything fragile rather than break it.

04

The report

An engineer-grade findings document, a remediation-ranked action list, and a summary a board can read.

05

Readout

A live walkthrough with your team — questions answered, priorities agreed, nothing left to interpret.

06

Retest

Once you've patched, we confirm the fixes held. On pen tests, that retest is included — not billed again.

03 · Add To Any Engagement

Extra Scope, Extra Cost

These bolt onto a pen test, audit, or readiness engagement. Prices are per item and confirmed in the same written quote — nothing gets added mid-job without your sign-off.

Additional application

A second web app or portal tested to the same depth as the primary target.

+$2,200

Phishing simulation

A controlled social-engineering campaign against your team, with a report on who clicked and why.

+$3,400

Cloud config deep-dive

An expanded review of a single cloud environment — IAM, network, and data stores in detail.

+$3,800

Board readout deck

A short, plain-language slide deck of the findings for a board or an investor's security review.

+$950

Remediation session

A half-day working session where we sit with your engineers and fix the top items together.

$1,200 / half-day

White-label report

For MSPs and agencies — the assessment rebranded to hand a client, with our methodology cited.

+$1,450

04 · Start The Conversation

Request A Scope

Tell us what you're running and what's driving the timeline. We'll reply within one business day with a scope, a fee, and a start date.

Or call (937) 980-9035

05 · How We Price

Fixed fee, quoted up front

Every engagement above is quoted against a written scope before it starts. If the work genuinely grows, we agree the change first — you never open an invoice you didn't expect.

Call (937) 980-9035
A printed security findings report on a dark desk, lit by a single warm lamp
Call Request a scope