AI can significantly speed up application development. It does not verify whether new features protect accounts, permissions and data correctly.
The Website Security Review is a practical assessment of a smaller web application with a clearly limited scope. I focus on issues that may allow someone to take over an account, bypass a user role, access another user’s data, abuse an API or unintentionally expose files and other information.
The review is suitable for applications built with AI, no-code or low-code tools as well as conventionally developed software. I carry out the review personally and do not rely solely on automated scanner output. I also assess how authenticationIdentity verification. A service checks whether you really are who you claim to be. More, roles, application workflows, APIs and data work together.
Who the service is for
- a startup or smaller team preparing to launch a web application;
- an AI-assisted or vibe-coded MVP that already handles real users or data;
- a smaller SaaS product, internal tool, client portal or administrative interface;
- an application that was developed quickly and has not yet received an independent security review;
- a project with user accounts, roles, non-public data, file uploads or APIs.
What I review
- loginThe information used to log in to a service, usually username, email, password, code, or security ke... More, registration, passwordIn general, a password is an arbitrary string of characters including letters, digits, or other symb... More recovery and sessionThe period after login when a service remembers you as a logged-in user. More management;
- authorisation, user roles, permissions and separation of data;
- forms, inputs, parameters, file uploads and file handling;
- API endpoints used by the application;
- common web application risks, including areas covered by the OWASP Top 10A list of common and important web application risks, used as a map for security reviews. More;
- basic cookieA small piece of data stored in the browser. A site can use it to remember login, settings, or a tra... More, security header, CORS and TLS configuration;
- publicly accessible application areas and unintentionally exposed information;
- common issues in applications developed quickly or with the assistance of AI.
Fixed service scope
- one smaller web application;
- one domainA human-readable name for an internet service, such as a website address. More or one testing or production environment;
- up to 3 user roles;
- up to 5 main application workflows;
- a basic review of the API used by the application.
We confirm the scope before the review begins. If the application does not fit within these boundaries, a Custom Penetration Test will be more appropriate.
What you receive
- a concise summary of the main risks and their practical impact;
- a prioritised list of findings;
- the technical detail needed to understand and remediate each issue;
- clear remediation recommendations;
- a distinction between important issues and lower-priority improvements;
- a final consultation to discuss the results.
The goal is not to deliver a long automated output. The report should make it clear what matters and what your developer or administrator should address first.
What is not included
- an open-ended penetration test of the entire application;
- a line-by-line source code review;
- a separate audit of the complete infrastructure or server;
- a compliance or certification audit;
- remediation of the identified issues;
- a retest after remediation;
- a guarantee that the application contains no other vulnerabilities.
Remediation, hardening or a retest can be agreed as separate follow-up work.
How the review works
- Send a brief description of the application. Include what it does, its user roles and the areas you need to verify.
- We confirm the scope. We clarify the tested environment, accounts, workflows and required access.
- The review takes place. Testing remains within the confirmed boundaries.
- You receive the report and consultation. Findings are prioritised by their impact and remediation priority.
Price and delivery
The Website Security Review costs CZK 35,000 for the predefined scope.
Typical delivery is within 7 business days after the scope and required access have been confirmed.
This is not a “penetration test starting at CZK 35,000”. It is a fixed-scope review of a smaller application. For a larger, more complex or more sensitive system, the scope and price are defined individually as part of a Custom Penetration Test.
