Web Application Security Review

AI can significantly speed up application development. It does not verify whether new features protect accounts, permissions and data correctly.

The Website Security Review is a practical assessment of a smaller web application with a clearly limited scope. I focus on issues that may allow someone to take over an account, bypass a user role, access another user’s data, abuse an API or unintentionally expose files and other information.

The review is suitable for applications built with AI, no-code or low-code tools as well as conventionally developed software. I carry out the review personally and do not rely solely on automated scanner output. I also assess how authentication, roles, application workflows, APIs and data work together.

Who the service is for

  • a startup or smaller team preparing to launch a web application;
  • an AI-assisted or vibe-coded MVP that already handles real users or data;
  • a smaller SaaS product, internal tool, client portal or administrative interface;
  • an application that was developed quickly and has not yet received an independent security review;
  • a project with user accounts, roles, non-public data, file uploads or APIs.

What I review

  • login, registration, password recovery and session management;
  • authorisation, user roles, permissions and separation of data;
  • forms, inputs, parameters, file uploads and file handling;
  • API endpoints used by the application;
  • common web application risks, including areas covered by the OWASP Top 10;
  • basic cookie, security header, CORS and TLS configuration;
  • publicly accessible application areas and unintentionally exposed information;
  • common issues in applications developed quickly or with the assistance of AI.

Fixed service scope

  • one smaller web application;
  • one domain or one testing or production environment;
  • up to 3 user roles;
  • up to 5 main application workflows;
  • a basic review of the API used by the application.

We confirm the scope before the review begins. If the application does not fit within these boundaries, a Custom Penetration Test will be more appropriate.

What you receive

  • a concise summary of the main risks and their practical impact;
  • a prioritised list of findings;
  • the technical detail needed to understand and remediate each issue;
  • clear remediation recommendations;
  • a distinction between important issues and lower-priority improvements;
  • a final consultation to discuss the results.

The goal is not to deliver a long automated output. The report should make it clear what matters and what your developer or administrator should address first.

What is not included

  • an open-ended penetration test of the entire application;
  • a line-by-line source code review;
  • a separate audit of the complete infrastructure or server;
  • a compliance or certification audit;
  • remediation of the identified issues;
  • a retest after remediation;
  • a guarantee that the application contains no other vulnerabilities.

Remediation, hardening or a retest can be agreed as separate follow-up work.

How the review works

  1. Send a brief description of the application. Include what it does, its user roles and the areas you need to verify.
  2. We confirm the scope. We clarify the tested environment, accounts, workflows and required access.
  3. The review takes place. Testing remains within the confirmed boundaries.
  4. You receive the report and consultation. Findings are prioritised by their impact and remediation priority.

Price and delivery

The Website Security Review costs CZK 35,000 for the predefined scope.

Typical delivery is within 7 business days after the scope and required access have been confirmed.

This is not a “penetration test starting at CZK 35,000”. It is a fixed-scope review of a smaller application. For a larger, more complex or more sensitive system, the scope and price are defined individually as part of a Custom Penetration Test.

Request a security review

Vyplňte, pokud je aplikace dostupná online. Neposílejte přístupové údaje. / Fill this in if the application is available online. Do not send any login credentials.
Stručně popište účel aplikace a její typické uživatele. Neposílejte technickou dokumentaci. / Briefly describe the purpose of the application and its typical users. Do not send technical documentation.
Uživatelská část a administrace mohou být součástí jedné aplikace. „Více aplikací nebo systémů“ zvolte například tehdy, pokud chcete zahrnout několik samostatných webů nebo oddělených systémů. / A user-facing area and administration can be part of one application. Select “multiple applications or systems” if the review should include several separate websites or systems.
Například běžný uživatel, firemní správce a administrátor jsou tři různé typy účtů. / For example, a regular user, an organisation manager, and an administrator are three different account types.
Můžete doplnit konkrétní obavu, důležitou okolnost nebo informaci, kterou bych měl před posouzením poptávky znát. / You may add a specific concern, important circumstance, or anything I should know before reviewing the request.