Application security · WAF tuning · Audit-ready evidence

Security work that ends with a letter your auditor, insurer or customer can rely on.

We find the weaknesses in your web applications, fix them with your team, and prove it — in one engagement, from a named practitioner, with our own AI cyber security agents doing the heavy lifting under human sign-off.

Find. Fix. Prove. — the whole loop, not just a report.
1

Find

A manual, authenticated review of your application or API against OWASP WSTG and ASVS. Our Triage agent clusters and de-duplicates scanner noise so the practitioner spends the hours on what matters.

2

Fix

A remediation sprint with your developers: WAF rules, configuration, code guidance. Warden drafts every WAF exception with scope, expiry and rollback. You keep ownership of production changes.

3

Prove

A retest and an attestation letter formatted for SOC 2 auditors, insurers and customer questionnaires, with evidence delivered into your Vanta or Drata workspace. Scribe drafts; the practitioner signs.

The service ladder

Start free. Climb only as far as your deadline needs.

Fixed scopes and published starting prices in CAD. Every paid step includes the fix work and the proof, not just the findings.

FREE

External Exposure Snapshot

What an attacker sees from outside, in plain language.

Free Details
ONE TIME

Web Application Security Review + Fix Sprint

Find the weaknesses, fix them with you, prove it to your auditor.

from $4,900 Details
ONE TIME

Vulnerability Baseline + Insurance-Readiness Evidence Pack

Pass your renewal without surprises.

from $2,400 Details
ONE TIME

WAF Tuning Sprint

Fewer false positives, cleaner rules, a decision record for every exception.

from $3,500 Details
ONE TIME

Compliance Readiness Pack

Audit-ready evidence for one framework and one business boundary.

from $4,500 Details
ONE TIME

Municipal + Public-Sector Web Security Review

Citizen-facing services reviewed, fixed and documented for council.

from $6,500 Details
MONTHLY

WAF + Vulnerability Retainer

Someone owns your edge and your exposure every month.

$1,500 - $3,500 per month Details
CREDITS

Security Sprint Credits

Capacity on call, without a retainer.

10 credits from $5,500 Details
PARTNER

Partner Price List (MSPs and development agencies)

Keep your client. Add our depth under your brand.

15-20% off list Details
Who we serve

Four kinds of deadline. One way of working.

Named practitioner, capped load

No more than 4 concurrent engagements across the team, so the five-day start promise holds. You meet the person who signs your letter.

Evidence your auditor accepts

Findings with reproduction steps and CVSS, a retest record, an attestation letter with framework references, and evidence hashes. Exported to Jira, Vanta or Drata.

Clear boundaries

Written authorization before any test. No work during an active incident. Round-the-clock response comes from a disclosed partner SOC, never an implied promise. Statement of practice

Not sure where to start? Start with what an attacker sees.

Scout runs a bounded, read-only External Exposure Snapshot of one domain — free, reviewed by a practitioner before it reaches you.

Request the free snapshot