Agree the boundaries
Both parties sign the named systems, rules of engagement, and maximum invoice.
Independent security assessments
Authorised assessments of your websites, applications and APIs. Human-verified findings. Clear fees. A scope you control.
Written authorisation first. Always.
A defined boundary.
A focused engagement
A focused assessment of the systems your business puts online, with boundaries agreed before work begins.
Redifact assesses named public-facing websites, applications, APIs, and internet-facing infrastructure. Every engagement is remote and non-destructive.
Explore the scopeThe deliverable
Understand the risk. Decide what comes next.
Your written report brings together verified findings, their severity, and recommended next steps. The agreed retest follows remediation.
See the engagement processFictional example · Example Company customer portal
A concise overview of the agreed scope, confirmed risks, and decisions needed by the business.
Verified findings organised by severity, with evidence and business impact to support prioritisation.
Recommended next steps and the outcome of the agreed retest after changes are made.
Structure only. No assessment has been performed and no client results are shown.
Transparent by design
Only verified, in-scope findings qualify. Each bills at its severity band, up to your signed assessment cap.
| Severity | Fee |
|---|---|
| Info | $0 |
| Low | $500 |
| Medium | $1,500 |
| High | $4,000 |
| Critical | $10,000 |
| Assessment cap | $15,000 |
Standard defaults in USD. Binding only when signed.
No qualifying finding means no fee.
From scope to clarity
Both parties sign the named systems, rules of engagement, and maximum invoice.
Work stays within the signed scope. A human verifies each finding before it can be billed.
Receive the evidence, severity, and recommended next steps. Complete the agreed retest.
Start with a conversation
An enquiry starts a conversation. It does not start a test.