Vulnerability remediation
Got a security report? We’ll fix what it found
A pentest report, scanner results, a warning from your host or an email from a researcher: a list of problems is only useful once someone fixes them. We’re developers, so fixing is the part we do best.
What’s included
Done properly, start to finish
Triage first
We confirm which findings are real, which are false positives, and what to fix first. You get that in writing before any work.
Fixed at the cause
Patched or replaced plugins, corrected code, safer configuration. Not a firewall rule hiding the problem.
Nothing breaks on the way
A backup before every change, a staging copy where possible, and a check of every page and form afterwards.
Re-tested and documented
Each finding re-tested, with what changed and how to verify it, so your auditor or client can sign off.
Works with your team
If you have developers, we can work alongside them or hand over fixes ready to review.
A fixed price
Once we’ve triaged the report, you get a fixed price for the fixes. No hourly meter.
What we work from
Any report, from anyone
If it lists security problems with your website, app or server, we can work through it.
The steps
From first message to closed
- 01
Send the report
Email it, or share it from your own secure storage.
- 02
Triage
Real or not, how serious, what order.
- 03
Fix
At the cause, with backups and staging.
- 04
Re-test
Each finding checked again.
- 05
Sign-off
A summary your auditor or client can accept.
Start here
Request a security assessment
Tell us what you run and what worries you. We’ll reply with a scope, dates and a fixed price in writing, and you decide from there.
- A reply from the people who’ll do the work
- Scope, dates and a fixed price before anything starts
- An NDA before we start, if you want one
- Nothing is tested without written authorization
Urgent? Message us on WhatsApp ↗
Does the original tester need to be involved?
No. We work from the report. If the tester can re-test afterwards, great; if not, we re-test ourselves and document it.
Can you fix findings in a custom app?
Usually, yes: PHP and JavaScript apps, including Next.js, and the servers they run on. If a fix needs your core developers, we write it up so they can apply it quickly.
What if most of the report is false positives?
Then we’ll tell you, with the reasoning for each, so you can close them with your auditor. Scanners flag plenty that doesn’t apply.
How do I send the report safely?
Email us first and we’ll agree a secure way to share it. Please don’t paste findings, passwords or keys into the form.
More security services
The rest of the loop
Manual testing of your website, web app or API, following the OWASP testing guide, with every finding re-tested after it’s fixed.
Read more → WordPress securityAudits, hardening and fixes for WordPress: plugins, users, logins, configuration and the server underneath.
Read more → Hack recoveryMalware removed, the entry point found and closed, passwords rotated and search warnings cleared.
Read more → Security operationsMonthly patching, access reviews, log checks and incident response, run by the people who know your site.
Read more →