AI can significantly speed up application development. It does not verify whether new features protect accounts, permissions and data correctly.
The Website Security Review is a practical assessment of a smaller web application with a clearly limited scope. I focus on issues that may allow someone to take over an account, bypass a user role, access another user’s data, abuse an API or unintentionally expose files and other information.
The review is suitable for applications built with AI, no-code or low-code tools as well as conventionally developed software. I carry out the review personally and do not rely solely on automated scanner output. I also assess how authenticationIdentity verification. A service checks whether you really are who you claim to be. More, roles, application workflows, APIs and data work together.
Who the service is for
- a startup or smaller team preparing to launch a web application;
- an AI-assisted or vibe-coded MVP that already handles real users or data;
- a smaller SaaS product, internal tool, client portal or administrative interface;
- an application that was developed quickly and has not yet received an independent security review;
- a project with user accounts, roles, non-public data, file uploads or APIs.
What I review
- loginThe information used to log in to a service, usually username, email, password, code, or security ke... More, registration, passwordIn general, a password is an arbitrary string of characters including letters, digits, or other symb... More recovery and sessionThe period after login when a service remembers you as a logged-in user. More management;
- authorisation, user roles, permissions and separation of data;
- forms, inputs, parameters, file uploads and file handling;
- API endpoints used by the application;
- common web application risks, including areas covered by the OWASP Top 10A list of common and important web application risks, used as a map for security reviews. More;
- basic cookieA small piece of data stored in the browser. A site can use it to remember login, settings, or a tra... More, security header, CORS and TLS configuration;
- publicly accessible application areas and unintentionally exposed information;
- common issues in applications developed quickly or with the assistance of AI.
Fixed service scope
- one smaller web application;
- one domainA human-readable name for an internet service, such as a website address. More or one testing or production environment;
- up to 3 user roles;
- up to 5 main application workflows;
- a basic review of the API used by the application.
We confirm the scope before the review begins. If the application does not fit within these boundaries, a Custom Penetration Test will be more appropriate.
What you receive
- a concise summary of the main risks and their practical impact;
- a prioritised list of findings;
- the technical detail needed to understand and remediate each issue;
- clear remediation recommendations;
- a distinction between important issues and lower-priority improvements;
- a final consultation to discuss the results.
The goal is not to deliver a long automated output. The report should make it clear what matters and what your developer or administrator should address first.
What is not included
- an open-ended penetration test of the entire application;
- a line-by-line source code review;
- a separate audit of the complete infrastructure or server;
- a compliance or certification audit;
- remediation of the identified issues;
- a retest after remediation;
- a guarantee that the application contains no other vulnerabilities.
Remediation, hardening or a retest can be agreed as separate follow-up work.
How the review works
- Send a brief description of the application. Include what it does, its user roles and the areas you need to verify.
- We confirm the scope. We clarify the tested environment, accounts, workflows and required access.
- The review takes place. Testing remains within the confirmed boundaries.
- You receive the report and consultation. Findings are prioritised by their impact and remediation priority.
What does the output look like?
I’ve published a complete sample report — exactly as clients receive it. Download the sample report (PDF)
Price and delivery
The Website Security Review costs CZK 35,000 for the predefined scope.
Typical delivery is within 7 business days after the scope and required access have been confirmed.
This is not a “penetration test starting at CZK 35,000”. It is a fixed-scope review of a smaller application. For a larger, more complex or more sensitive system, the scope and price are defined individually as part of a Custom Penetration Test.
