Skip to content
Free · 30 minutes · Done by a human

A real engineer looks at your systems before you spend anything

A practitioner reviews your systems by hand, without relying on an automated scanner or a templated report, then spends 30minutes walking you through what they found. Start with a security review of what you have exposed, or, if you're building, a review of your AI and software. Either way you get a clear answer and written findings, whether or not you ever work with us.

  • Free, with nothing to sign

    There is no card to enter and no contract. If we're not the right fit we'll tell you where to look instead.

  • Reviewed by hand

    A practitioner goes through your systems personally, and the person on the call is the person who did the review rather than an account manager relaying notes.

  • You keep the findings

    The written summary is yours to act on or take elsewhere, whether or not you work with us.

Book your manual assessment

Pick a track and a time that suits you. Times are shown in your own timezone.

Two tracks

Pick the review that matches your problem

The same 30 minutes, pointed at whichever half of your stack concerns you most. Both are run by the practitioner who'd do the paid work.

Cybersecurity

Security review

Where your systems are exposed today

What we look at

  • Your externally reachable surface: domains, subdomains, and services that answer from the public internet
  • Transport and email security posture: TLS configuration, HSTS, SPF, DKIM, and DMARC
  • The security headers and cookie flags your application returns today
  • Which of the OWASP Top 10 categories your stack is structurally most exposed to
  • Whether a full VAPT, a targeted test, or compliance work is the right next spend

What you get

  • A written summary of what we found, ranked by real-world risk rather than scanner severity
  • The specific issues worth fixing first, with the reasoning behind the order
  • A straight answer on whether you need a paid engagement at all, and what it would cover if you do
AI & Software

AI & software review

Whether what you're building will hold up

What we look at

  • The architecture you have or are planning, and where it will strain as usage grows
  • For AI work: whether RAG, fine-tuning, an agent, or plain automation fits the problem
  • Retrieval and evaluation quality, the usual reason an AI feature is confidently wrong
  • Where cloud and delivery cost is accumulating without buying you reliability
  • What is worth automating and what is cheaper to leave alone

What you get

  • A clear recommendation on the approach, including where your current plan would cost you later
  • The specific technical risks in what you're building, and what each one would take to address
  • A realistic view of scope and sequencing: what to build first and what can wait
How it works

Four steps from booking to written findings

A practitioner reviews what you send before the call, so the 30 minutes goes on findings rather than on getting up to speed.

  1. 1

    Pick a track and a time

    Choose the security or the AI and software track, tell us what to look at, and pick a slot that works in your own timezone.

  2. 2

    A practitioner reviews it by hand

    An engineer goes through what you've shared by hand before the call, without an automated scan or a generated report, so the 30 minutes goes on findings and decisions rather than background.

  3. 3

    A 30-minute working call

    We walk you through what we found and what it means. It is a working session, so bring your questions.

  4. 4

    Written findings afterwards

    You get a short written summary you can forward internally, whether or not you go on to work with us.

Questions

The things people ask before booking

Including the question of what the catch is.

Why is this free? What's the catch?

There's no catch and no obligation. Most people who need security or engineering help can't tell from the outside whether they need a full engagement, a small piece of work, or nothing at all, so they put off deciding. Thirty minutes of a practitioner's time answers that, and it costs us far less than writing proposals for work that was never the right fit. If you don't need us, we'll tell you so.

Is this a sales call?

No. It's a technical conversation with someone who does the work. We'll tell you what we found and what we'd do about it. If a paid engagement is the right next step we'll say so and explain what it would involve, but nobody is going to push you toward one on the call.

What do you need from me beforehand?

For a security review, the domain or application you want us to look at, and confirmation that you own it or are authorised to have it assessed. For an AI or software review, a short description of what you're building or running; a repo or architecture doc helps but isn't required.

Do you scan my systems automatically when I submit the form?

No. Submitting the form books a slot and tells us what you'd like reviewed. Nothing is scanned at that moment. The assessment is run by a person, only against systems you've told us you're authorised to have assessed, and only after you've booked.

Is this a free VAPT scan or free penetration testing?

It is a free manual review. It is not a full VAPT or penetration test, and the difference matters. A VAPT engagement is days of scoped, authorised testing against your systems, and it is paid work. This assessment is thirty minutes in which a practitioner examines what is reachable from the outside, tells you which of the OWASP Top 10 categories your stack is structurally most exposed to, and gives you a clear view of whether a full VAPT, a targeted test, or nothing at all is the right next step. If someone offers you a free penetration test, ask what they are running. It is almost always an automated scan with the output retyped.

Can you do a free ISO 27001 or compliance gap check?

The security track covers this. In thirty minutes we can tell you roughly where you sit against ISO 27001, what a customer security questionnaire is likely to catch you on, and which gaps are cheap to close versus which need real project work. It is not a certification audit or a formal gap assessment; those are paid engagements with evidence collection and documentation. It is enough to show you what you are walking into before you commit budget.

Do you offer a free AI audit or architecture review?

Yes, that is the AI and software track. A practitioner looks at the architecture you have or are planning and tells you where it will strain, whether RAG, fine-tuning, an agent, or plain automation fits your problem, and where retrieval or evaluation quality is likely to make an AI feature confidently wrong. A repo or architecture document helps but is not required; a couple of paragraphs describing the system is enough to make the call useful.

Is what I share kept confidential?

Yes. What you share is used to prepare for your assessment and nothing else. We're happy to sign an NDA before you send anything sensitive. Ask on the booking form and we'll arrange it before the call.

What happens if I want to go further afterwards?

We'll scope the engagement properly and quote it before any work starts. The assessment carries no commitment either way, and the written summary is yours regardless of what you decide.

Find out where you stand in thirty minutes

The assessment is free and you are under no obligation afterwards. If you turn out to be in better shape than you thought, you will know that for certain.

Book my free assessment