Skip to content
Free · 30 minutes · Done by a human

A real engineer looks at your systems before you spend anything

Not an automated scan and not a templated PDF. A practitioner reviews your systems by hand, then spends 30 minutes walking you through what they found. Choose a security review of what you have exposed, or a review of the AI and software you're building — either way you get a straight answer and written findings, whether or not you ever work with us.

  • No obligation, no card, no contract

    Nothing to pay and nothing to sign. If we're not the right fit we'll tell you where to look instead.

  • Reviewed by hand, not by a scanner

    A practitioner goes through your systems themselves — and the person on the call is the person who did it, not an account manager relaying notes.

  • You keep the findings

    The written summary is yours to act on or take elsewhere, whether or not you work with us.

Book your manual assessment

Pick a track and a time that suits you. Times are shown in your own timezone.

Two tracks

Pick the review that matches your problem

The same 30 minutes, pointed at whichever half of your stack is keeping you up at night. Both are run by the practitioner who'd do the paid work.

Cybersecurity

Security review

Where your systems are actually exposed

What we look at

  • Your externally reachable surface — domains, subdomains, and services that answer from the public internet
  • Transport and email security posture: TLS configuration, HSTS, SPF, DKIM, and DMARC
  • The security headers and cookie flags your application returns today
  • Which of the OWASP Top 10 categories your stack is structurally most exposed to
  • Whether a full VAPT, a targeted test, or compliance work is the right next spend

What you get

  • A written summary of what we found, ranked by real-world risk rather than scanner severity
  • The specific issues worth fixing first, with the reasoning behind the order
  • An honest read on whether you need a paid engagement at all — and what it would cover if you do
AI & Software

AI & software review

Whether what you're building will hold up

What we look at

  • The architecture you have or are planning, and where it will strain as usage grows
  • For AI work: whether RAG, fine-tuning, an agent, or plain automation actually fits the problem
  • Retrieval and evaluation quality — the usual reason an AI feature is confidently wrong
  • Where cloud and delivery cost is accumulating without buying you reliability
  • What is genuinely worth automating versus what is cheaper to leave alone

What you get

  • A clear recommendation on the approach, including where your current plan would cost you later
  • The specific technical risks in what you're building, and what each one would take to address
  • A realistic view of scope and sequencing — what to build first and what can wait
How it works

Four steps, no runaround

A human reviews what you send before the call — so the 30 minutes is spent on findings, not on getting up to speed.

  1. 1

    Pick a track and a time

    Choose the security or the AI and software track, tell us what to look at, and pick a slot that works in your own timezone.

  2. 2

    A practitioner reviews it by hand

    A real engineer goes through what you've shared before the call — no automated scan, no generated report — so the 30 minutes is spent on findings and decisions rather than on background.

  3. 3

    A 30-minute working call

    We walk you through what we found and what it means. Questions welcome — this is a working session, not a presentation.

  4. 4

    Written findings afterwards

    You get a short written summary you can forward internally, whether or not you go on to work with us.

Questions

The things people ask before booking

Including the one everybody thinks and nobody says out loud.

Why is this free? What's the catch?

There's no catch, and there's no obligation. Most people who need security or engineering help can't tell from the outside whether they need a full engagement, a small piece of work, or nothing at all — so they delay deciding. Thirty minutes of a practitioner's time answers that, and it costs us far less than the alternative of writing proposals for work that was never the right fit. If the honest answer is that you don't need us, we'll tell you that.

Is this a sales call?

No. It's a technical conversation with someone who does the work. We'll tell you what we found and what we'd do about it. If a paid engagement is the right next step we'll say so and explain what it would involve, but nobody is going to push you toward one on the call.

What do you need from me beforehand?

For a security review, the domain or application you want us to look at — and confirmation that you own it or are authorised to have it assessed. For an AI or software review, a short description of what you're building or running; a repo or architecture doc helps but isn't required.

Do you scan my systems automatically when I submit the form?

No. Submitting the form books a slot and tells us what you'd like reviewed — nothing is scanned at that moment. The assessment is run by a person, only against systems you've told us you're authorised to have assessed, and only after you've booked.

Is what I share kept confidential?

Yes. What you share is used to prepare for your assessment and nothing else. We're happy to sign an NDA before you send anything sensitive — just ask on the booking form and we'll sort it out before the call.

What happens if I want to go further afterwards?

We'll scope the engagement properly and quote it before any work starts. The assessment carries no commitment either way, and the written summary is yours regardless of what you decide.

Thirty minutes now, or a much worse conversation later

There's no cost and no obligation. Worst case, you find out you're in better shape than you thought.

Book my free assessment