Secures AppsTake the free assessment
Now booking Q3 engagements

An AppSec expert, securing your apps for a fraction of the cost

Free AI-assisted assessment, then 30 minutes with a real AppSec engineer — 10+ years implementing these controls in production, not just writing about them. AI speeds up the busywork; the recommendations are mine.

50 questions · 8 minutes · no credit card · get your roadmap immediately

[ 01 ]

AI-assisted assessment

Answer 50 questions across 10 AppSec domains. Get an instant maturity score, prioritized gaps, and a roadmap.

[ 02 ]

30-minute expert review

Sit down with an engineer with 10+ years in AppSec. I'll tell you what actually matters for a company your size.

[ 03 ]

Fix it, or have me fix it

Take the roadmap and run with it yourself, or bring me in — from a single review to ongoing fractional coverage.

More than a checklist

50 questions across the 10 domains that actually determine whether a startup gets breached. You get a maturity score per domain, not just one number.

SDLC
CI/CD
Cloud
IAM
Secrets
Threat Modeling
AppSec Testing
Dependencies
Incident Response
Dev Training
Overall maturity, 1–5
Plus a breakdown for every domain so you know exactly where you stand.
Top 5 priorities
Ranked by real-world risk, not alphabetically or by how many questions were asked.
Quick wins under 30 days
Specific, no-budget actions you can start this week — plus the longer-term roadmap.
[ Included free ]

A vulnerability disclosure program, set up for you

Most startups have no legitimate way for a security researcher to report a bug. I'll help you publish a security.txt file and a lightweight VDP policy, and triage your first 25 incoming reports at no cost — so you get real testing coverage from day one, without the overhead of running a bug bounty program yourself.

  • Published security.txt + disclosure policy
  • A safe-harbor reporting process researchers trust
  • Triage of your first 25 reports included, free
  • Clear escalation path for anything critical
# /.well-known/security.txt
Contact: mailto:security@secures.app
Expires: 2027-01-01T00:00:00.000Z
Preferred-Languages: en
Canonical: https://yourcompany.com/.well-known/security.txt
Policy: https://yourcompany.com/security-policy

Services

Scoped engagements or ongoing coverage — brought in where you actually need application security expertise.

Secure code reviews
Manual review of your highest-risk code paths — the flaws automated scanners miss.
Threat modeling
Structured sessions on new features and systems before architecture decisions are locked in.
Secure SDLC design
Practical policies and gates that fit how your team actually ships, not a compliance binder.
DevSecOps & CI/CD
Scanning, branch protection, and pipeline hardening that developers don't fight against.
Security architecture review
Independent review of new systems and major changes before they go to production.
Cloud security review
AWS / Azure / GCP configuration review against real-world attack paths, not just checklists.
AI application security
Assessments for products built on LLMs — prompt injection, data exposure, agentic tool risk.
vCISO (AppSec focus)
Fractional security leadership for startups that need the function before they need the headcount.
[ Flagship offering ]

AppSec Partner

Ongoing, fractional AppSec coverage — the closest thing to an in-house AppSec hire, without the in-house hire.

Talk about a partnership
  • Monthly threat modeling
  • Architecture reviews
  • Pull request / code review support
  • Security champions program
  • CI/CD security guidance
  • Vulnerability triage
  • Quarterly security roadmap
  • On-demand expert access
  • Bug bounty program management

Pricing

Start free. Upgrade when you need more than a roadmap — the consulting becomes a premium feature, not the entire product.

Free

€0

Understand where you stand and get a real, actionable roadmap.

  • Security maturity assessment
  • VDP + security.txt setup
  • Personalized roadmap
  • Free 30-min expert review
Start the assessment

Starter

€49–99/month

For teams that want to track progress, not just get a one-time score.

  • Progress dashboard
  • Recurring reassessments
  • Basic integrations
  • Up to 25 vulnerability reports
Get started
Most popular

Growth

€299–999/month

Continuous coverage with a human in the loop, integrated into how you ship.

  • GitHub / Jira / cloud integrations
  • AI-assisted recommendations
  • Monthly advisory sessions
  • Architecture reviews
Talk to us

Enterprise

Custom

Fractional AppSec leadership for companies that need the function, not a tool.

  • Fractional AppSec leadership
  • Custom implementation
  • Executive reporting
  • Team workshops
Contact us

Why founders bring me in

10+ years in application security, spent implementing — not just recommending — the controls in this assessment: secure SDLC rollouts, threat modeling programs, CI/CD hardening, and incident response, inside real engineering organizations. I use AI to move faster on assessments and research — the recommendations are still a human call, made by someone who's actually done this before. Most AppSec vendors sell you a scanner or a report. I tell you what actually reduces risk for a company at your stage, and help you build it.

Find out where you actually stand

8 minutes now saves months of guessing what to prioritize.