Giacomo Balli profile picture
Giacomo Balli
The Mobile Guy

For founders and teams whose growth depends on mobile.
Clear judgment when AI, vendors, and product choices muddy the roadmap.

Find the Right Move LinkedIn

Production Security Assessment

Independent security assessment of one production application and the systems behind it. $16,000 fixed, 2 to 3 weeks to initial findings, one remediation retest included.

Your developers built it. Your team maintains it. Your customers trust it with their data. But when was the last time someone independent tried to break it?

I review your production application the way an attacker would, across the app, APIs, authentication, permissions, data access, storage and connected services, and tell you what I find.

  • $16,000 fixed
  • 2 to 3 weeks to findings
  • Retest included
  • No hourly billing

Tell me what your company builds, what data it handles, and why security matters now. I will tell you whether this assessment is the right next step.

Schedule a call

If you think an attack is happening right now, this is the wrong call. Get incident response first.

The problem

Security problems rarely announce themselves

Most serious application vulnerabilities are not obvious from reading the code or running a scanner. They live in the gaps between systems.

An API trusts something it should not. A user can access another user's data. An old endpoint bypasses newer protections. A mobile app exposes credentials or internal architecture. A storage bucket has broader permissions than anyone realized. A legacy feature still works in ways the current team does not know about.

Your developers can be good at their jobs and these problems can still exist.

One missing permission check is the difference between one customer's records and every customer's records. That shows up as copied data, a stalled enterprise deal, or a disclosure to every customer at once.

As CEO you do not need to become a security expert. You need an independent answer to a simpler question: what could someone actually do to us?

The work

I test it the way an attacker would

I independently assess one of your production applications and the systems directly behind it, from the outside in: how it communicates, what it exposes, where it places trust, how users and permissions are separated, and what happens when those assumptions are deliberately violated.

Depending on the application, that typically includes:

  • Web or mobile application
  • APIs and backend services
  • Authentication and account access
  • Authorization and user permissions
  • Sensitive data exposure
  • Cloud storage exposed through the application
  • Secrets and credentials
  • Business-logic vulnerabilities
  • Third-party integrations
  • Push notifications, email and SMS
  • Common vulnerabilities and injection attacks
  • Architectural weaknesses that create larger attack paths

This is hands-on investigation, not a scanner report. Automated tools are useful and I use them too. The value is figuring out what the results actually mean, following one weakness into another, understanding how the application works as a system, and determining what an attacker could accomplish.

Deliverables

What you get

The CEO memo

A short, plain-English assessment of what I found. You will know:

  • What is exposed
  • How serious it is
  • What could realistically happen
  • What to fix first, and what can wait
  • Whether anything requires action today

The technical findings

Your developers receive the detail they need to fix the problems. Each significant finding includes the issue, severity, evidence, reproduction details, impact and recommended remediation.

I walk the team through the findings directly so they can ask questions and start fixing them.

Verification

Fixing something is not the same as knowing it is fixed.

One retest within 60 days is included. I verify the remediation and document which findings are closed and which remain open.

A defined end

There is a beginning and an end. I assess the system, document what matters, explain it to you and your team, and verify the fixes.

If you need help beyond that, we can decide afterward.

Boundaries

What this is not

It is not a compliance checkbox

Passing an audit and being hard to compromise are different achievements. This work aims at the second and can support the first.

It is not an automated vulnerability scan

You can buy scanners for a fraction of the price. They are good at finding known patterns. They are much less useful at asking:

Why does this anonymous user have a token?

What else can I do with it?

Can this API access another customer's records?

Does this old endpoint bypass the permissions implemented everywhere else?

What happens if I combine these two seemingly minor weaknesses?

Those are the questions I care about.

Fit

Who this is for

This works best for a founder or CEO who has a real software product in production and wants an independent answer about its security. It is particularly useful when:

  • your application has been running for years and accumulated legacy code;
  • you handle meaningful customer or business data;
  • you have never had an independent application security review;
  • someone recently reported a vulnerability;
  • you are preparing for SOC 2 or an enterprise security review;
  • development has accelerated, including through AI coding tools;
  • you inherited an application and are not certain what is inside it;
  • customers increasingly depend on your product.

You do not need an internal security team. You do need developers who can answer questions about the system and implement fixes.

This is not for you if the application holds no sensitive data, if you only need an audit badge, or if you cannot free up developers to fix what I find.

Why me

A builder and an adversary

I have been building software and mobile applications since 2010.

That matters because application security is not just about knowing a catalog of vulnerabilities. It requires understanding how real products are built: old code beside new code, APIs accumulated over years, mobile clients that reveal more than expected, third-party services, shortcuts that became permanent, and assumptions nobody remembers making.

The goal is not to produce the longest possible list of findings. It is to find the things that actually matter.

The engagement

What it costs and what it covers

$16,000 fixed

2 to 3 weeks from kickoff to initial findings. One remediation retest within 60 days.

  • Production application security assessment
  • Application and exposed backend or API review
  • Authentication and authorization testing
  • Relevant data and integration exposure
  • Severity-ranked technical findings
  • CEO security memo
  • Developer remediation walkthrough
  • One remediation retest
  • Written closure status

The fixed price covers one production product and the systems directly supporting it. We confirm the boundaries together before starting.

  • No hourly billing
  • No meter running while I investigate
  • No incentive to make the project take longer
Next step

Start with one question

You do not need to know which security test to buy. You do not need to prepare a technical scope.

If a customer, an auditor or a board is already asking, what is the wait costing you?

Tell me what your company builds, what data it handles, and why you are thinking about security now. I will tell you whether this assessment is the right next step.

Talk to Giacomo