// SECURITY ASSESSMENT
Start with your current security posture.
Tell us what you run. We will confirm scope, agree the authorization in writing, and return a prioritized assessment of what is actually exposed across your code, APIs, and external surface.
Request a security assessment
Every field helps us scope accurately. If something is not settled yet, say so in the notes — an approximate answer is more useful than a blank.
// DELIVERABLES
What you receive.
Two reports, written for two different audiences, because the person who approves the budget and the person who writes the fix need different things.
EXECUTIVE SECURITY REPORT
For founders, CEOs, CTOs, and boards.
- Overall security posture and score
- Critical risks in business language
- Potential business impact of each
- Asset coverage — what was and was not assessed
- Remediation priorities and effort estimates
- Risk trend once monitoring is running
TECHNICAL SECURITY REPORT
For engineers and engineering leadership.
- Every finding with severity and confidence
- Affected repository, file, and route
- Evidence sufficient to reproduce safely
- Correlated attack paths
- Specific remediation guidance per finding
- Verification status and references
Assessment packages.
Every package is credited in full toward your first three months if you subscribe within 30 days.
| Package | Price | Scope | Turnaround |
|---|---|---|---|
| Focused | $750 | 1 application, 1 repository. Code, dependencies, secrets, API inventory. | ≈5 business days |
| Standard | $1,500 | Up to 3 applications, 5 repositories, plus external surface and correlated attack paths. | ≈7 business days |
| Comprehensive | $2,500 | Up to 10 applications, human verification of critical findings, remediation session, re-test. | ≈10 business days |
Common questions
Do we have to subscribe afterwards?
No. The assessment is a standalone engagement and the report is yours regardless. If you do subscribe within 30 days, the entire fee is credited toward your first three months.
What access do you actually need?
A read-only GitHub App installation on the repositories you select, and written authorization for the domains in scope. Veyra cannot modify, merge, or delete code, and you can revoke the installation at any time.
Can we run this against staging instead of production?
Yes, and for external testing many teams prefer it. Code analysis is identical either way. If staging differs meaningfully from production, the report will say so rather than implying coverage it does not have.
What if you find nothing serious?
Then the report says that, with the coverage and limitations stated plainly, and you have something credible to show customers and investors. We do not inflate severity to justify an invoice — see the severity model.
Who performs the work?
Analysis is performed by the Veyra platform. Human verification of critical findings, and the remediation walkthrough, are performed by the Veyra team. Veyra is early-stage and does not pretend to be a large firm — you will be dealing directly with the people building it.