// SECURITY ASSESSMENT

Start with your current security posture.

Tell us what you run. We will confirm scope, agree the authorization in writing, and return a prioritized assessment of what is actually exposed across your code, APIs, and external surface.

NO OBLIGATION TO SUBSCRIBE · READ-ONLY ACCESS · AUTHORIZED ASSETS ONLY

Request a security assessment

Every field helps us scope accurately. If something is not settled yet, say so in the notes — an approximate answer is more useful than a blank.

We reply from a person, not a sequence.

Not sure? Leave it blank and we will recommend a scope.

GitHub is supported today. Others are on the roadmap — tell us and we will be straight about timing.

One per line. Only list assets your company owns or is contractually authorized to have tested.

We reply within one business day. No testing of any kind begins until scope and authorization are agreed in writing.

// DELIVERABLES

What you receive.

Two reports, written for two different audiences, because the person who approves the budget and the person who writes the fix need different things.

EXECUTIVE SECURITY REPORT

For founders, CEOs, CTOs, and boards.

  • Overall security posture and score
  • Critical risks in business language
  • Potential business impact of each
  • Asset coverage — what was and was not assessed
  • Remediation priorities and effort estimates
  • Risk trend once monitoring is running

TECHNICAL SECURITY REPORT

For engineers and engineering leadership.

  • Every finding with severity and confidence
  • Affected repository, file, and route
  • Evidence sufficient to reproduce safely
  • Correlated attack paths
  • Specific remediation guidance per finding
  • Verification status and references

Assessment packages.

Every package is credited in full toward your first three months if you subscribe within 30 days.

PackagePriceScopeTurnaround
Focused$7501 application, 1 repository. Code, dependencies, secrets, API inventory.≈5 business days
Standard$1,500Up to 3 applications, 5 repositories, plus external surface and correlated attack paths.≈7 business days
Comprehensive$2,500Up to 10 applications, human verification of critical findings, remediation session, re-test.≈10 business days

See full pricing and ongoing plans

Common questions

Do we have to subscribe afterwards?
No. The assessment is a standalone engagement and the report is yours regardless. If you do subscribe within 30 days, the entire fee is credited toward your first three months.
What access do you actually need?
A read-only GitHub App installation on the repositories you select, and written authorization for the domains in scope. Veyra cannot modify, merge, or delete code, and you can revoke the installation at any time.
Can we run this against staging instead of production?
Yes, and for external testing many teams prefer it. Code analysis is identical either way. If staging differs meaningfully from production, the report will say so rather than implying coverage it does not have.
What if you find nothing serious?
Then the report says that, with the coverage and limitations stated plainly, and you have something credible to show customers and investors. We do not inflate severity to justify an invoice — see the severity model.
Who performs the work?
Analysis is performed by the Veyra platform. Human verification of critical findings, and the remediation walkthrough, are performed by the Veyra team. Veyra is early-stage and does not pretend to be a large firm — you will be dealing directly with the people building it.