# Ceron > Ceron provides AI-assisted security audits of web applications, APIs, cloud infrastructure, and access controls. Assessments cover authorized assets and deliver verified findings, evidence, and prioritized remediation guidance. Core audits start at USD 1,500 as a one-time engagement. Scope and a fixed fee are agreed before testing. The fee applies only when a verified, actionable vulnerability is identified within scope. Larger environments receive a custom quote. An audit is a point-in-time assessment, not a guarantee of complete security. ## Services - [About Ceron](https://getceron.com/about): Our purpose, assessment principles, and founder Mario Luckeneder. Based in Scottsdale, Arizona. - [Security audits](https://getceron.com/): Coverage, approach, deliverables, and the no-findings, no-fee commitment. - [Pricing and frequently asked questions](https://getceron.com/pricing): Core and Extended audits, access requirements, data handling, and engagement limitations. - [Full service reference](https://getceron.com/llms-full.txt): Expanded plain-text service information and FAQs. ## Blog - [Ceron Blog](https://getceron.com/blog): Practical perspectives on application security, AI threats, cloud risk, and security audits. - [Mario Luckeneder](https://getceron.com/authors/mario-luckeneder): Founder of Ceron and author. Browse his biography and complete article archive. - [When Business Documents Become Instructions for an AI Assistant](https://getceron.com/blog/prompt-injection-in-business-documents): How prompt injection reaches assistants through documents, where business permissions matter, and what a controlled security test can establish. - [AI Agent Permissions: Defining What a Business Workflow May Change](https://getceron.com/blog/ai-agent-permissions-business-workflows): Map an AI agent’s tools to business authority, separate preparation from execution, and verify permissions with controlled workflow tests. - [RAG Access Control: What Happens When Document Permissions Change?](https://getceron.com/blog/rag-access-control-after-permission-changes): Follow document permissions through retrieval, cached answers, and citations to test whether an AI search system respects access changes. - [MCP Security: Why a Valid Token May Still Be the Wrong Token](https://getceron.com/blog/mcp-security-token-audience-and-tool-access): Understand token audience, delegated access, and consent boundaries when connecting business applications through Model Context Protocol. - [AI Output Validation: From a Generated Answer to a Business Action](https://getceron.com/blog/validating-ai-output-before-business-actions): Separate structured output, authorization, and transaction validation before model-generated content reaches databases or business systems. - [AI Usage Limits Are Also Availability Controls](https://getceron.com/blog/ai-usage-limits-cost-and-availability): Examine how token budgets, concurrent jobs, retries, and tenant quotas affect the cost and availability of an AI business feature. - [AI Prompt Logs: Where Business Data Goes After the Answer](https://getceron.com/blog/ai-prompt-logs-sensitive-business-data): Trace prompts, responses, and retrieved documents across AI logs to define retention, access, and evidence collection for business data. - [A Model Download Is Part of the Software Supply Chain](https://getceron.com/blog/model-downloads-software-supply-chain): Review model files, loading code, dependencies, and artifact provenance before introducing a downloaded model into business infrastructure. - [Knowledge Base Poisoning: Checking the Sources Behind an AI Answer](https://getceron.com/blog/ai-knowledge-base-poisoning-source-integrity): Examine how document ownership, ingestion, version history, and source verification affect the integrity of answers from a company knowledge base. - [AI Security Evaluations Need Different Questions From Accuracy Tests](https://getceron.com/blog/ai-security-evaluations-business-acceptance): Design AI release checks that distinguish answer quality from unauthorized access, unsafe actions, and failures of business controls. - [Passkey Rollouts Need an Account Recovery Plan](https://getceron.com/blog/passkey-rollout-account-recovery): Review enrollment, lost devices, recovery, and session handling when introducing passkeys to employee or customer accounts. - [After an Account Reset, Which Sessions Still Work?](https://getceron.com/blog/session-revocation-after-account-compromise): Distinguish passwords, access tokens, refresh tokens, and application sessions when verifying that an account reset removes access. - [Password Reset Flows Deserve Their Own Security Review](https://getceron.com/blog/password-reset-flow-security-review): Test reset-token binding, expiry, reuse, notifications, and session behavior across the full account recovery workflow. - [OAuth Refresh Token Rotation: When Two Workers Renew the Same Grant](https://getceron.com/blog/oauth-refresh-token-rotation-business-integrations): Follow concurrent token renewal, replay detection, lost responses, and recovery without turning integration failures into repeated credential reuse. - [OIDC for Deployments: Replacing a Stored Secret With a Trust Policy](https://getceron.com/blog/oidc-ci-cloud-deployment-credentials): Review repository, workflow, environment, and audience conditions when CI jobs exchange OIDC tokens for cloud deployment credentials. - [Service Accounts Need Owners, Expiration Decisions, and Retirement Tests](https://getceron.com/blog/service-account-ownership-and-retirement): Build a reviewable lifecycle for automated identities, including ownership, permissions, credential use, and safe retirement. - [Emergency Administrator Access Must Work During an Identity Outage](https://getceron.com/blog/emergency-admin-access-testing): Evaluate emergency account dependencies, custody, monitoring, and recovery drills without weakening normal administrator access. - [SCIM Offboarding: Verify the Access Change Behind the Directory Update](https://getceron.com/blog/scim-offboarding-access-verification): Follow deprovisioning from the identity provider to SaaS roles, active sessions, API credentials, and scheduled work. - [SSO Domain Claims: Proving Which Company Controls a Workspace](https://getceron.com/blog/sso-domain-claims-tenant-onboarding): Review domain verification, tenant selection, account linking, and ownership changes in enterprise single sign-on onboarding. - [Vendor Access Reviews Need More Than an MFA Checkbox](https://getceron.com/blog/vendor-access-phishing-resistant-mfa): Examine authentication methods, fallback paths, privilege, and session behavior for external administrators and support providers. - [GitHub Actions: The Trust Boundary Between a Pull Request and a Release](https://getceron.com/blog/github-actions-pull-request-trust-boundaries): Review how untrusted contributions, workflow permissions, artifacts, and release jobs interact in a GitHub Actions pipeline. - [Artifact Attestations: What Build Provenance Can Prove](https://getceron.com/blog/artifact-attestations-what-provenance-proves): Separate artifact identity, build provenance, and software quality when evaluating signed release evidence in a deployment pipeline. - [npm Trusted Publishing Changes How a Release Gets Permission](https://getceron.com/blog/npm-trusted-publishing-release-controls): Examine OIDC publishing, workflow identity, package ownership, and remaining credentials when moving npm releases to trusted publishing. - [SBOM and VEX: Two Different Records in a Vulnerability Investigation](https://getceron.com/blog/sbom-vex-vulnerability-response): Use component inventories and exploitability statements together while checking release identity, completeness, and deployment context. - [A Leaked Secret Requires Revocation, Not Just a Deleted Commit](https://getceron.com/blog/leaked-secret-remediation-beyond-git-deletion): Trace a disclosed credential through revocation, replacement, access review, and repository cleanup to verify the exposure is contained. - [Dependency Lockfiles Make Changes Reviewable, but They Still Need Review](https://getceron.com/blog/dependency-lockfiles-security-review): Understand what dependency lockfiles establish, how clean installs use them, and which package changes still require security review. - [Pinned Container Images Need a Deliberate Update Process](https://getceron.com/blog/container-image-digests-patching): Connect container digests, base-image updates, rebuilds, and running deployments to verify that a patch reaches production. - [Self-Hosted CI Runners Extend the Build’s Access Into Your Network](https://getceron.com/blog/self-hosted-ci-runner-isolation): Review persistent state, network reachability, credentials, and job isolation when builds run on company-managed CI infrastructure. - [Private Package Names Need Explicit Registry Rules](https://getceron.com/blog/private-package-registry-dependency-confusion): Review package scopes, registry routing, lockfiles, and install behavior to prevent private dependencies resolving from unintended sources. - [Browser Extensions Belong in the SaaS Access Inventory](https://getceron.com/blog/browser-extension-access-business-applications): Assess extension permissions, business use, update ownership, and access to sensitive browser pages alongside ordinary SaaS integrations. - [Presigned Download URLs Carry Access Beyond the Login Screen](https://getceron.com/blog/presigned-download-urls-access-control): Review how signed file links are issued, shared, logged, expired, and invalidated when private documents leave an application’s access checks. - [A Completed Backup Is the Start of a Recovery Test](https://getceron.com/blog/cloud-backup-restore-testing-business-recovery): Verify data restoration, credentials, application dependencies, and business output instead of relying only on successful backup jobs. - [Kubernetes RBAC: Review What a Permission Allows Indirectly](https://getceron.com/blog/kubernetes-rbac-indirect-permissions): Examine workload creation, secrets, service accounts, and namespace boundaries when assessing Kubernetes access permissions. - [Cloud Audit Logs May Record Configuration Changes Without Recording File Reads](https://getceron.com/blog/cloud-audit-logs-data-access-coverage): Distinguish management events from data events and verify which cloud actions are visible before an investigation depends on them. - [Retiring a Cloud Service Also Means Retiring Its DNS Record](https://getceron.com/blog/subdomain-retirement-dangling-dns): Follow subdomains, provider bindings, certificates, and ownership records when decommissioning a hosted application or campaign site. - [API Field Permissions: Which Parts of a Record May a User Read or Change?](https://getceron.com/blog/api-object-authorization-testing): Review response fields, editable properties, nested updates, and schema changes when a user may access a record but not every value inside it. - [GraphQL Rate Limits Need to Account for Query Cost](https://getceron.com/blog/graphql-query-cost-availability): Review depth, breadth, aliases, batching, and resolver authorization when testing the workload behind a GraphQL request. - [Webhook Security Includes What Happens When the Same Event Arrives Twice](https://getceron.com/blog/webhook-signatures-retries-idempotency): Separate sender verification, replay checks, duplicate handling, and business-state validation in webhook consumers. - [File Upload Security Continues After the Upload Finishes](https://getceron.com/blog/file-upload-processing-security): Trace uploaded files through validation, storage, scanning, previews, downloads, and deletion to review the full processing path. - [URL Import Features Give the Server a New Network Request](https://getceron.com/blog/url-import-features-ssrf-security): Review redirects, DNS resolution, destination rules, and response limits when applications fetch links supplied by users or AI tools. - [When a Cache Stores a Customer-Specific Response](https://getceron.com/blog/cdn-cache-private-customer-data): Check cache keys, response directives, authentication, and invalidation before customer-specific content reaches a shared cache. - [Background Exports Need Authorization at More Than One Moment](https://getceron.com/blog/background-export-jobs-authorization): Follow queued exports from request through generation and download, including permission changes, retries, and tenant-bound storage. - [Race Conditions Can Break a Business Rule Without Breaking Authentication](https://getceron.com/blog/business-logic-race-conditions): Test whether concurrent requests preserve single-use actions, balances, and approval limits across business transactions. - [A Checkout Success Page Is Not Payment Evidence](https://getceron.com/blog/payment-confirmation-fulfillment-security): Connect provider payment status to order fulfillment, duplicate handling, delayed methods, and customer-account binding. - [Support Impersonation Needs Its Own Access Boundary](https://getceron.com/blog/support-impersonation-customer-account-controls): Review approval, scope, actor attribution, restricted actions, and expiry for tools that let support staff view customer accounts. - [Application Audit Logs Need to Explain the Business Action](https://getceron.com/blog/application-audit-logs-investigation-evidence): Design and test audit events that connect actors, customer accounts, actions, outcomes, and request identifiers without retaining unnecessary secrets. - [CVSS, EPSS, and KEV Answer Different Vulnerability Questions](https://getceron.com/blog/cvss-epss-kev-vulnerability-priorities): Combine severity, predicted exploitation, known exploitation, and local exposure without treating any one score as a complete risk decision. - [Remediation Metrics: Measure Verified Closure as Well as Ticket Speed](https://getceron.com/blog/remediation-metrics-verified-risk-reduction): Distinguish discovery, engineering completion, deployment, retesting, and accepted exceptions when reporting vulnerability remediation. - [security.txt Makes a Reporting Channel Discoverable. The Channel Still Needs an Owner.](https://getceron.com/blog/security-txt-vulnerability-disclosure-process): Connect a discoverable security contact to report intake, triage, scope, acknowledgments, and a maintained vulnerability disclosure process. - [Detecting Outdated Answers in a Security Questionnaire Library](https://getceron.com/blog/security-questionnaires-evidence-and-scope): Connect reusable security answers to system changes, evidence versions, review triggers, and correction records before stale statements are reused. - [A Critical CVE Affects Your Technology Stack. Do You Need a Security Assessment?](https://getceron.com/blog/a-critical-cve-affects-your-technology-stack-do-you-need-a-security-assessment): A CVE with a 9-plus CVSS score lands in your inbox, a vendor's security page turns red, and five different people in Slack ask the same question in five different ways: are we affected? - [How to Check If Your Website Is Secure: A Practical Guide](https://getceron.com/blog/how-to-check-if-your-website-is-secure): Most website security problems aren't hidden. - [Missing Security Headers: What They Mean and How to Fix Them](https://getceron.com/blog/missing-security-headers-what-they-mean-and-how-to-fix-them): A missing security header rarely takes more than one line to fix. - [What Can Hackers Learn About Your Company From Its Domain?](https://getceron.com/blog/what-can-hackers-learn-about-your-company-from-its-domain): Before an attacker ever touches a login form or tries a single exploit, they've usually already learned a lot about your company just from your domain name. - [Does HTTPS Mean Your Website Is Secure?](https://getceron.com/blog/does-https-mean-your-website-is-secure): The padlock icon in a browser's address bar has become shorthand for safe. - [Website Security Scan Results Explained: What's Actually Dangerous?](https://getceron.com/blog/website-security-scan-results-explained-whats-actually-dangerous): Run any website security scan and you'll get a list back. Some of it will look alarming. - [How to Choose a Security Assessment Provider: 10 Questions to Ask Before Hiring](https://getceron.com/blog/how-to-choose-a-security-assessment-provider-10-questions-to-ask-before-hiring): Security assessment providers all sound similar on a sales call. - [OpenAI vs Open Source: Hacking of HuggingFace](https://getceron.com/blog/openai-vs-open-source-hacking-of-huggingface): None of the traditional lines of defense move at the speed of an agent swarm coordinating over its own private channel. - [Switching IT Providers? Why Your Company Should Consider a Security Assessment During the Handover](https://getceron.com/blog/switching-it-providers-why-your-company-should-consider-a-security-assessment-during-the-handover): The contract with your old IT provider ends on a Friday. The new provider starts Monday. - [Security Assessments for SaaS Integrations: What to Test Before Connecting Customer Accounts](https://getceron.com/blog/security-assessments-for-saas-integrations-what-to-test-before-connecting-customer-accounts): Between August 8 and August 18, 2025, attackers used stolen OAuth tokens from a single third-party chat integration to pull data out of more than 700 Salesforce environments, plus a subset of connected Google Workspace inboxes. - [No Findings, No Fee Security Assessments: How Does Outcome-Based Pricing Work?](https://getceron.com/blog/no-findings-no-fee-security-assessments-how-does-outcome-based-pricing-work): Most security assessment providers get paid the same amount whether they find a critical vulnerability or nothing at all. - [Bug Bounty Programs vs. Security Assessments: What Should Businesses Pay For?](https://getceron.com/blog/bug-bounty-programs-vs-security-assessments-what-should-businesses-pay-for): Two CTOs can spend the same security budget on completely different things and end up with completely different answers to the same question: what's actually wrong with our systems. - [Customer Portal Security Assessments: Protecting the Systems Your Clients Log Into](https://getceron.com/blog/customer-portal-security-assessments-protecting-the-systems-your-clients-log-into): Every SaaS product eventually earns a login screen that matters more than the rest of the site combined. - [Security Assessments After Cloud Migration: What Needs to Be Revalidated?](https://getceron.com/blog/security-assessments-after-cloud-migration-what-needs-to-be-revalidated): A cloud migration doesn't move your security posture along with your data. It resets it. - [Security Due Diligence Before Fundraising: What Should Startups Have Ready?](https://getceron.com/blog/security-due-diligence-before-fundraising-what-should-startups-have-ready): Investors used to evaluate a startup on three things: the team, the market, and the traction. - [Vibe Coding Security: What to Audit Before Deploying an AI-Built Application](https://getceron.com/blog/vibe-coding-security-what-to-audit-before-deploying-an-ai-built-application): You can describe an entire SaaS product in a chat window and have a working, deployed application within a weekend. - [Multi-Domain Security Assessments: How to Identify and Scope Every Public-Facing Asset](https://getceron.com/blog/multi-domain-security-assessments-how-to-identify-and-scope-every-public-facing-asset): Ask most companies how many domains and subdomains they operate, and the number they give you is almost always wrong, not because anyone is lying, but because nobody has actually looked. - [Your Web Agency Just Delivered Your Website. Who's Responsible for Security?](https://getceron.com/blog/your-web-agency-just-delivered-your-website-whos-responsible-for-security): The website is done. The agency sends the final invoice, you make the last payment, and the project moves into "launched" status. - [E-commerce Security Assessments: What to Check Before Peak Sales](https://getceron.com/blog/e-commerce-security-assessments-what-to-check-before-peak-sales): Attackers don't wait for Black Friday to start planning for it. - [Cybersecurity Due Diligence for Acquisitions: What to Assess Before Buying a Company](https://getceron.com/blog/cybersecurity-due-diligence-for-acquisitions): Buying a company means buying its data, its infrastructure, and every unresolved vulnerability sitting inside it, whether anyone disclosed those vulnerabilities or not. - [Security Assessment Retesting: How to Verify Vulnerabilities Have Actually Been Fixed](https://getceron.com/blog/security-assessment-retesting-how-to-verify-vulnerabilities-have-actually-been-fixed): A vulnerability assessment report tells you what's broken. - [Web Application vs. Infrastructure Security Assessments: Which One Do You Need?](https://getceron.com/blog/web-application-vs-infrastructure-security-assessments): Security assessment gets treated as one product on most sales pages, but web application testing and infrastructure testing check fundamentally different layers of your environment, using different methodology, finding different categories of risk. - [Vulnerability Assessment for Startups: Your Enterprise Customer Requested a Security Assessment. What Happens Next?](https://getceron.com/blog/vulnerability-assessment-for-startups-enterprise-customer-security-assessment): An enterprise prospect's security team sends over a questionnaire, or a one-line email asking for your latest penetration test report, and the deal that was moving through your pipeline suddenly stalls on a document you don't have. - [Vulnerability Assessment for Startups: What to Test Before Launching](https://getceron.com/blog/vulnerability-assessment-for-startups): Pre-launch is the cheapest point in your company's life to find a security problem, and the most expensive point to skip looking for one. - [Website Security Audit for Businesses: What Gets Checked and What You'll Receive](https://getceron.com/blog/website-security-audit-for-businesses): A website security audit means something specific: a scoped engagement where your web applications, APIs, cloud infrastructure, and access controls get tested against real exploitation techniques, not just matched against a list of known software versions. - [Automated vs. Manual Vulnerability Assessments: Which Does Your Business Need?](https://getceron.com/blog/automated-vs-manual-vulnerability-assessments): The old framing was simple: automated vulnerability scanning was fast and shallow, manual penetration testing was slow and thorough, and businesses picked one or budgeted for both. - [How Often Should Your Company Conduct a Security Assessment?](https://getceron.com/blog/how-often-should-your-company-conduct-a-security-assessment): The right cadence depends on compliance obligations, how fast your attack surface changes, and what happens between assessments if something new gets exposed and nobody catches it. - [What Is an External Security Assessment? A Guide for Businesses](https://getceron.com/blog/what-is-an-external-security-assessment): An external security assessment tests your organization the way an actual attacker sees it: from outside your network, with no privileged access, using only what's publicly reachable. - [AI Security Assessments: How They Work, What They Find, and Their Limitations](https://getceron.com/blog/ai-security-assessments-how-they-work-what-they-find-and-their-limitations): Security testing has run on the same basic model for two decades: automated scanners flag known issues, and human testers manually dig for what the scanners miss. - [How Much Does a Security Assessment Cost in 2026?](https://getceron.com/blog/how-much-does-a-security-assessment-cost-in-2026): Security assessment pricing spans an enormous range in 2026, anywhere from a few hundred dollars for an automated scan subscription to well into the six figures for a full penetration test across a complex enterprise environment. - [Vulnerability Assessment vs. Penetration Testing: What's the Difference?](https://getceron.com/blog/vulnerability-assessment-vs-penetration-testing): Compliance frameworks like SOC 2 and PCI DSS often require both a vulnerability assessment and a penetration test, but plenty of security budgets get spent on one when the mandate actually called for the other. - [The AI Arms Race](https://getceron.com/blog/the-ai-arms-race): AI has changed the economics of cyberattacks. Mario Luckeneder explores what happens when offense scales faster than defense. ## Contact - [Book a scoping call](https://calendly.com/mario-getceron/30min): A 30-minute conversation to define scope and fee; no system access needed for the call. - [Email Ceron](mailto:mario@useceron.com): Contact Mario about an assessment. ## Optional - [Sitemap](https://getceron.com/sitemap.xml): Canonical public pages. - [X](https://x.com/getceron): Ceron social profile. - [Instagram](https://www.instagram.com/getceron): Ceron social profile.