ceron
Book a Call
STRAIGHTFORWARD BY DESIGN

No findings, no fee.

Your fee is agreed before testing and only applies if we find a qualifying vulnerability.

Extended audit

DEEPER TESTING

Test how an attacker could move across your systems.

Tailored to your environmentCustom quoteOne-time
Plan an extended audit

Go beyond a single application

Penetration testing

Test exploitable weaknesses across your agreed coverage.

For multiple apps, cloud accounts, complex access roles, or internal networks.

CORE DELIVERABLES, PLUS
  • Multiple environments and asset groups
  • Additional access roles and trust boundaries
  • Penetration testing within agreed boundaries
  • Fee and delivery window agreed upfront

What counts as a finding? A verified, actionable vulnerability within the agreed coverage. The fixed fee does not increase with the number of findings.

COVERAGE, NOT HEADCOUNT

Price the attack surface.
Not the org chart.

A small team can run complex infrastructure. A larger company can have a simple environment. We price the work around what needs testing.

01

What’s exposed

Applications, APIs, domains, and services that need testing.

ASSETS
02

How it connects

Cloud accounts, networks, and integrations between systems.

ENVIRONMENTS
03

How deep we go

Access roles, internal testing, and the complexity of your setup.

TESTING DEPTH
A FEW GOOD QUESTIONS

Clear from the start.

A question about your environment?
Talk directly with Mario

What access do we need to provide?+

You choose the assets and access included in the audit. An external assessment can begin with approved public-facing assets. Cloud, internal, or authenticated testing requires separately agreed permissions. The report identifies any limits caused by unavailable access.

How is our data handled during the audit?+

Before granting access, agree in writing on the data the assessment may use, any AI providers involved, retention and deletion terms, and how findings will be delivered. These terms belong in the engagement scope before testing begins.

Do I pay anything if you find nothing?+

No. If the agreed assessment finds no verified, actionable vulnerability, the audit fee is $0. You still receive a summary of the scope and assessment outcome.

Is $1,500 the price for every company?+

It is the starting price for a focused audit. Larger asset counts, additional environments, and more complex testing receive a custom fixed quote before work begins.

How is severity determined?+

Findings are rated Critical, High, Medium, or Low based on evidence, exploitability, potential impact, and the context of your environment. The report explains the reasoning and what to prioritize.

Does a clean audit mean we are completely secure?+

An audit is a point-in-time assessment within agreed boundaries. No findings means none were identified in that assessment; it does not guarantee that every vulnerability has been discovered.

Does the audit include fixing the issues?+

The audit includes remediation guidance. Implementation and any follow-up testing are separate work unless explicitly included in your agreed scope.

Will testing disrupt our business?+

Testing boundaries, permissions, and timing are agreed before work begins. Disruptive testing requires explicit authorization. Your engagement defines the permitted methods and stop conditions.

LET’S PLAN YOUR AUDIT

Start with a conversation.

Book 30 minutes with Mario to discuss your infrastructure, access preferences, and audit goals. We’ll confirm the coverage and fee before any testing begins.

30 minutes · Scheduled through Calendly