FastSiteLab

    Website Security Check

    Know what needs fixing. Give your developer a clear next step.

    We check common technical security weaknesses within an agreed scope, validate what we observe and explain what it means for your business. You get practical priorities and one free follow-up check of the findings.

    Packages from €590 + VAT. Scope and suitability confirmed before work starts.

    One website. A defined scope.

    Choose the depth of the review

    All prices exclude VAT. We confirm the exact assets, flows and any additional work before starting.

    External Check

    €590+ VAT

    For a small website with a public-facing scope.

    What we check

    One website, up to two explicitly named public hostnames and one email domain.

    Public configuration and low-impact checks. No authenticated business-logic testing.

    What you receive

    • Asset inventory and a tested/not-tested checklist
    • Manually validated observations and a prioritized report

    We explain the results and include one free follow-up check of the original findings and any fixes. You have a 30-day window to use this included service. Timing is agreed based on scope and complexity.

    Enquire about this package
    Main offer

    Security Review

    €990+ VAT

    For an owner who needs clear priorities and a developer who can act on them.

    What we check

    External Check plus deployment/configuration evidence supplied by you and up to three named application flows.

    Account/role testing only when explicitly scoped, with controlled test accounts and suitable expertise.

    What you receive

    • Everything in External Check, with reproducible evidence
    • Coverage matrix and tickets ready for your developer

    We explain the results and include one free follow-up check of the original findings and any fixes. You have a 30-day window to use this included service. Timing is agreed based on scope and complexity.

    Enquire about this package

    Review & Hardening

    €1,490+ VAT

    For a scoped review plus a small, agreed batch of fixes.

    What we check

    Security Review plus up to four hours implementing agreed, reversible configuration or small code fixes on a supported stack.

    The same bounded testing scope. Larger changes are quoted separately; not every finding is guaranteed to be fixed.

    What you receive

    • Everything in Security Review, with reviewed changes and rollback notes
    • Regression checks for affected flows and updated findings

    We explain the results and include one free follow-up check of the original findings and any fixes. You have a 30-day window to use this included service. Timing is agreed based on scope and complexity.

    Enquire about this package

    A separate authentication origin can use the second hostname. Extra subdomains, applications, tenants and integrations are not included automatically. Each flow names its operations, roles and expected outcomes; additional work needs agreement first.

    How the review works

    1. 01

      Agree the boundaries

      We agree the authorized assets, methods, test window, contacts and stop conditions before testing. Controlled test accounts and synthetic data are used where needed.

    2. 02

      Check and validate

      A qualified person validates findings before delivery. The report separates confirmed vulnerabilities, hardening opportunities, inconclusive tests and areas not tested.

    3. 03

      Explain the results and recheck

      We discuss the results with you and your developer, explain the priorities and how to verify a correction. Your package includes one free follow-up check of the original findings and any fixes, with a 30-day window to use it. This is your follow-up benefit, not the turnaround time for the initial review. We agree when the 30-day window starts and schedule the work based on scope and complexity.

    Useful evidence. Clear next actions.

    Your report explains what matters to the business, what was covered and what your developer should do next. The number of findings is not a measure of value: finding no issues within a documented test plan is a valid outcome.

    • Owner summary with priorities and business implications
    • Agreed assets, versions where available, coverage and limitations
    • Validated findings, separate hardening opportunities and remediation criteria
    • Verification or retest results linked to the updated version

    Clear limits, before we start

    This is a scoped technical review, not a comprehensive penetration test, a security certification or a guarantee that a website is secure. Automated output alone is not a confirmed finding. Areas we cannot competently test are recorded as not tested.

    Complex multi-tenant SaaS assessments, payment business logic, bespoke cryptography, infrastructure penetration testing, social engineering, denial-of-service testing and compliance certification require a separate scope and appropriate specialist delivery.

    How this fits with Care

    Care already includes ongoing technical security care. This separate review adds a defined assessment, documented coverage, validated findings and one free follow-up check, for example after changes or when taking over an existing website.

    Normal secure delivery remains part of our website work. We do not charge extra just to correct basic defects in our own delivery. A review of a site we built is not presented as independent assurance.

    See Care plans

    Start with your website and your concern

    Tell us the public website address and what prompted the review. We will confirm whether the scope fits and agree the next steps.

    Request a security review

    Please do not send passwords, API keys, security evidence or sensitive system details through the public form. We agree secure evidence handling separately.

    Call Now