Spot Check
from$500
A static, read-only scan of your repo — your full score, fast.
- Static, read-only repo scan
- Full 0–4 score across all 8 dimensions
- Prioritized fix list
- Technical report
The Agent-C Checkup
A production-readiness score for the app you built without a security team — a plain-language grade across the 8 things that decide whether you're ready for real users, plus exactly what to fix first.
● 8-dimension maturity model · anchored to OWASP ASVS + PTES
Sound familiar?
You shipped something real without a dedicated security or infrastructure person — because you were busy shipping. That's not a mistake. It just means the role a security team usually owns hasn't been filled yet.
And you're staring at it, unsure which answers are true, which are aspirational, and which will lose the deal.
"It works on my machine" was fine at zero users. It is not a security posture at a thousand.
Boutique pentests are built for enterprises with a security team already in place. You need a straight answer first.
The Agent-C Checkup handles exactly that: the production-readiness work a security team would normally own — scored, prioritized, and explained in plain language.
The 8 checks
Each one is graded 0–4 on the same red→green scale you saw up top. Security carries the most weight — it's where the damage is worst and the questions are hardest.
Clean history, secrets kept out of the repo, and access that actually controls who can change what.
Code reaches production through a repeatable, reviewed pipeline — not a laptop and a prayer.
Prod and staging are separated, configured, and reproducible if you had to rebuild tomorrow.
Enough automated coverage that you can change code without quietly breaking something else.
Auth, input handling, dependencies, secrets, and the OWASP basics an attacker checks first.
When something breaks at 2am, you can see what broke and why — before a customer tells you.
If the database died right now, you could get it back — and you have actually tested that.
A new developer — or you in six months — can understand, run, and safely change the system.
How it works
A checkup is a fixed, hands-on engagement — not a subscription you have to babysit. Here's the whole thing.
Pick a tier and tell us about your app — stack, where it runs, and what a customer is asking for.
We scan and review your codebase — and, at higher tiers, your pipeline and running system — against the rubric.
A clear grade, a prioritized fix list, and — on Deep and Full — a signed Letter of Attestation you can share.
What you get
Every checkup ends with something you can act on today and something you can show someone else. Higher tiers add the sharable proof.
The 0–4 grade across all 8 dimensions — the same picture you saw up top, for your codebase.
What to fix first, in plain language, ordered by risk reduced — not an alphabetized vulnerability dump.
The detail behind each grade, written for whoever actually does the fixing.
Shareable, signed proof of the work — the thing you hand a customer or auditor to unblock a deal.
We re-check after you fix, and confirm the score moved — so the attestation reflects reality.
Pricing
Three tiers, by how much access you grant — from a read-only repo scan to live testing of the running system. Every tier gives you the full 8-dimension score.
from$500
A static, read-only scan of your repo — your full score, fast.
from$1,500
Adds your pipeline and staging — plus proof you can share.
Everything in Spot Check, plus
from$3,500
Adds live testing against the running system, and a retest.
Everything in Deep Check, plus
Prices are typical starting points. Every codebase is different — a single simple repo and a complex, multi-service system take very different amounts of work, so the final quote depends on scope. We'll confirm before any work begins.
Coming soonWant a score that stays live as your code changes? That's the platform —join the waitlist.
The always-on platform re-checks your code as it changes, so your score never goes stale — and you can prove it stayed high. Join the waitlist and we'll email you when it opens.
Who's behind it
Agent-C Security is run by a developer who has spent three decades building, shipping, and cleaning up production software — the same work you're doing, seen from the other side of a lot of incidents. The Checkup is the review a seasoned engineer would give your codebase, written so you can actually act on it.
No fear-mongering, no theater. Just a straight read on where your code stands and what to fix first — anchored to standards a security team would recognize.
Sample report
A redacted sample — the scorecard, the prioritized fix list, and the technical write-up — so you know exactly what lands in your inbox. Drop your email and we'll send it over.
FAQ
Not exactly. A pentest looks for a way in; the Checkup grades whether your whole app is ready for real users — across 8 dimensions, security included. The Full tier does add live/dynamic testing, so it's the closest to a pentest, but with the wider production-readiness picture around it.
As little as you want. Spot Check is a static, read-only look at your repo. Deep adds your pipeline and staging config. Full adds testing against a running system — and only with your explicit sign-off on scope first.
Yes — that's what the Letter of Attestation is for. On Deep and Full you get a signed letter you can hand to a customer's security team or an auditor to unblock a deal, without handing over your raw report.
A checkup is a fixed, scoped engagement — usually days, not weeks. Because scope drives the work, we agree on it (and the quote) with you before anything starts.
We work from the least access that gets the job done, and we scope data handling with you up front. (Exact retention and handling terms are confirmed as part of booking.)
Usually yes — the value is the honest, prioritized picture across all 8 dimensions. If a dimension is already solid, that shows in the score; the fix list just points you at the ones that aren't.
Book a checkup
Tell us about your app and which tier you're leaning toward. We'll confirm scope and a fixed quote before any work begins — no obligation.