Website and System Security and Vulnerability Testing
Our website and system security service starts with a methodical review of your website, system or app: common vulnerabilities, permissions, password storage, data protection, server configuration and secrets exposed in the code. Then we fix what we find and hand you a written report of priorities. It suits companies that hold customer, payment or employee data, anyone who has been hacked, and anyone preparing for a compliance review. The assessment usually takes one to 3 weeks depending on the size of the system. The cost depends on the number of systems and interfaces and the scope of testing and fixing. We send you a written quote within 24 hours.
- Quote
- Written, within 24 hours
- Timeline
- One to 3 weeks for the assessment, with fixes based on the findings
- Ownership
- The code is yours
- Delivery
- On the agreed date
On this page
- Who is this for?
- What you get
- When do you need a security assessment?
- What does the security report include?
- How we test your system, and what we usually find
- Payment and personal data security
- What to do if your site has just been hacked
- Security is not a one-off task
- Our commitments
- How we work with you
- Frequently asked questions
Who is this for?
- Companies that hold customer or payment data and worry about leaks
- Businesses whose site was hacked, defaced or is sending spam from its server
- Companies preparing for a PDPL compliance review
- Legacy systems that have not been updated in years and whose security status is unknown
- Companies that want their systems secured before launching an app or client portal
What you get
Common vulnerability testing
SQL injection, cross-site scripting, broken access control and dangerous file uploads.
Permissions review
Making sure every user sees and edits only what is theirs, and admin panels are not exposed.
Leaked secrets detection
Searching for keys and passwords written into code, repositories or configuration files.
Server hardening
Closing ports, updating the OS, enabling a firewall and secure key-based login.
Login protection
Two-factor authentication, login attempt limits and correct password storage.
Personal data protection
Encrypting sensitive data, access logs, and documenting where data is stored in line with the PDPL.
Incident response plan
What to do in the first hour after discovering a breach, and who contacts whom.
Report and remediation
A written report of vulnerabilities ranked by severity, then fixes and a retest to confirm.
When do you need a security assessment?
Do not wait for a breach. A security assessment is essential before launching a system that holds customer data, after inheriting a system from another developer whose work you do not know, when the system has not been updated for over a year, and before any compliance review or request from a major client.
Some signs call for an urgent check: strange pages appearing in search results under your domain, spam going out from your mailbox, sudden slowness with no explanation, or user accounts nobody created.
What does the security report include?
A good report is written for two audiences: management, who need to understand the size of the risk and the spending decision, and the technical team, who need precise fix steps. So we split it into a short executive summary, followed by technical detail for each vulnerability.
For each vulnerability we document where it was found, how it can be exploited, its potential impact on your business and data, its severity and the recommended fix. We include evidence that proves it without actually using it to reach more real data than needed to prove the point.
After the fixes we retest the same vulnerabilities and update the report with the status of each, so you have a documented record of what was found, what was closed and when. That record is useful in any compliance review, or when a major client asks about the security of your systems.
- A non-technical executive summary for management
- Vulnerabilities ranked by severity and impact
- Specific fix steps for each vulnerability
- General recommendations on permissions, backups and monitoring
- Retest results after remediation
How we test your system, and what we usually find
We combine automated scanning, which finds known vulnerabilities quickly, with manual review, which finds what tools miss: permission logic, payment flows, and what happens when a user changes a number in the URL. The most serious vulnerabilities in custom systems are usually logical, not technical.
From our experience reviewing systems, the most dangerous problems are not exotic techniques but simple mistakes that repeat over and over. Knowing them helps you ask any developer about them before handover.
Fixing these points alone closes most of the routes attackers use against custom systems, and many of them can be fixed in hours, not days.
- Scope defined in writing: which domains, systems and apps are covered
- Automated scanning for outdated libraries and weak configuration
- Manual review of permissions, login, payments and file uploads
- Review of the server, backups and access logs
- A report with severity, impact and fix steps for each vulnerability
- Pages that show any customer’s data just by changing the number in the URL
- An admin panel on a well-known URL with no two-factor authentication or login attempt limit
- Payment gateway or cloud service keys written inside the code or the mobile app
- Accounts of employees who left the company still active
- File uploads with no type checking, letting an attacker upload a file that runs on the server
- Backups stored on the same server, so they are lost with it in a breach
Payment and personal data security
If your system accepts payments through mada, Apple Pay, STC Pay, Tabby or Tamara, the golden rule is that card data should never pass through your server at all; it is processed by the payment gateway and you receive only the result. We check that the integration is built this way and that payment notifications are signed and cannot be forged.
For personal data, we review what you actually collect, who can see it, whether it is encrypted and where it is stored. The goal is to collect the minimum you need and protect it well, in line with the PDPL.
What to do if your site has just been hacked
Do not delete anything or reinstall the system before preserving the evidence; the logs reveal how the attacker got in and how to keep them out. Change the passwords for the control panel, hosting, email and domain immediately from a clean device, and enable two-factor authentication.
Contact us on WhatsApp and we start by containing the damage, then find and close the vulnerability, then clean up and restore from a clean backup, then monitor closely. You receive a written report of what happened and what changed.
Security is not a one-off task
New vulnerabilities are found in libraries every week, so an assessment you ran a year ago does not mean you are safe today. We recommend including security updates in a maintenance contract, and retesting with every major release or at least once a year.
The cheapest security measure is staff training: most breaches start with a phishing message or a reused password. A short session with your team can protect you more than any tool.
Our commitments
You own the code
Source code, accounts and domain are in your organisation’s name from day one.
Written scope and contract
Scope, milestones and price are agreed in writing before the first line of code.
On-time delivery, guaranteed
The delivery date is written into the contract, and we keep it at every milestone.
Fast technical support
A team that responds quickly after launch and fixes any issue in production.
How we work with you
- 1
Free discovery session
30 minutes with an engineer to understand your needs and how you work.
- 2
Written proposal within 24 hours
Clear scope, milestones, timeline and a price in SAR, with no obligation.
- 3
Contract and staged payments
You pay in stages tied to deliveries, not everything upfront.
- 4
Delivery with weekly reports
Follow progress in the client portal and review every milestone before sign-off.
- 5
Launch, training and support
We launch on schedule, train your team and stay with you with fast support.
Frequently asked questions
How much does a security assessment for a website or system cost?
It depends on the number of systems, interfaces, user types and the scope of testing; a brochure site is very different from an ERP with dozens of permission levels. We define the scope in writing first, then send a written quote within 24 hours that separates the cost of testing from the cost of fixing. The assessment is usually far cheaper than a single breach: downtime, data recovery, and lost customer trust that money cannot buy back.
My site was hacked. What should I do first?
Do not delete files before saving a copy of them and of the logs, and change the passwords for hosting, the control panel, email and domain from a clean device, with two-factor authentication on. Then contact us on WhatsApp so we can contain the damage, find the vulnerability, clean the site and restore it. The sooner you start, the less damage: some breaches silently steal data for weeks, while others use your server to send spam that damages your domain’s reputation.
Does the assessment include fixing the vulnerabilities?
We keep the two stages separate so the report stays neutral and clear. The assessment ends with a written report ranked by severity, then we quote for the fixes, and you can give them to us or to your own team. After the fixes we retest to confirm. The report is ordered so your team starts with critical vulnerabilities that could be exploited today, then important ones, then improvements that can be scheduled into regular maintenance.
Do you test mobile apps too?
Yes. We review the APIs the app talks to, how sessions and data are stored on the device, and whether keys are exposed inside the app. Most app vulnerabilities are in the server it connects to, not in the app itself. We also test what happens when a user tampers with requests sent from the app, because trusting the app alone without server-side checks is a common mistake.
Can you help us comply with the PDPL?
We help with the technical side: inventorying the personal data the system collects, setting up permissions, encryption and access logs, and documenting where data is stored. The legal side, policies and procedures, needs a legal adviser, and we work alongside them when needed. The goal is clear technical documentation you can present in any review: where the data is, who can access it, and how it is protected.
Will you see our sensitive data?
We work with the least access possible and in a test environment when one is available, and we sign an NDA on request. We do not copy production data to our machines, and access is revoked when the engagement ends. If the assessment needs real data, we use masked samples wherever possible and document every access granted to us and the date it was revoked.
How often do we need a security assessment?
At least once a year, and with every major release, every change to payments or permissions, and after any incident. Between assessments, regular security updates under a maintenance contract cover most new risks. Ideally the annual assessment coincides with a permissions review and the removal of accounts belonging to employees who have left, one of the most neglected gaps.
What is the difference between vulnerability scanning and penetration testing?
Vulnerability scanning searches broadly and methodically for known weaknesses. Penetration testing simulates a real attacker trying to exploit them to reach a specific target. We agree with you which fits your system and its stage before writing the scope. What matters is not the name but the written scope: which systems are covered, what may be tested, and when testing happens so your business is not disrupted.
You may also need
Ready to start?
Send us your idea on WhatsApp and get a written proposal with scope, timeline and price within 24 hours.
Talk to us on WhatsAppLast updated: