Secure Web App Development
Web Applications Built Secure Before They Ship
Most development agencies build the product and treat security as someone else's problem. Most security firms arrive after launch and hand you a list of things that are now expensive to fix. We do both, which means the people writing your authentication logic are the same people who know how it gets attacked.
Every application we build is penetration tested before it reaches production. Not by a third party you have to coordinate with afterwards, and not as an upsell. It is part of the engagement.
Request a quote Book a 15-minute call
Why security has to happen during the build
The cost of fixing a security defect rises sharply with how late you find it. A missing authorisation check caught during architecture is a conversation. The same check caught in a pentest two days before launch is a delayed release. Caught six months after launch by someone who was not supposed to find it, it is an incident with disclosure obligations.
The defects that hurt most are rarely exotic. They are broken access control, where one user can read another user's records by changing an ID. They are secrets committed to a repository. They are a session that never properly expires. None of these are hard to prevent while building, and all of them are painful to retrofit.
What we do differently
- Threat modelling before the first line of code. We map who your users are, what they are allowed to touch, and what an attacker would want. That drives the data model, not the other way round.
- Authorisation designed once, applied everywhere. Access control enforced at a single layer that every request passes through, rather than repeated per-endpoint checks that eventually get forgotten.
- Secrets never touch the repository. Environment-scoped secret storage from day one, with rotation paths defined before launch instead of discovered during an incident.
- Dependency review as part of the build. We have written extensively about npm and PyPI supply chain compromises, because packages are now a primary attack path rather than a background risk.
- A real penetration test before launch. Full application test, remediation-ready report, and a free verification retest once fixes are in.
Engagements and pricing
Fixed scope, fixed price, security tested before anything reaches production.
Three weeks. Up to three workflow automations or system integrations, built and handed over.
90 days. Custom web application or AI tool, penetration tested before launch. Billed 40/30/30.
Multi-tenant architecture, role-based access, SSO, audit logging, and third-party integrations.
What Secure Build includes at $38,000
- Discovery and security architecture: $6,000
- Custom application build: the core engagement
- Pre-launch penetration test: $6,500
- Cloud and identity hardening sprint: $5,500
- First 90 days of App Care: $2,550
- Launch monitoring and incident runbook: $3,000
$61,550 of scope, delivered for $38,000.
Keeping it secure after launch
Software is never finished. The dependencies you shipped with will have known vulnerabilities within months whether or not anyone is looking. These plans cover the work that keeps the application secure once it is live.
Dependency and security patching, backups, uptime monitoring, and a quarterly health report.
App Care plus continuous vulnerability scanning, quarterly pentest of changed surface, identity and secrets review, and one-hour incident acknowledgement.
Secure Operate plus one feature drop per month and standing roadmap sessions.
Our guarantees
Ship or We Work Free. Secure Build ships in 90 days, or we keep working at no charge until it does. Requires 48-hour feedback turnaround and the access and content agreed at kickoff.
Clean-Code Warranty. Any critical vulnerability we introduced, found within 12 months of launch, is fixed at no cost and that month's retainer is credited.
Fixed Scope, Fixed Price. If the signed scope takes longer than we estimated, we absorb the overage. You pay what the proposal says.
How a Secure Build runs
- Discovery and security architecture, weeks 1-2. Requirements, threat model, data model, and the authorisation design. You get the architecture document before we build against it.
- Core build, weeks 3-10. Two-week increments with a working deployment at the end of each. You see progress continuously rather than at a single reveal.
- Penetration test, weeks 11-12. Full application test against the near-final build, with time reserved to fix what it finds.
- Hardening and launch, week 13. Cloud and identity hardening, monitoring, incident runbook, and handover.
Building something with AI in it?
LLM features change the threat model. Prompt injection, over-permissioned agents and model supply chain risk are not covered by conventional application testing, and we test for them separately.
Frequently Asked Questions
What does secure web application development actually mean?
It means the security work happens during the build instead of after it. Threat modelling at architecture, authentication and authorisation designed before the first feature, secure defaults for sessions, secrets and data handling, and a full penetration test before launch. The alternative is shipping and then paying to find out what is wrong.
How much does it cost to build a secure web application?
A Secure Build is $38,000 for a custom web application or AI tool delivered in 90 days, billed 40/30/30, with a penetration test included before launch. Smaller scopes start at $9,500 for a three-week automation sprint. Multi-tenant platforms with SSO, role-based access and audit logging start at $95,000.
What is included in the $38,000 Secure Build?
Discovery and security architecture worth $6,000, the custom application build itself, a pre-launch penetration test worth $6,500, a cloud and identity hardening sprint worth $5,500, the first 90 days of App Care worth $2,550, and launch monitoring with an incident runbook worth $3,000. That is $61,550 of scope delivered for $38,000.
What happens if the project runs late?
Secure Build ships in 90 days or we keep working at no charge until it does. That requires a 48-hour feedback turnaround from you and the access and content agreed at kickoff, since we cannot hold a deadline while waiting on decisions.
What if you introduce a vulnerability?
Any critical vulnerability we introduced, found within 12 months of launch, is fixed at no cost and that month's retainer is credited. We wrote the code, so the defect is ours.
Do you work with an existing codebase?
Yes. We review what is there, produce a findings report with severity and effort estimates, and then either remediate it or continue building on it. Inheriting a codebase usually starts with a penetration test so both sides know the real starting position.
What technologies do you build on?
Primarily TypeScript across the stack, deployed on Cloudflare Workers and Pages with edge databases and object storage. We choose boring, well-understood infrastructure because unusual choices are where security bugs hide.
Do we need a retainer after launch?
Not contractually, but software is never finished. Dependencies accumulate known vulnerabilities whether or not anyone is watching. App Care at $850 a month covers patching, backups and uptime monitoring. Secure Operate at $2,750 adds continuous vulnerability scanning and a quarterly pentest of whatever changed.
Start the conversation
Tell us what you are building and we will come back with scope, price and a delivery date. If you would rather start with the security of what you already have, the pentest intake returns a quote in one to three business days.
Request a quote Start pentest intake All cybersecurity services