dgxcode

Services

Fixed-scope engagements with a written quote before any testing starts. Starting prices in USD, based on one application, a staging environment, and up to two user roles. Final price is set after scoping — no hourly surprises.

Web & API penetration test

Manual gray-box testing of a web application and its REST or GraphQL API: authentication and session handling, authorization and IDOR, injection, SSRF, race conditions, file upload, and business-logic abuse across every role you expose.

What you get

  • Attack-path findings, not a scanner dump
  • CVSS v3.1 score and a reproduction step per finding
  • Redacted proof of concept safe to attach to a ticket
  • Retest of every fixed finding within 30 days

To scope it, send

  • Base URL(s) and API base URL
  • Number of user roles and endpoints, plus test accounts
  • Staging or production, and the allowed testing window

from USD 2,500

per application · typical 5–10 working days

Request a quote

Mobile app security testing

Static and dynamic assessment of an Android or iOS client: local storage and keychain handling, exported components and deep links, transport security and certificate-pinning strength, obfuscation, and the API surface the binary reveals.

What you get

  • Endpoint and secret exposure map extracted from the binary
  • Local storage, keychain, and IPC findings with device/OS versions
  • Transport-layer and pinning-bypass assessment
  • Fix guidance per finding, plus retest within 30 days

To scope it, send

  • APK/AAB or IPA build (TestFlight or store link)
  • Target OS versions and whether the backend API is in scope
  • Any jailbreak/root or emulator restrictions for your policy

from USD 4,000

per platform (Android or iOS) · backend API quoted separately

Request a quote

Secure code review

Targeted review of the code paths that decide whether your app is safe: authentication, authorization checks, cryptographic use, secret handling, deserialization and injection sinks, and third-party dependency risk.

What you get

  • Findings anchored to file and line, with the vulnerable path explained
  • Suggested patch or safe API replacement per finding
  • Dependency and secret-hygiene issues flagged separately
  • A prioritized fix list your team can work through in one sprint

To scope it, send

  • Repository access (read-only) or an archive of the modules in review
  • Language, framework, and approximate lines of code in scope
  • What the code protects: user data, payments, admin actions

from USD 1,800

per engagement up to 20k lines in scope · larger codebases quoted per module

Request a quote

Offensive assessment / red team

Objective-based adversary simulation against your people, process, and infrastructure: initial access from an external position, lateral movement, and a defined crown-jewel objective, with detection and response measured as it happens.

What you get

  • A written objective and rules of engagement agreed before start
  • Attack narrative with every step, tool, and detection gap
  • Purple-team debrief so your defenders see the same timeline
  • Prioritized detection and hardening recommendations

To scope it, send

  • The objective (data, system, or action) and what counts as success
  • Who is aware of the test, and the escalation contact
  • Cloud, network, or physical boundaries in and out of scope

from USD 9,000

per engagement · typical 2–3 weeks

Request a quote

AI / LLM security review

Adversarial review of an LLM-powered feature or agent: direct and indirect prompt injection, tool- and function-calling abuse, SSRF and command paths reachable through the model, system-prompt and training-data leakage, and guardrail bypass.

What you get

  • Injection findings with the exact prompt chain that triggered them
  • Tool-permission and data-exposure map for every function the model can call
  • Coverage against the OWASP LLM Top 10 (2025)
  • Guardrail and monitoring recommendations, plus retest

To scope it, send

  • How users reach the model (chat, agent, API) and what tools it can call
  • Model provider and whether prompts/system instructions are shareable
  • A test tenant or API key scoped to non-production data

from USD 5,000

per application or agent · multi-agent platforms quoted per agent

Request a quote

Retainer / advisory & disclosure handling

Ongoing hours for the work that does not fit a one-off test: security review of pull requests before merge, architecture advice, incident support, and handling inbound vulnerability reports end to end — triage, vendor coordination, and advisory text.

What you get

  • A reserved monthly block of hours with a named response path
  • Async review of PRs, designs, and third-party questionnaires
  • Triage and coordination of reports you receive from researchers
  • A running log of decisions so nothing gets re-litigated

To scope it, send

  • Rough monthly hours you expect to use, and your busiest period
  • Stack and cloud providers your team runs
  • Whether you need report handling for an existing disclosure inbox

from USD 2,000

per month, up to 10 hours · unused hours do not roll over

Request a quote

How an engagement runs

  1. Scoping — assets, roles, endpoints, environment, timeline.
  2. Written authorization — rules of engagement, test accounts, maintenance window.
  3. Manual testing — hypothesis-driven, business logic first.
  4. Report — findings, CVSS, redacted PoC, remediation.
  5. Retest — fixes re-verified within 30 days of the report, no extra fee.

What every quote includes

Request a quote

Send the scoping items above to security@dgxcode.com. You get a fixed price and a timeline back, usually within three business days. If the work is not a fit, I will say so and point you somewhere better.

Telegram — direct @dgxcode Open Telegram
Telegram — announcements (one-way) t.me/dgxcodex Open Telegram

Broadcast channel for disclosures and write-up announcements. It is not monitored for reports — use email for anything time-sensitive.