Security audit (OWASP Top 10)

Already have a site or an app? We review it against the OWASP Top 10 and you get a clear report with the fixes to make, ranked by priority.

AuditOWASP Top 10Hardening

What the audit covers

The OWASP Top 10 is the reference list of the most common web vulnerabilities: injection, access control, authentication, configuration, outdated components, data exposure, and so on. Each one is gone through on your site, your app or your API.

What you get

A clear report, with each issue explained in plain language, its risk level, and the fixes to apply, ranked by priority. The fixes can then be carried out by your team or by NorthWick.

An exemplary site, starting with our own

Every NorthWick project is checked against the OWASP Top 10 before launch: HTTPS, security headers (Content-Security-Policy, HSTS, Permissions-Policy…), form protection and up-to-date dependencies. With the monthly plan, those checks continue over time.

Frequently asked questions

Another question? Write to us at hello@northwick.xyz.

What does the security audit cover?

We check your site or app against the OWASP Top 10: injection, access control, authentication, configuration, outdated components, and so on. You get a clear report, with each issue explained in plain language and the fixes to apply, ranked by priority.

Could the audit disrupt my site?

The audit is run in a controlled way, with the scope and timing agreed with you beforehand. No destructive action is taken.

Do you fix the vulnerabilities you find?

The report is written so your team can fix things themselves. If you'd rather, NorthWick can carry out the fixes on a quote.

Ready for a site that measures up?

A 30-minute conversation to see whether we're a good fit. Reply within 24 hours.

Book a free callhello@northwick.xyz