Pricing

Clear prices for bounded security reviews.

Choose the situation that matches your decision. Every engagement starts with a short, non-secret fit check so the authorised boundary and the accepting party’s requirement are clear before any work or evidence intake.

Public service lines

Customer Security Review Sprint

A customer, buyer or procurement team has sent a security questionnaire or evidence request that is delaying a deal or consuming senior technical time.

From €1,600 after a non-secret fit check

Approximately three working days after scope, owners, required inputs and evidence access are confirmed

The customer owns the final answers and submission. WitnessOps does not guarantee customer acceptance, certification or compliance.

Bounded Workflow Review

One technical action, finding, change or handoff must be explained after the work changes hands.

From €1,500

Confirmed during the non-secret fit check

The exact workflow and verification mechanism are named in the engagement. A report alone is not described as independently verified.

One Server Security Check

You need a clear, read-only security picture of one authorised Linux host before a customer ask, hardening step, or internal review.

€950 standard after a non-secret fit check

Within two business days after the authorised collection window

No exploitation, secret collection, compliance certification, or host-security guarantee. One named host, read-only, authorised collection only.

Primary fixed-scope offer

External Exposure Assessment

A manually reviewed outside-in security review of one authorised public-facing system.

€1,500 paid pilot — one public-facing domain/application

Within 3 working days after payment, accepted scope, authority, required inputs, and the collection window are confirmed

No sales call required. One focused retest within 30 days is included; an additional or late retest is €550 ex VAT.

No exploitation, credentials, destructive testing, certification, or security guarantee. Unauthenticated outside-in checks only, within the agreed fixed scope.

Launch Readiness Check

You need a before-and-after readiness picture for one launch host against an approved baseline, including drift and open decisions.

€2,500–€7,500

Four business days after candidate collection

No launch approval, security guarantee, remediation, or arbitrary cloud review. Bounded readiness package only.

Key, Access and Custody Review

You need a proof-backed review of how custody or wallet-operations controls are documented, using sanitised observations only.

€3,000–€15,000

Confirmed during the non-secret fit check

No keys, seed phrases, balances, fund movement, taking custody, or solvency claim. Documentation and agreed non-secret observations only.

Incident Readiness Review

You need a bounded readiness record for one named incident class and environment — preparation, unknowns and open decisions on the package.

€5,000–€25,000

Confirmed during the non-secret fit check

No hack-back, exploitation, destructive testing, live incident command, secret intake before handling is agreed, compromise claim, root-cause or attribution.

Commercial boundary

No review starts from this page or from payment alone.

An External Exposure Assessment can be started without a sales call; authority, scope, fee treatment, timing, capacity, and evidence handling are still accepted before work begins.

Published figures are fixed prices or starting ranges for the named boundary, excluding VAT where stated.

A report, receipt, or verifier does not prove that a system is secure, complete, compliant, or free of vulnerabilities.