VULNERABILITY AND SECURITY AUDIT
I look at your system the way an attacker would.
The first step into a system is usually a known hole nobody patched. In one to two weeks you get it in writing — where the code, the dependencies and the configuration are vulnerable, and how much work each fix is. If you want, I'll try the live system from outside too. The price is fixed, and it doesn't change along the way.
- Where can it be broken today?
- What only shows while it runs?
Mihály Tari · 20 years shipping software, web and mobile.
Request an audit ↓Not a theoretical risk
-
31%
Verizon's 2026 report analysed 22,000 confirmed breaches, and in 31% of them the first step was exploiting a known vulnerability. A year earlier that was 20%, so this is the first time it has overtaken stolen credentials.
Verizon, Data Breach Investigations Report 2026 -
78%
Black Duck audited 947 commercial codebases in 2025. More than three-quarters had at least one high-risk vulnerability in the open-source parts pulled in from outside, and 44% had a critical one. The average codebase held 581 known vulnerabilities.
Black Duck, Open Source Security and Risk Analysis 2026 -
$4.99M
That's the global average cost of a data breach in IBM's 2026 study, a record and 12% more than a year earlier. A small company won't pay that much, but even one incident is enough there.
IBM, Cost of a Data Breach Report 2026
Three places I look
-
01
In the code
Static review: without running it, I read the code, its configuration and git history — every saved version.
- Known vulnerabilities in dependencies, and whether your system actually runs the affected code
- Secrets in the code and in every saved version behind it: API keys, passwords, tokens
- Login, keeping people logged in, permissions: who can see what, and who can do what
- Injection, where typed text becomes an instruction: SQL, shell, template, prompt
- Configuration: HTTP headers, cookie flags, which sites may call your API — that is CORS —, file uploads, rate limits, database access rules
-
02
In the running system
Dynamic testing as an add-on: I probe the running system from outside, with written authorisation.
- Automated scan of staging — your rehearsal copy — or production, logged in as well
- Trying the findings from the code for real: exploitable, or only on paper
- The things that only appear while the system runs: error messages that give too much away, endpoints nobody closed, an admin page
- The two sides held against each other: what the code led me to expect, and what is actually running
-
03
In the documents
I read the policies your company has written, and then check whether the code keeps to them.
- Your privacy notice, security policy and access rules: what the company promises in writing
- The same promises in the code: whether data really is kept only that long, and whether only the people named on paper can read it
- The pieces that are missing: an incident plan, a rule for passwords, and a rule for who gets access and when they lose it
What I typically find
This list comes out of my earlier audits and the sample report, and the severity column says how urgent a fix is rather than how common.
| Finding | Severity | What it means for you |
|---|---|---|
| A known vulnerability in a dependency, and your system runs the affected code | critical | A ready-made exploit is online, so it doesn't take a skilled attacker. |
| An API key or password in the git history | critical | Deleted from the file, still in an old commit, so anyone who clones it has it. |
| Changing an ID in the address brings back another customer's record | critical | Login exists, the authorisation check is skipped; this one is called IDOR. |
| Injection at an input | high | Text from outside lands in a query, a command, a template or a prompt, and runs. |
| Missing security headers, loose CORS, cookies without their security flags | high | These are browser-level settings, rarely a problem on their own, but with another finding they become one. |
| An error message that gives too much away, or an admin panel nobody closed | medium | Only visible at runtime, so the dynamic test is what finds it. |
| No rate limit on login or password reset | medium | Tries are unlimited, so it can be guessed; one weak password is enough. |
What you get
-
01
A one-page summary
I write this one for whoever doesn't read code. It says how many vulnerabilities there are and how serious they are, which three are worth closing this week, and how much work the whole list is.
-
02
The full report
This one is for the developers. Every finding carries the file and the line, or the URL and the request that triggers it, so nobody has to go looking, then a concrete scenario of how it would bite, the fix, and roughly how many hours the fix takes. At the end I set out the order I'd tackle them in.
-
03
Optional: half a day with your team
I walk your team through the report on your own code, finding by finding. The half day is there so that next time they spot this kind of thing without me.
SAMPLE REPORT
So you can see what you get, I audited my own repo — where my code lives — and published the report exactly as it came out. It's the AI code audit sample; the security report comes in the same format.
Why not just run a scanner?
Snyk, Dependabot, ZAP: run them, they're free and they're good. Here is the difference.
| Aspect | Automated scanner | This audit |
|---|---|---|
| What it sees | Known patterns and known package versions. | Your code, your configuration and your git history, and whether you call the vulnerable code at all. |
| What it finds | Many hits, many of them false. | What is actually exploitable in your system, and in the add-on I try it for real. |
| Order | A CVSS score — generic severity — that doesn't know what you run. | Severity as it lands in your system, an estimate in hours, and an order to work through. |
| Who is accountable | Nobody. | Me, by name and on an invoice. |
| Price | Free, or a subscription. | €970, fixed. Dynamic testing €560. |
Price
€970
1–2 weeks, fixed price
- Dynamic testing of the live system
- €560
- Half a day with your team
- €280
One day at my usual €70/hour: automated scan of staging or production, then manual verification, on your written authorisation saying what I may try and when.
Four hours at the same rate, and only if you want it.
When this is not the price
- More than one repo, or more than one live system.
- Above roughly 150,000 lines.
- A web app and a mobile app together.
- Dynamic testing that runs over several days, when the standard add-on is a single day.
If any of these is true, you get a different fixed price in writing before we start, and it still doesn't change mid-audit.
What it is not
This isn't a full penetration test — days of hands-on break-in attempts — nor a certification, nor a NIS2, ISO or SOC 2 audit. If you need one of those, I'll say so and point you to the right people.
How it goes
-
01
You give access
Read access to the repo and to your policies is all I need to start. If you want the dynamic testing, I also need written authorisation saying what I may try and when. I'll sign an NDA — a confidentiality agreement — if you want one.
-
02
I examine
That takes one to two weeks. I start with tools — a dependency scan, a secret scan, static analysis, and the dynamic scan if you asked for it — because they are good at flagging places worth a look. Then I go through every hit by hand and decide whether it is real, because only what I can prove goes into the report. At the end of the third business day I send a short status note with the first findings, so you can see what is coming; if that shows you it is not what you expected and you stop the work in writing, the deposit comes back.
-
03
You get
You get the one-page summary and the full report, and if you asked for the half day, we find a date for it.
What comes after the audit
The audit is a report, and it can end there. If you want, I take the fixes further myself.
-
01 · Audit
€970, 1–2 weeks, plus a day of dynamic testing if you ask for it. That is what this page describes.
-
02 · Fixes
The fixes go in the order the report sets out, at a fixed price, and it runs as a Project.
-
03 · Support
From €1,100 a month with no notice period, if you want the dependencies updated every month and someone looking over every major change.
Who this is for
- A customer has sent you a security questionnaire, and you don't know what to put in it.
- An investor or an enterprise partner has asked for someone outside to look at the system.
- Something happened at a company near you, and now you want to know where your own system stands.
- You're preparing for NIS2, the EU's security rules, and you want to see where you're starting from.
Not for you if
- AI wrote most of the code, and what worries you is not only security but whether the code can still be maintained. AI code audit →
- you need a certification, ISO 27001 or SOC 2. That takes a registered auditor rather than this, and my reply tells you who to ask.
- someone has asked you for a multi-day penetration test with a written scope, because that is a different job at a different price.
Questions
- Is this a penetration test?
- Not quite. A pentest — a penetration test — tries to break into the running system from outside, by hand, and usually takes several days. I start from the inside, from the code, an approach called white-box testing, because I can see the source while I work; the dynamic add-on then spends one day checking my findings from outside. If a full pentest is what you need, I'll tell you.
- Which tools do you use?
- My own scripts and the usual open-source tools for dependencies and secrets, Semgrep for static analysis, OWASP ZAP and hand-built requests for the dynamic part. The tools only produce candidates; I write the report, and only what I have looked at myself goes in.
- Does my code go into an AI?
- Yes, through Claude Code into Anthropic's API. Model training is switched off on my account: it isn't used for training, and it's deleted after 30 days. If that isn't acceptable, the audit is done without AI, for €420 more and in 2–3 weeks. The details are on a separate page. How I work with AI →
- How large a system do you take?
- One repository and one live system. The audit is time-boxed, so I look hardest at the biggest risks, and the report says what I didn't get to.
- Which stacks do you work with?
- TypeScript and JavaScript are where I go deepest: React, Next.js, Node and Astro, with Postgres, Supabase or Firebase underneath. Python and mobile work too, meaning React Native and Expo. If you run something else, write and tell me, and my reply says whether I'll take it on.
- My code wasn't written by AI. Is this still for me?
- Yes, because a security audit doesn't depend on who wrote the code. If most of it was written by AI and nobody has read it end to end, the other audit gives you more, because it looks at maintainability too. AI code audit →
- Isn't dynamic testing risky on production?
- An automated scan can have side effects, because it fills in forms and sends requests: test records appear, emails go out, and the system carries extra load. That is why I ask for staging first, and on production I only try what I wrote down in advance and you approved. I never trigger a delete, a payment or a flood of requests.
- Who owns the report?
- It's yours. You can keep it internal, or hand it to an investor or to a customer, whichever you need. I talk about it publicly only if you agreed to that in advance.
- Do you fix things, or only report?
- The audit is a report, and your team can do the fixes from it; that's the idea. If you'd rather I did them, I quote that separately at a fixed price. What comes after the audit ↑
- Do you sign an NDA?
- Yes, if you want one, and your own draft is fine too.
- I need this for NIS2. Does it count?
- A NIS2 cybersecurity audit can only be carried out by a registered auditor, and I am not one, so this does not count as that audit. What it does is prepare you for it: the same gaps come up here that the auditor would find there, only earlier and for less money.
- How do I pay?
- In two steps. I ask for 30% of the price as a deposit once I have access: €291 on the €970 price. The remaining 70% is invoiced when the report is delivered. At the status note at the end of the third business day you can stop the work in writing; then I refund the deposit in full and there's nothing more to pay. After that the deposit stays, and silence isn't a stop. I'm a VAT-exempt sole trader in Hungary, which means no VAT goes on top, so the price you see here is what you pay.
Request an audit
Send a link to the repo or the product, and a few sentences on what has brought the question up now. I reply within two business days, telling you whether I'll take it and when I can start.
or email me directly: contact@mihalytari.com
or call me: +36 30 179 8852
Before sending, please read the privacy notice .