The Agent-C Checkup
Your app works.Is it safe to ship?
A production-readiness score for the app you built without a security team — a plain-language grade across the 8 things that decide whether you're ready for real users, plus exactly what to fix first.
● 8-dimension maturity model · anchored to OWASP ASVS + PTES
Sound familiar?
You built the product. Nobody built the security review.
You shipped something real without a dedicated security or infrastructure person — because you were busy shipping. That's not a mistake. It just means the role a security team usually owns hasn't been filled yet.
A customer sent a security questionnaire
And you're staring at it, unsure which answers are true, which are aspirational, and which will lose the deal.
You have real users now
"It works on my machine" was fine at zero users. It is not a security posture at a thousand.
A $25K pentest is the wrong size
Boutique pentests are built for enterprises with a security team already in place. You need a straight answer first.
The Agent-C Checkup handles exactly that: the production-readiness work a security team would normally own — scored, prioritized, and explained in plain language.
The 8 checks
Eight dimensions decide if you're ready for real users.
Each one is graded 0–4 on the same red→green scale you saw up top. Security carries the most weight — it's where the damage is worst and the questions are hardest.
- 01
Source control & hygiene
Clean history, secrets kept out of the repo, and access that actually controls who can change what.
- 02
CI/CD
Code reaches production through a repeatable, reviewed pipeline — not a laptop and a prayer.
- 03
Infrastructure & environments
Prod and staging are separated, configured, and reproducible if you had to rebuild tomorrow.
- 04
Testing
Enough automated coverage that you can change code without quietly breaking something else.
- 05weighted heaviest · ×2
Security
Auth, input handling, dependencies, secrets, and the OWASP basics an attacker checks first.
- 06
Observability
When something breaks at 2am, you can see what broke and why — before a customer tells you.
- 07
Disaster recovery
If the database died right now, you could get it back — and you have actually tested that.
- 08
Documentation
A new developer — or you in six months — can understand, run, and safely change the system.
How it works
Three steps, no mystery.
A checkup is a fixed, hands-on engagement — not a subscription you have to babysit. Here's the whole thing.
- 01
Book a checkup
Pick a tier and tell us about your app — stack, where it runs, and what a customer is asking for.
- 02
We assess
We scan and review your codebase — and, at higher tiers, your pipeline and running system — against the rubric.
- 03
You get your score
A clear grade, a prioritized fix list, and — on Deep and Full — a signed Letter of Attestation you can share.
What you get
A score, a fix list, and proof — not a 100-page PDF.
Every checkup ends with something you can act on today and something you can show someone else. Higher tiers add the sharable proof.
- Every tier
Maturity scorecard
The 0–4 grade across all 8 dimensions — the same picture you saw up top, for your codebase.
- Every tier
Prioritized fix list
What to fix first, in plain language, ordered by risk reduced — not an alphabetized vulnerability dump.
- Every tier
Technical report
The detail behind each grade, written for whoever actually does the fixing.
- Deep & Full
Letter of Attestation
Shareable, signed proof of the work — the thing you hand a customer or auditor to unblock a deal.
- Full only
Retest
We re-check after you fix, and confirm the score moved — so the attestation reflects reality.
Who's behind it
A 30-year software veteran, not a scanner reseller.
Agent-C Security is run by a developer who has spent three decades building, shipping, and cleaning up production software — the same work you're doing, seen from the other side of a lot of incidents. The Checkup is the review a seasoned engineer would give your codebase, written so you can actually act on it.
No fear-mongering, no theater. Just a straight read on where your code stands and what to fix first — anchored to standards a security team would recognize.
- OWASP ASVSApplication security verification standard
- PTESPenetration testing execution standard
- 30 yearsShipping and maintaining real software
- Human-deliveredA veteran reviews it — not a scanner reselling output
Sample report
See a real checkup before you book one.
A redacted sample — the scorecard, the prioritized fix list, and the technical write-up — so you know exactly what lands in your inbox. Drop your email and we'll send it over.
FAQ
Questions people ask first.
Is this a penetration test?
Not exactly. A pentest looks for a way in; the Checkup grades whether your whole app is ready for real users — across 8 dimensions, security included. The Full tier does add live/dynamic testing, so it's the closest to a pentest, but with the wider production-readiness picture around it.
How much access do you need?
As little as you want. Spot Check is a static, read-only look at your repo. Deep adds your pipeline and staging config. Full adds testing against a running system — and only with your explicit sign-off on scope first.
Can I show the result to a customer or auditor?
Yes — that's what the Letter of Attestation is for. On Deep and Full you get a signed letter you can hand to a customer's security team or an auditor to unblock a deal, without handing over your raw report.
How long does it take?
A checkup is a fixed, scoped engagement — usually days, not weeks. Because scope drives the work, we agree on it (and the quote) with you before anything starts.
What happens to our code?
We work from the least access that gets the job done, and we scope data handling with you up front. (Exact retention and handling terms are confirmed as part of booking.)
We already have some of this covered. Still worth it?
Usually yes — the value is the honest, prioritized picture across all 8 dimensions. If a dimension is already solid, that shows in the score; the fix list just points you at the ones that aren't.
See where your app stands.
A production-readiness score, a prioritized fix list, and — at higher tiers — a signed attestation you can share. We confirm scope and a fixed quote before any work begins.