Skip to main content
MAG&Cie
Application audits

What your application is really worth, on cold review

Security · Debt · Quality · Dependencies

Independent audit of an existing application. We read the code, watch it run, talk to your team. Deliverables: detailed report with screenshots, prioritized remediation plan, executive presentation.

TL;DR
  • What it is

    Independent audit of a production application: technical debt, code security (OWASP), performance, hosting costs, prioritised refactor roadmap.

  • For whom

    SaaS editors, SMEs and startups with an app that lags, costs too much or worries them — before a rebuild, fundraise or takeover.

  • Indicative price

    EUR 4,500 to 15,000 excl. VAT depending on scope (5 to 10 business days). 20-40 page report delivered.

OWASP Top 10Secrets handlingDependencies / CVEPrioritized plan
Typical audit cases

Every audit is a case of its own. Here are the moments we get called in.

  • 1

    Audit before go-live. You are a few weeks from launch and want an outside eye on quality, security and robustness before opening the doors.

  • 2

    Pre-acquisition audit. You are acquiring a company or a product and want to qualify tech debt, code quality and hidden risks before signing.

  • 3

    Audit after an incident. An intrusion, a major regression or a data leak occurred. We investigate the root cause, map the residual exposure and propose the remediation plan.

  • 4

    Preventive annual audit. You want to keep tech debt and security exposure under control without waiting for the next incident. Yearly cadence, stable scope, year-over-year comparison.

Typical control points

Grid applied systematically, adapted to the scope defined at kickoff.

OWASP Top 10

Systematic walkthrough of the 10 most critical application risk categories: broken access control, injection, misconfiguration, vulnerable components, etc.

Secrets handling

Search for cleartext secrets in code, version history, logs, config files. Verification of rotations and secure storage.

Authentication and authorization

Sign-in robustness, resistance to credential stuffing, role consistency, privilege separation, session, password reset.

Session handling

Duration, invalidation, hijack protection, reconnection, multi-device consistency, server-side expiration.

Injection and cross-site

Resistance to database injections, script injections into pages, cross-site request forgeries, system command injections.

Third-party dependencies

Complete inventory of libraries, cross-reference with published vulnerability bulletins, version age, licenses, dependency chain.

Incident logging

What is traced, what is not, the ability to reconstruct an incident a posteriori, log retention, real-time alerting.

Error robustness

Behavior under invalid inputs, dependency outages, load spikes, missing data. Information leaks via error messages.

Method

5 to 15 audit days depending on scope. Written report + oral debrief.

01

Static code review

Source code reading, identification of sensitive points, cross-referencing with OWASP and domain best practices.

02

Dynamic analysis

Live application observation, application penetration tests, unexpected input injection, runtime log review.

03

Architecture review

Overview: modularization, data flows, coupling points, external dependencies, application fallback plan.

04

Dependency audit

Library inventory and cross-check with published vulnerability advisories. Update recommendations prioritized by severity.

Frequent questions

How much does an application audit cost?+

Fixed-fee quote. Range 5 to 15 person-days depending on scope, from €5,500 excl. VAT for a focused audit (5 days), up to €18,000 excl. VAT for a full audit including penetration tests and architecture review.

Do you fix the vulnerabilities found?+

Not by default — the audit is a diagnostic deliverable. If you want remediation next, we scope a separate mission (fixed-fee or T&M), with 20% of the audit price deducted from the first remediation work.

Do you sign an NDA before the audit?+

Always, before any code or system access. MAG&Cie NDA available if you don't have one. Multi-party supported (co-shareholders, investors, lawyers).

Can you audit remotely?+

Yes, most of the mission is done remotely with read-only access to code and systems. An on-site visit for the debrief and team interviews is offered if you want it.

Do you offer a follow-up phase after the audit?+

Yes, 30 days of written support are included after the report is delivered to answer questions that emerge during execution. A longer follow-up (remediation support) can be contracted separately.

/ En résumé

An application to audit?

Free 1-hour scoping. Report in 5 to 15 business days.