What it is
Independent audit of a production application: technical debt, code security (OWASP), performance, hosting costs, prioritised refactor roadmap.
For whom
SaaS editors, SMEs and startups with an app that lags, costs too much or worries them — before a rebuild, fundraise or takeover.
Indicative price
EUR 4,500 to 15,000 excl. VAT depending on scope (5 to 10 business days). 20-40 page report delivered.
Every audit is a case of its own. Here are the moments we get called in.
- 1
Audit before go-live. You are a few weeks from launch and want an outside eye on quality, security and robustness before opening the doors.
- 2
Pre-acquisition audit. You are acquiring a company or a product and want to qualify tech debt, code quality and hidden risks before signing.
- 3
Audit after an incident. An intrusion, a major regression or a data leak occurred. We investigate the root cause, map the residual exposure and propose the remediation plan.
- 4
Preventive annual audit. You want to keep tech debt and security exposure under control without waiting for the next incident. Yearly cadence, stable scope, year-over-year comparison.
Typical control points
Grid applied systematically, adapted to the scope defined at kickoff.
OWASP Top 10
Systematic walkthrough of the 10 most critical application risk categories: broken access control, injection, misconfiguration, vulnerable components, etc.
Secrets handling
Search for cleartext secrets in code, version history, logs, config files. Verification of rotations and secure storage.
Authentication and authorization
Sign-in robustness, resistance to credential stuffing, role consistency, privilege separation, session, password reset.
Session handling
Duration, invalidation, hijack protection, reconnection, multi-device consistency, server-side expiration.
Injection and cross-site
Resistance to database injections, script injections into pages, cross-site request forgeries, system command injections.
Third-party dependencies
Complete inventory of libraries, cross-reference with published vulnerability bulletins, version age, licenses, dependency chain.
Incident logging
What is traced, what is not, the ability to reconstruct an incident a posteriori, log retention, real-time alerting.
Error robustness
Behavior under invalid inputs, dependency outages, load spikes, missing data. Information leaks via error messages.
5 to 15 audit days depending on scope. Written report + oral debrief.
Static code review
Source code reading, identification of sensitive points, cross-referencing with OWASP and domain best practices.
Dynamic analysis
Live application observation, application penetration tests, unexpected input injection, runtime log review.
Architecture review
Overview: modularization, data flows, coupling points, external dependencies, application fallback plan.
Dependency audit
Library inventory and cross-check with published vulnerability advisories. Update recommendations prioritized by severity.
Frequent questions
How much does an application audit cost?+
Fixed-fee quote. Range 5 to 15 person-days depending on scope, from €5,500 excl. VAT for a focused audit (5 days), up to €18,000 excl. VAT for a full audit including penetration tests and architecture review.
Do you fix the vulnerabilities found?+
Not by default — the audit is a diagnostic deliverable. If you want remediation next, we scope a separate mission (fixed-fee or T&M), with 20% of the audit price deducted from the first remediation work.
Do you sign an NDA before the audit?+
Always, before any code or system access. MAG&Cie NDA available if you don't have one. Multi-party supported (co-shareholders, investors, lawyers).
Can you audit remotely?+
Yes, most of the mission is done remotely with read-only access to code and systems. An on-site visit for the debrief and team interviews is offered if you want it.
Do you offer a follow-up phase after the audit?+
Yes, 30 days of written support are included after the report is delivered to answer questions that emerge during execution. A longer follow-up (remediation support) can be contracted separately.
/ En résumé
An application to audit?
Free 1-hour scoping. Report in 5 to 15 business days.
Continue with
Pages that pair well with this one
Adjacent topics covered by MAG&Cie, hand-curated to stay on your problem.