Application Security Assessment

The Application Security Assessment is Strata's primary commercial engagement — a structured, engineer-led review that goes beyond what automated scanning alone can surface. It combines source code review with authentication, authorization, dependency, secrets, and configuration analysis, reported with clear risk prioritization and a remediation roadmap.

Typically $6,000–$15,000

Who This Is Built For

  • Growing SaaS and software companies preparing for an enterprise customer's security questionnaire or vendor review
  • Teams that want a second set of expert eyes beyond continuous automated scanning
  • Organizations establishing a security baseline before a major release or funding milestone
  • Engineering teams without a dedicated in-house security function

Typical Engagement Scope

Engagements are scoped collaboratively — this describes typical coverage, not a fixed checklist applied uniformly.

Typically Included

  • Source code review
  • OWASP-aligned findings
  • Authentication and authorization review
  • Dependency and secrets review
  • Configuration review

May Be Included, Depending on Scope

  • Application architecture observations
  • A formal executive presentation and developer walkthrough
  • A follow-up remediation validation review

Outside This Engagement

  • Mobile reverse engineering (part of the Product Security Assessment)
  • Infrastructure or network penetration testing
  • Ongoing or continuous monitoring — this is a point-in-time engagement, covered instead by the Security Retainer

Representative Deliverables

Executive reporting
Technical findings
Risk prioritization
Remediation roadmap

Deliverables reflect agreed scope — not every engagement includes every item. See the full deliverables breakdown on the Services hub.

What a Report for This Engagement Looks Like

Structure only — no findings are shown here. Every real report reflects the engagement's actual scope and results.

Sample Report Structure — Demonstration Only

Executive Reporting

Executive Summary

A plain-language overview of business risk and overall posture, for stakeholders who don't need technical detail.

Business Risk Overview

What the findings mean in terms of business impact, not just technical severity.

Executive Dashboard

A single-page visual summary of risk distribution and posture, built for a quick stakeholder read.

Executive Recommendations

Strategic, prioritized next steps aimed at leadership, not implementation detail.

Findings & Risk Analysis

Technical Findings

Each finding documented in full engineering detail — what it is, where it lives, and why it matters.

Risk Prioritization

Findings ranked by severity and real-world reachability, not a raw score alone.

CVSS Summary

Standardized severity scoring applied where a CVSS score genuinely applies to the finding.

OWASP Mapping

Findings mapped to OWASP categories where a mapping is applicable.

Affected Components

The specific files, endpoints, or modules a finding touches, so engineers know exactly where to look.

Attack Paths

How a finding could realistically be chained or exploited, explained in plain engineering terms.

Evidence & Documentation

Evidence Collection

Supporting artifacts — code excerpts, request/response captures, or configuration snippets — behind each finding.

Screenshots

Visual evidence captured during manual review, referenced directly from the relevant finding.

Remediation Guidance

Developer Guidance

Implementation-level detail aimed at the engineer who will actually make the fix.

Remediation Roadmap

Findings grouped and sequenced by priority and dependency, not an unordered list.

Estimated Fix Effort

A rough sense of engineering effort per finding, to help with sprint planning.

Assessment Process

  1. Discovery

    An initial conversation about the application, goals, and constraints.

  2. Scope Definition

    Engagement scope, tier, and boundaries are agreed in writing before work begins.

  3. Kickoff

    Access, authorization, and points of contact are confirmed with the client.

  4. Assessment

    Manual and tool-assisted review of the authorized application, repository, or artifact.

  5. Engineering Review

    Findings are validated and prioritized by the engineer who performed the assessment.

  6. Report Preparation

    Executive and technical findings are documented with evidence and remediation guidance.

  7. Executive Briefing

    Business risk and priorities are presented to stakeholders in plain language.

  8. Developer Walkthrough

    Technical findings are reviewed directly with the engineering team.

  9. Optional Validation

    A follow-up review to confirm remediation, scoped and scheduled separately.

For the full engineering practice behind every engagement, see the Methodology page.

Common Questions

No — it complements it. Automated scanning is fast, repeatable, and continuous; this engagement adds the architectural judgment and manual validation a human engineer contributes, which is a genuinely different kind of coverage.
Yes, typically read access to the relevant repository or repositories, scoped to what's agreed for the engagement. Access requirements are confirmed during scoping, before work begins.
No. Scope is tailored to the application and goals during project planning — the list above describes what this tier typically covers, not a fixed checklist applied uniformly.
Findings are grouped and sequenced by priority and dependency, so engineering teams have a concrete order of operations rather than an unordered list of issues.

Scope Your Assessment

Every engagement starts with a conversation, not a purchase.