How It Works

What actually happens during an audit.

A Thunkle audit has four stages: we scope the work and give you a fixed quote, we review the code and test the live app by hand, we hand you a prioritised report with a fix for every finding, and once you have applied the fixes we re-review them at no extra cost.

Get a quote

No hourly meter, no black box.

Security work has a reputation for open-ended engagements and reports you cannot act on. Ours is deliberately the opposite: a fixed price agreed before we start, a hands-on review rather than a scanner dump, a report written so you or your builder can act on every line, and a re-review included so you know the fixes held. Here is exactly how each stage works.

1. Scope and fixed quote

You tell us what the app does, what built it, and what worries you. From that we scope the audit and give you a fixed quote up front, based on the size of the app, with no hourly billing. You know the full price before you commit to anything, and the re-review is already included in it.

2. Hands-on review and testing

We read the code and test the live app by hand. Automated scanners assist, but a senior engineer decides what matters, because the findings that count, broken access rules, flawed logic, need someone who understands what your app is supposed to do. We probe the running app the way an attacker would, from the outside, and trace the flows that carry weight: auth, payments, data writes.

For anything that changes data, we use marked test accounts and tell you before we touch it. The audit reads and probes; it does not stress or damage your live system.

3. The prioritised report

You get a clear write-up within about a week: every finding rated by severity, with a concrete fix for each, ordered so you know what to close first and what can wait. It is written to be acted on, whether you apply the fixes yourself, hand them to your builder, or ask us to. We walk through it with you on a call so nothing is ambiguous.

4. The free re-review

Once you have applied the fixes, we re-test the same paths to confirm they actually closed the holes. This is included in the original price, because a finding is not resolved until the fix is verified. You end the process knowing your app is genuinely in a better place, not just that you were handed a list.

Common questions.

How long does the whole process take?
Most audits deliver the report within about a week of getting access. The re-review happens whenever you have finished applying the fixes, which is up to you. Larger apps take longer and we tell you in the quote.
What do you need from me to start?
Read access to the repository and a short walkthrough of what the app does. For part of the audit we only need the public URL, because that is all an attacker has.
Can you fix the findings, not just report them?
Yes. You can apply the fixes yourself, hand them to your builder, or have us do them. The report is written to support all three.

Related services.

Let's build something real.

Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.

Get a quote