01The work

Apps break in four places: the sign-in, the API, the data and who is allowed to reach it. Code written quickly, or written by AI tools, opens those gaps faster than most teams can review them. We test all four before someone else does.

We test with a normal user account, the way a real attacker usually starts, and work through the OWASP Top 10. Every finding is rated by CVSS severity, shown step by step so your team can reproduce it, and paired with the fix. Once you have fixed them, we test again.

Who it is for
  • Schools and universities with student and staff portals
  • Businesses taking payments or personal data online
  • Teams about to launch, or just after a big release
  • Anyone asked for a security review by a client or a partner
02What is included
Sign-in and sessions

Passwords, resets, tokens, sessions and every form a user can type into.

The API

Each endpoint asked who is calling and what they may see, including the ones the app never calls.

The data

What you store, how it is encrypted and who can read it.

Access

Admins, staff, teachers and students, each held to their own role, and nobody able to step into another's.

A findings report

Each finding rated by CVSS severity, with the steps to reproduce it and how to fix it.

One retest

When your fixes are in, we test those findings again and confirm what is closed.

03How it runs

A short call, a fixed quote, then the work

01A short call

We learn who it is for, what it must do and when you need it.

02A fixed quote

Scope, price and dates in writing, from the starting prices above.

03We do the work

In the open: you see it take shape, on your own devices.

04Launch and support

We ship it to the stores or the web, and stay on for fixes and changes.

$1,000Starts at
1 to 2 weeksTypical time
04Credentials
What we hold
  • Certified Offensive Security Explorer (COSE), 2025
  • M.Sc. in Information Security, 2026
  • Penetration test for Gazinformservice LLC, 2025
05Questions

Will testing break our site?

Testing can disturb a system, so we agree the times and limits with you first and stay inside them. For a site in daily use we can test a copy instead.

What do you need from us?

Written permission from the owner of the system, the scope and dates we agree, and a normal user account for each role we test.

What is in the report?

Every finding, rated by CVSS severity, with the steps to reproduce it and how to fix it, plus a short summary for whoever signs off the work.

Is a retest included?

Yes. Once your team has made the fixes, we test those findings again and tell you which are closed.

Who sees the findings?

Only you. Findings are confidential, and we report them to no one else.

How is the price set?

The price on this page is where the work starts. After a short call we send a written quote with the scope, price, dates and what you will receive. It holds for 30 days.

How do we pay?

In US dollars unless the quote says otherwise: a deposit before work starts and the balance on delivery. Invoices are due within 14 days.

06Contact

Tell us what you need tested or built

We reply within one business day, on WhatsApp or by email.

Contact formStart a project
We reply within one business day.
WhatsApp+263 77 176 2494
Chat
Call+263 73 259 1148
Call
Emailapps@invalcre.com
Email

4293 96 Close Kuwadzana 5 Harare, Zimbabwe

What happens next
  1. 01We reply within one business day, on WhatsApp or by email.
  2. 02A short call to scope what you need.
  3. 03A fixed quote, then we start.