Access first
Authentication, authorisation, session handling and tenancy boundaries — and whether access is modelled in the data and enforced on the server, or merely hidden in the interface. Hiding a button is not access control.
Secrets
Keys and passwords belong in a managed store, not in code or config files, with rotation that someone actually performs.
What the app pulls in
A dependency and supply-chain audit: what you ship, what it pulls in, and what is unmaintained. More in what a supply-chain audit covers.
How it runs
Hardened deployments — least-privilege service accounts, private networking, verified TLS — and backups that have actually been restored, with a written plan for the day something is breached. More in why an untested backup does not count.
What you get
A written dossier with ranked findings, yours to keep whether or not you hire us. Reviews of systems we did not build usually start with the free audit, because the risk often sits somewhere other than where it was expected.