/services

We design, build, and secure software.

Web and mobile products, from first design to launch and long-term support. Security testing by people who do it for a living. Scoped per engagement.

designbuildtestlaunchsupport
recommendedbundle · $ spidyops --hire full-package

Full lifecycle

Design, build, test, launch, and support under one contract.

What you get
  • Discovery and design
  • Web and mobile development
  • A penetration test before you launch
  • Launch support
  • A support and maintenance retainer after launch
  • One accountable point of contact from first design through launch and support
Engagement model

Discovery call, then a tailored proposal, then phased delivery with shared milestones. Priced below the sum of the parts.

Who this is for

Founders who want one company accountable from first design through launch and beyond, instead of stitching together separate vendors.

Book a scoping call →

Design and branding

Product design and visual identity for web and mobile.

Discovery, then moodboard, exploration, refinement, and handoff with full brand guidelines.
Scope
Written SOW · in/out/exclusions
Cadence
Discovery, then moodboard, exploration, refinement, and handoff with full brand guidelines.
Deliverable
Brand guidelines + design files (Figma) handoff
Who this is for

Pre-launch startups, rebrands, and companies that need a complete identity.

~/spidyops · design
$ spidyops --hire design
Brand strategy, naming, and messaging
Logo, wordmark, colour system, typography
UI and UX design for web and mobile
Marketing site design and production
Pitch decks, one-pagers, and brand guidelines
ships: Brand guidelines + design files (Figma) handoff
Get in touch →

Web development

Web applications built to production standards.

Written statement of work, fixed milestones, weekly check-ins.
Scope
Written SOW · in/out/exclusions
Cadence
Written statement of work, fixed milestones, weekly check-ins.
Deliverable
Deployed app + source code + documentation
Who this is for

Founders building a new product and teams replacing a legacy system or internal tool.

~/spidyops · fullstack
$ spidyops --hire fullstack
Web apps in Next.js, React, and TypeScript
API design and backend (Node, PostgreSQL, serverless)
DevOps and deployment (Vercel, AWS, or your infrastructure)
Threat modelling and security review during the build
Accessibility and performance held to WCAG 2.2 AA and Core Web Vitals
ships: Deployed app + source code + documentation
Get in touch →

Mobile development

iOS and Android apps, cross-platform or native.

Written statement of work, fixed milestones, store-submission support.
Scope
Written SOW · in/out/exclusions
Cadence
Written statement of work, fixed milestones, store-submission support.
Deliverable
Store-submitted build + source code
Who this is for

Companies launching a mobile product or extending a web product to phones. We ship our own iOS app, Fitra — the same discipline applies to yours.

~/spidyops · mobile-dev
$ spidyops --hire mobile-dev
Cross-platform apps in React Native
Native iOS or Android where the product needs it
Offline-first architecture and on-device data
App Store and Play Store submission and review support
Security review of the mobile attack surface as part of delivery
ships: Store-submitted build + source code
Get in touch →

Penetration testing — black box

External testing with no prior knowledge of your internals.

One to three week scoped window, fixed price, sample report on request.
Scope
Written SOW · in/out/exclusions
Cadence
One to three week scoped window, fixed price, sample report on request.
Deliverable
CVSS-rated report + remediation call + one retest
Who this is for

Companies validating their external-attacker posture, meeting a compliance requirement, or checking security before launch.

~/spidyops · pentest-blackbox
$ spidyops --hire pentest-blackbox
Adversarial testing against your public surface
Manual exploitation, not just scanner output
Methodology aligned to OWASP WSTG
Findings rated by CVSS 3.1 with reproduction steps
A report your engineers can act on, plus a remediation call
One retest after you ship fixes
ships: CVSS-rated report + remediation call + one retest
Get in touch →

Penetration testing — white box

Full-knowledge review with source code and architecture access.

Two to six week scoped window depending on codebase size.
Scope
Written SOW · in/out/exclusions
Cadence
Two to six week scoped window depending on codebase size.
Deliverable
Code-level findings report + remediation guidance
Who this is for

Teams shipping security-sensitive products that want depth over breadth, or preparing for a funding or compliance audit.

~/spidyops · pentest-whitebox
$ spidyops --hire pentest-whitebox
Source-code review for security defects
Architecture review against a threat model
Authentication, authorisation, and session audit
Cryptographic implementation review
Dependency and supply-chain analysis
Remediation guidance at the code level, with optional pairing on fixes
ships: Code-level findings report + remediation guidance
Get in touch →

Penetration testing — mobile

Security testing for iOS and Android applications.

One to three week scoped window, fixed price, sample report on request.
Scope
Written SOW · in/out/exclusions
Cadence
One to three week scoped window, fixed price, sample report on request.
Deliverable
MASVS-aligned report + remediation call
Who this is for

Companies shipping a mobile app that handles accounts, payments, or sensitive data.

~/spidyops · pentest-mobile
$ spidyops --hire pentest-mobile
Testing aligned to the OWASP MASVS and MASTG
Static and dynamic analysis of the app binary
Local data storage, keychain, and secrets review
API and backend testing behind the app
Transport security and certificate-pinning checks
CVSS-rated findings with reproduction steps and one retest
ships: MASVS-aligned report + remediation call
Get in touch →

Penetration testing — network

External and internal network and infrastructure testing.

One to three week scoped window, fixed price.
Scope
Written SOW · in/out/exclusions
Cadence
One to three week scoped window, fixed price.
Deliverable
Network findings report + remediation call
Who this is for

Companies with cloud or on-premise infrastructure that want their network posture tested.

~/spidyops · pentest-network
$ spidyops --hire pentest-network
External perimeter and internal network testing
Methodology aligned to PTES and MITRE ATT&CK
Service enumeration, misconfiguration, and patch-gap analysis
Cloud infrastructure review (AWS, GCP, Azure)
Lateral-movement and privilege-escalation paths where in scope
CVSS-rated findings with reproduction steps and one retest
ships: Network findings report + remediation call
Get in touch →

Red team engagement

Objective-based testing that models a real attacker.

Scoped to an objective and a timebox, defined together up front. We are honest about what a focused team delivers versus a large red-team firm.
Scope
Written SOW · in/out/exclusions
Cadence
Scoped to an objective and a timebox, defined together up front. We are honest about what a focused team delivers versus a large red-team firm.
Deliverable
Attack narrative + findings + debrief
Who this is for

Organisations with a mature security programme that want to test detection and response, not just find bugs.

~/spidyops · redteam
$ spidyops --hire redteam
Objective-based and assumed-breach engagements
Written rules of engagement agreed before any testing
Multi-surface approach (web, network, and — where authorised — people and physical)
ATT&CK-mapped narrative of the path taken
A debrief with your security and engineering teams
ships: Attack narrative + findings + debrief
Get in touch →

Vulnerability assessment

Recurring scanning plus manual validation of the findings.

Monthly recurring or a one-time assessment.
Scope
Written SOW · in/out/exclusions
Cadence
Monthly recurring or a one-time assessment.
Deliverable
Prioritised vulnerability report
Who this is for

Teams without dedicated security staff who want ongoing posture monitoring, or a compliance baseline without a full pentest.

~/spidyops · vuln-assessment
$ spidyops --hire vuln-assessment
Automated scanning across web, network, container, and dependencies
Manual triage to remove false positives
Risk-scored findings with remediation priority
Trend reporting over time
Optional integration with your ticket tracker
ships: Prioritised vulnerability report
Get in touch →

SEO and content strategy

Technical SEO and content that earns search traffic.

Three-month minimum baseline with monthly reporting.
Scope
Written SOW · in/out/exclusions
Cadence
Three-month minimum baseline with monthly reporting.
Deliverable
SEO audit + monthly reporting
Who this is for

Companies whose product quality is ahead of their search visibility.

~/spidyops · seo
$ spidyops --hire seo
Technical SEO audit and remediation
Content strategy and editorial calendar
On-page optimisation and internal linking
Core Web Vitals and performance tuning
Long-form content production
ships: SEO audit + monthly reporting
Get in touch →

Support and maintenance

Ongoing care after launch.

Monthly retainer with an agreed scope and response time.
Scope
Written SOW · in/out/exclusions
Cadence
Monthly retainer with an agreed scope and response time.
Deliverable
Monthly retainer + agreed SLA
Who this is for

Teams that shipped a product and want it kept current, secure, and running without hiring in-house.

~/spidyops · support
$ spidyops --hire support
Dependency updates and security patching
Uptime and error monitoring
Small features and fixes on a predictable cadence
Periodic security re-tests
A named point of contact and an agreed response time
ships: Monthly retainer + agreed SLA
Get in touch →
book a scoping call · powered by cal.com

Pick a day + time to start a conversation.

A 15-minute intro to scope the work — scoping is free, no commitment. Opens a booking window; pick any open slot.

how an engagement runs

Five phases. Predictable timelines. No surprise line items.

01

Discovery

Free 30-minute call. We agree on the goal, the constraints, and whether we are a fit.

~1 day
02

Scope

Written statement of work: what is in, what is out, what gets delivered, and when.

2–3 days
03

Execute

The actual work. A private channel for fast pings on anything that needs your call.

1–3 weeks
04

Deliver

Artifacts handed over — code, designs, the report, whatever the engagement promised.

3–5 days
05

Iterate

One follow-up pass included. Re-tests, fix reviews, copy revisions — whatever closes the loop.

1 day
How are engagements scoped and priced?
Scoping is free: a 30-minute discovery call followed by a one-page written statement of work with inclusions, exclusions, deliverables, and a fixed fee. Pricing is fixed per engagement, not hourly. Anything that changes mid-engagement gets a written addendum first.
What's the typical timeline?
Discovery to scope takes two to three days. Execution runs one to three weeks depending on the engagement, with another week for delivery and iteration. Focused audits ship faster; full builds and the full-lifecycle bundle run on a phase plan agreed up front.
Who actually does the work?
Engagements are delivered by SpidyOps. Where a project needs specialist depth we bring in vetted partners under NDA — either way you have one contract and one accountable point of contact.
What's in a penetration test report?
Every finding comes with reproduction steps, a CVSS 3.1 rating, and remediation guidance, mapped to the relevant methodology (OWASP WSTG for web, MASVS for mobile, PTES and MITRE ATT&CK for network and red team). One retest after you ship fixes is included. A sample report is available on request.
Do you sign NDAs, MSAs, or DPAs?
Yes. Standard NDA and DPA templates are available, and most reasonable redlines on your paper get signed within a business day. MSAs are welcome, and we work under your security and compliance addenda within reason.
What happens after launch?
The support and maintenance retainer covers dependency updates, security patching, monitoring, small features, and periodic security re-tests, with a named contact and an agreed response time.
next step

Have a project? Get in touch.

A 1-page scope outline within two business days. Scoping is free; the ground rules are upfront so the engagement doesn't become a negotiation.

Start the conversation →