Skip to content
Security Consulting

Practical website and app security reviews

Website and app security reviews, data protection guidance and secure builds, from the engineers who write production code, not from people who stopped a decade ago. Practical and plain-spoken: we look at what you run, find the weaknesses that matter, and give you a prioritised plan in language you don't need an IT department to understand.

You don't need to be a bank to be a target. Small businesses, schools, charities, and community organisations hold exactly the kind of data attackers want, and usually have the least support protecting it. If it's one specific website you're worried about, our fixed-price website security audit is the more focused starting point.

Reviewed by Lucas Reddington, full-stack developer and AI engineer, shipping production systems since 2020. Last reviewed .

What we do, and what we don't - in the words a buyer uses

Three terms get used interchangeably and they are not the same product. If you are filling in a procurement form or an insurance questionnaire, the distinction matters more than the marketing, so here is ours plainly.

A development security review is us reading the code, configuration and infrastructure: how access is enforced, how secrets are held, how data moves, what the dependencies drag in. That is the work we do most, and it is the one that catches the problems that actually sink small applications.

A vulnerability assessment is scanning a running system for known weaknesses and misconfiguration, then triaging what comes back. We run this continuously rather than as an annual event, using our own AI-assisted tooling against the systems we host. Jenny Rafferty, who has been shipping to production since 2023, reviews the findings as a second pass before anything reaches you, so no automated report goes out untriaged.

A penetration test is a scoped, adversarial engagement by a human tester working to agreed rules of engagement, usually ending in a formal report for a third party. We do not sell that, and we will tell you so early rather than late. If your client, insurer or framework requires one, we will help you scope it, brief a CREST or equivalent-accredited tester, and fix what they find - which is the part we are actually good at.

What we run on the systems we host

Security on a system nobody watches decays quietly, so this is a schedule rather than a one-off. It applies to everything on our hosting and maintenance plans.

Weekly

Error and exception triage through Sentry, so a fault that started on Tuesday is not still running on Friday. Dependency alerts reviewed as they land.

Monthly

Dependency and platform updates applied and verified, access and account review, and a check that backups restore rather than merely exist.

Quarterly

A deeper pass over each application: AI-assisted vulnerability scanning across the running system, with the findings triaged and second-reviewed by an engineer rather than forwarded as a raw report.

Annually

A full review of the whole estate - architecture, access model, data retention, third-party processors and the recovery plan - written up so you can hand it to whoever asks.

What we can look at for you

Security consulting can mean a hundred things. Here's what ours covers most often.

Website & app security reviews

We examine your site or app the way an attacker would - authentication, data handling, common vulnerabilities - and report what we find with fixes, not fear.

GDPR & data protection guidance

What data you hold, where it lives, whether you're handling it lawfully, and what to fix first. Practical compliance, not paperwork for its own sake.

Secure-by-design builds

Building something new with us? Encryption, access controls, and audit trails are baked into every project - see how we build for the full picture.

Incident readiness

A simple, rehearsed plan for the bad day: who does what, what gets isolated, who gets told, and how you recover.

Automated checks, manual review, and the difference

Most of what gets sold as a security review is a scanner report. Automated scanning is useful and we run it: it finds out-of-date dependencies with known vulnerabilities, missing security headers, exposed configuration and the well-catalogued classes of problem, quickly and cheaply. What it cannot do is understand your application.

The findings that actually matter to small organisations are usually logic ones: a URL that shows you another customer's record if you change the number in it, an admin function the interface hides but the server still accepts, a password reset that can be pointed at someone else's account. No scanner finds those, because they require knowing what the system is meant to do. That's the manual half, and it's why a developer does this and not a tool.

So a review is both: the automated sweep for the catalogued problems, then a person working through authentication, access control, data exposure and the paths through your application that money or personal data travel down. Findings are mapped to the OWASP categories so your developer recognises the vocabulary, and we confirm every one by hand before it reaches your report.

What we will not claim to be

Three boundaries, stated up front, because the alternative is a client discovering them at the worst possible moment.

This is not accredited penetration testing. If a contract, insurer or regulator requires a CREST-accredited test, Cyber Essentials Plus certification, PCI DSS assessment or an ISO 27001 audit, that requires an accredited body and we will tell you plainly and help you find one rather than stretching our service to fit your tender document.

It is not a compliance verdict. We can tell you your site leaks personal data through an unauthenticated endpoint and what to do about it. We cannot certify that you are GDPR compliant, because nobody outside a regulator or an accredited auditor can, and any supplier who offers to is overreaching.

And it is not legal advice. Piers's background in law means data-protection obligations get taken seriously and explained clearly, and it means we know where the line is. For a formal legal opinion you need a solicitor advising you, and we'll say so.

Why us - a rare combination

Most security consultants stopped writing code years ago. Ours haven't: the same engineers who build production systems do the reviewing, so the advice is grounded in how software actually breaks, not in checklists.

And because Northbytes is co-founded by someone with a background in law, the legal side - data protection obligations, liability, duty of care - is treated as seriously as the technical side. You get one conversation that covers both.

Thorough doesn't have to mean expensive

A real security review is human work: someone who understands how systems break, looking hard at yours. That part never gets handed to a machine. What modern AI tooling changes is the legwork around it - mapping what you run, surfacing the obvious gaps, widening the coverage - so our senior engineers spend their time on judgement instead of busywork. Every finding is still confirmed and owned by a person.

That's how you get the depth of a specialist engagement without the specialist price tag: senior attention at a fair, fixed price you'll know before we start, not an open-ended day rate. It's the same way we build and ship our own software - apps like The Forge and Light of the Word - so it's a proven way of working, not a cut corner. Most organisations don't need the five-figure engagement they feared, and when something genuinely does need an accredited specialist, like formal penetration testing for a regulated industry, we'll tell you plainly rather than stretch beyond what we should.

Common questions

How much does a security review cost?

It depends on what you run, but it's a fixed price agreed before we start, never an open-ended day rate. A review of a single website or app costs a fraction of what most people fear when they hear "security consultant", and we'll tell you up front if what you actually need is smaller than what you asked for. If something genuinely requires an accredited specialist, like formal penetration testing for a regulated industry, we'll say so plainly and help you find one.

Do we need a security review if we're a small business?

Probably more than a big one does. Small businesses, schools and charities hold exactly the kind of data attackers want, usually with the least support protecting it, and attackers automate their searching so size is no protection. A short review that finds the two or three weaknesses that matter is far cheaper than the average recovery from an incident, in money and in trust.

Worried about something specific?

Tell us what you run and what keeps you up at night. The first conversation is free and confidential.

Start the conversation