Zero data egress · Audit-ready · AI-verified

Your CI/CD pipelines
are the front door

We find what auditors will find — before they do. CI/CD security assessments with copy-paste fixes, board-ready evidence, and zero data leaving your perimeter.

Ready to start? Email us — we reply within 24 hours.

From $100/developer · One-time fee · No subscription

The Problem

Your CI/CD pipelines are the most exposed attack surface you're not checking

Automated tools find vulnerabilities. They don't tell you which ones matter, how to fix them, or how to prove to an auditor that you did.

🔓

Unpinned Actions

74.5% of CI/CD findings in GitHub's top 50,000 repos trace to unpinned actions with mutable tags. A single compromised tag gives attackers code execution in your production pipeline.

🔑

Secret Sprawl

Hardcoded tokens, leaked credentials, and overprivileged service accounts — the #1 finding in every CI/CD assessment we've run.

📋

Audit Gaps

SOC 2, ISO 27001, and NIST CSF auditors now ask about CI/CD pipeline security. If you can't evidence it, you fail — or pay for remediation.

Services

Three ways to secure your pipelines

From a one-time deep assessment to sovereign analysis that never touches the cloud. Choose what fits your risk profile.

🛡️

Sovereign Shield

$150 per developer · One-time · $3,750 max (26+ devs)

Zero data egress. We run the Reckon Intelligence Stack on isolated infrastructure — your pipeline metadata never leaves your perimeter. Built for defence, fintech, and regulated industries.

  • Everything in Deep Clean
  • Isolated, air-gapped infrastructure
  • No external AI processing
  • Sovereign compliance documentation
  • 5 business day turnaround
🔄

Quarterly Refresh

$25/dev (Standard) · $40/dev (Sovereign) · Quarterly

Code changes. Actions change. A one-time audit is stale in 3 months. Quarterly refreshes keep your compliance evidence current and your pipeline secure.

  • Re-scan on your schedule
  • Updated risk scoring
  • Continuous compliance evidence
  • Diff report (what changed)
  • Available after any Deep Clean or Sovereign Shield

Need it faster? Express turnaround — 1 business day for +20% surcharge. Available on any tier. Deposit and access confirmation required by 10:00 GMT.

Why Us

Not a scanner. Not a dashboard. A specialist.

We don't sell tools. We sell outcomes — audit evidence, proof of diligence, and CI/CD pipelines you can defend to a board.

🧮

3-Pass Verification Safeguard

Available on every engagement: three independent verification passes with consensus required before a finding is confirmed. Contested findings get a 4th-pass tiebreaker. Deterministic fact-checking validates every finding against source files.

🛡

Live Threat Intelligence

Our scanner patterns are continuously updated from the CISA Known Exploited Vulnerabilities catalog and GitHub Security Advisories. Newly disclosed CVEs are evaluated for CI/CD relevance and added to our detection database automatically.

🎯

Contextual, Not Auto-Generated

Every finding is scored using CVSS 4.0 with full vector strings, contextualised for business impact, and classified under the OWASP CI/CD Security Top 10. We tell you what matters and why — not a prioritised YAML dump.

📋

Audit-Ready from Day One

Our reports are written for auditors and executives, not engineers. SOC 2, ISO 27001, and NIST CSF evidence included.

🔒

Zero Data Egress (Sovereign)

For regulated industries, we run on isolated infrastructure. Your pipeline logic and secrets never leave your perimeter.

Fast Turnaround

Deep Clean delivered in 3 business days (5 for 26+ devs). Not weeks. Not a retainer. A one-time engagement with a clear deliverable.

💰

Half the Cost of Alternatives

$100/developer one-time. Subscription tools charge $150-$200+/dev/year — every year. We are roughly 50% cheaper in year one — and you own the report forever.

vs Subscription tools $150+/dev/yr · vs Traditional pentest $5K-$15K
🤝

Partnership Model Available

For pentest firms and security consultancies: add CI/CD assessments to your offering. We do the work, you keep the client relationship.

Honest Scope

What we assess — and what we don't

We assess the CI/CD pipeline configuration attack surface. Every finding is classified under the OWASP CI/CD Security Top 10. We tell you what's in scope and what isn't, up front.

In Scope

  • GitHub Actions workflows (`.github/workflows/*.yml`)
  • Secret & credential handling patterns
  • Dependency chains & supply chain (unpinned actions, typosquatting)
  • Pipeline access controls (GITHUB_TOKEN, OIDC, PBAC)
  • Poisoned Pipeline Execution (PPE) vectors
  • Artifact integrity & build provenance (SLSA, signing)
  • IaC: Terraform, CloudFormation, Kubernetes, Dockerfile
  • Cross-repo reusable workflow call chains

Outside Static Scope

  • Org-level identity lifecycle (stale, local, external identities)
  • 3rd-party app governance (GitHub Apps, OAuth, webhooks)
  • Audit logging & SIEM configuration
  • Branch protection rules & signed-commit enforcement
  • Application source code (SAST/DAST)
  • Runtime environment testing
  • Full git-history secret scanning
  • Implementation of fixes (guidance only)

Org-level controls require API access and are outside static pipeline analysis. The OWASP CI/CD Security Top 10 covers all 10 categories — we have strong depth in 7, and disclose the 3 that require org-level access.

Pricing

Simple, transparent pricing

No subscriptions. No seat licences. No hidden fees. Pay once, own the report, use it for your audit.

Service Per Developer Min / Max Notes
Deep Clean $100 $500 - $2,500 One-time · Full assessment · 7-day support
Sovereign Shield $150 $750 - $3,750 One-time · Air-gapped · Zero data egress
Express (any tier) +20% 1 business day turnaround · Same deliverables · Requires deposit by 10:00 GMT
Quarterly Refresh $25 (Sovereign: $40) $125 min Requires prior Deep Clean or Sovereign · Billed quarterly
Re-scan (after fix) $50 -- Discounted follow-up scan
Extended Support $250 Flat +7 days of email support
Monthly Retainer $5,000 Flat Weekly threat briefings + on-demand re-scans
CI/CD Add-on (Partnership) $1,000 Flat For pentest firms · You keep $200

Volume discount: 10% off for assessments of 3+ repositories booked simultaneously.

All engagements subject to 50% deposit to begin. Balance due before full report delivery. Ask about our payment terms for enterprise engagements.

All prices in USD. Minimum 5 developers. Enterprise teams (50+) — contact us for custom pricing. Partnership pricing available for pentest firms and security consultancies.

Your auditor is asking about CI/CD right now.

Let's have that conversation before it becomes a finding.

Start the Conversation → Review Services