Security engineering for startups that scale.
Fixed-scope, fixed-price security work for startups that just need: a pentest, to close a deal, and get back to shipping. No retainers, no sales process, no junior consultants.
One engineer. Senior work. Clear deliverables.
Who this is for
You've reached the point where security matters but not the point where you can hire for it.
- A customer sent you a security questionnaire or asked for a pentest report.
- You're working toward SOC 2 and your auditor wants evidence, not intentions.
- Nobody has ever reviewed how your Google Workspace, Microsoft 365, or cloud account is actually configured.
- Something happened, like a phishing incident or a leaked credential, and you want an expert to look before it happens again.
If that's you, the services below are built to be bought without a six-week sales cycle.
Services
Security Hardening Review
Google Workspace & Microsoft 365
5 business days
$2,500
Cloud Account (AWS, GCP, Azure)
5 to 7 business days
$4,000
Bundled
2 weeks
$6,000
The two places a small company gets compromised are its identity and email tenant and its cloud account. Most companies set both up in an afternoon and never looked again. I review the configuration the way an attacker would look for a way in, and give you a prioritized list of what to fix.
Tenant review
- MFA enforcement and conditional access
- Admin roles and privileged accounts
- Third-party apps with OAuth access to your data
- External sharing and link settings
- Email authentication (SPF, DKIM, DMARC) and anti-phishing controls
- Retention, audit logging, and device policies
Cloud review
- IAM users, roles, and permission boundaries
- Public exposure: storage, databases, load balancers, security groups
- Secrets and credential handling
- Logging, alerting, and audit trail coverage
- Encryption, backups, and recovery
- Network segmentation between environments
One account or organization. Configuration and identity, not application testing.
Every option
- A findings report ranked by risk, written for the person who has to fix it
- A prioritized fix list for whoever administers the system
- A 45-minute walkthrough call
- Optional: I make the changes with you
Application Security Assessment
2 weeks
From $6,000
A manual penetration test of one web application or API, combined with a review of the code paths that matter. This is the report you hand to customers, auditors, and enterprise procurement.
How it works
- Scoping call to agree on what's in and out
- Manual testing against OWASP and business-logic issues, not just a scanner
- Code-assisted review of authentication, authorization, and data handling
- A report with severity, reproduction steps, and specific remediation guidance
- A retest of everything you fix, included
What you get
- A full technical report
- A customer-safe summary letter for questionnaires and audits
- A retest and updated report at no additional cost
Fractional Security Engineer
Monthly, 3 days per month
From $4,000 per month
For companies that want an experienced security engineer on call without a full-time hire. I join your Slack, review designs and pull requests, own your security backlog, answer questionnaires, and represent you to auditors and customers.
Typical work
- Security review of new features and infrastructure changes
- Owning SOC 2 or ISO 27001 technical controls
- Customer security questionnaires
- Incident triage when something looks off
- Building the processes so you eventually don't need me
How it works
Call
30 minutes, free. You describe the situation; I tell you whether one of these fits or whether you need something else.
Scope
You get a one-page statement of work with a fixed price and a delivery date. No hourly billing, no surprises.
Work
I do the work myself. You get updates as I go, not a report dropped on your desk at the end.
Deliver
A report you can act on, a walkthrough, and remediation help if you want it.
Why Neutrala
I'm Zac. I've spent 8 years doing security engineering and application security for global security providers, financial institutions, and health insurance companies.
Neutrala is just me. That's on purpose. You get the person with the experience, not a project manager and a rotating bench. Every finding in your report is something I found and verified myself.
FAQ
Do you use automated scanners?
Yes, as a starting point. Scanners find the easy things. The findings that matter, like broken authorization, business-logic flaws, and misconfigured trust between systems, come from manual work, and that's what you're paying for.
Will this get us through SOC 2?
The Application Security Assessment produces the pentest evidence auditors ask for. The Hardening Review, especially the cloud option, covers a large share of the technical controls. Neither replaces a compliance platform or an auditor, but they give you real evidence instead of checkbox evidence.
What if you find something serious?
You hear about it the same day, before the report is finished. Critical findings don't wait for a deliverable.
Can you fix things, not just find them?
Yes. Remediation is optional on every engagement and quoted separately so you can decide after seeing the findings.
What do you need from us?
For the Hardening Review: read-only admin access to the tenant or a read-only IAM role in the cloud account, or a screen-share session if you'd rather not grant access. For the App Assessment: a test environment, test accounts for each role, and repository access if you want the code-assisted review.
We're tiny. Is this overkill?
The Hardening Review exists for exactly this case. Five days, one price, and the most common ways small companies get compromised are covered.
Not sure which one you need?
Book a 30-minute call. I'll tell you what I'd look at first, whether or not you hire me.