A team of ethical hackers. Not scanners.

See what others
miss before launch.

We're ethical hackers and software developers who review your app by hand to find what scanners and AI miss. Plain-English findings, zero noise, complete trust.

Trusted by founders & early-stage teams
Confidential
Always
Founder Friendly
Clear & actionable
100% Human
No AI scanners
Fast Turnaround
Built for startups
Launch Readiness
Overview Authentication Data & Privacy APIs & Backend Infrastructure Dependencies Secrets & Config Business Logic
78
Risk Readiness Score
Good
SummaryOverall posture is solid. We found important issues that should be addressed before launch.
7 High-Risk Issues
3 Medium-Risk Issues
11 Informational Items
Hidden Issues
Broken Object Level AuthorizationUsers can access and modify resources they don't own. High
Exposed API KeyHardcoded key found in client bundle, allows unauthorized access. High
IDOR in Invoice EndpointInvoice IDs are predictable and not user-scoped. Medium
Over-Permissioned TokenToken has unnecessary scopes increasing blast radius. Medium
Deeper issues revealed. Fixed before launch.
Real people. Every audit. Your app in trusted hands.

Human-Led Review

Real people. Every audit. We read, test, and break it like an attacker.

Plain English Findings

No jargon. No noise. Clear issues, explained in founder language.

Security + Launch Ready

From code to config to compliance — ship safe, launch stronger.

Startup Friendly

Fast turnaround, fair pricing, built for lean teams.

No Scanner Noise

No automated tools. No filler. Just signal that matters.

Services

Focused audits. Real impact.

Choose the review that matches your stage.

10-Foot Audit

High-level security review to identify critical risks and blind spots.

Learn more

Pen Test Audit

In-depth penetration testing to uncover exploitable vulnerabilities.

Learn more

Code Review

Line-by-line code analysis for security, design, and maintainability in game and server code.

Learn more

Fix-It Solution

We don't just find issues — we help you fix them fast and right.

Learn more

Staging & Testing Environment

Secure, production-like environments to test with confidence.

Learn more
Process

A clear path from uncertainty to launch.

Discover

We learn about your app, stack, and goals.

Audit

We manually review your systems, code, and configs.

Explain

You get a clear report with proof, context, and impact.

Fix

You ship the fixes and validate improvements.

Launch

You launch with confidence. We've got your back.

Pricing

Simple pricing. Real work.

Every audit ends the same way — a plain-English report, ranked by severity: what it is, why it matters, and how to fix it.

The audits

Each tier goes one level deeper and needs one more level of access. Two rates: an established price, and a lower starting-out price while we build up reviews.

T1
$199
starting out: $99

The 10-Foot Audit

"Is it broken?"
2–3 days
  • Click through every core flow and confirm things land where they should
  • Break-test forms and inputs with junk, empty, and oversized values
  • Watch the network tab for obvious leaks and client-side price/logic
  • Mobile + desktop, plus error and broken-state handling
  • Written findings report + 15-minute walkthrough call
Needs: access to the working app.
T2
$499
starting out: $299

The Pen Test

"Can someone break in?"
3–5 days
Everything in T1, plus:
  • Auth testing — can we reach another user's data, ride, or account?
  • Hunt for exposed API keys, service credentials, and database access
  • Broken access control / IDOR — change an ID, see someone else's data
  • Endpoint probing and business-logic abuse (e.g. tampering with a fare)
  • Severity-ranked vulnerability report + walkthrough call
Needs: app + test account + written go-ahead, staging only, no real user data.
T3
$999
starting out: $599

The Code Review

"Is it built right?"
5–7 days
Everything in T1 + T2, plus:
  • Read the code — auth logic, database rules, and permission model
  • Secrets handling — hardcoded or committed to the repo?
  • Architecture + data model, and where PII and location history live
  • Dependency, config, and payment-flow review
  • Full written audit with file/line references and specific fixes
Needs: read-only repo access. The deepest look — catches what the outside can't see.
T4
$125/hr
or fixed from $1,500

The Fix

"Make it right."
1–3 weeks
Stop auditing, start fixing:
  • Hands-on remediation of the findings from T1–T3
  • Production hardening — secrets, auth, and access control
  • Re-test after fixing to confirm each hole is actually closed
  • Two-week support window + a "here's what we changed" summary
Needs: repo access + agreed scope. Fixed price only after T3 sizes the work.
Most founders start here

The Full Once-Over — Tiers 1–3

The complete outside-in and inside picture. For "just tell me if I'm okay to launch." One easy yes — we anchor everything to this.

$1,499
starting out: $899 · ~1–2 weeks
Book the Full Once-Over

Before you ship & beyond

Most founders test on production, with real users. These fix that — and the recurring lines are where safe-shipping actually lives.

S0
$499
the front door

Get-Set-Up

"Give me a safe place to test."
2–4 days
  • A real staging environment, separate from production
  • Realistic seed data that isn't your live users
  • Secrets pulled out of the client and split from the code
  • A one-page "how you ship from now on" checklist + 30-min walkthrough
Note: credited toward any audit or the Full Once-Over. Complex stacks quoted to $900–1,200.
S1
$149/mo
recurring · light $79/mo

Shipping Safety

"Keep me safe every time I ship."
ongoing
  • Keep staging in sync with production
  • Refresh seed data so tests stay realistic
  • Monthly smoke test across the core flows
  • We're your "I think I broke something" people before you push
Note: reliability upkeep. Light tier keeps it synced + monthly check, no on-call.
S2
$199
one and done

Show-Me Session

"Just show me how."
1 call
  • One call — turn on the preview/branch environment you likely already have
  • Set the safe-to-ship workflow and never-test-on-prod habit
  • A Loom recording so you can do it yourself next time
  • No ongoing commitment (but it warms you up for Shipping Safety)
Note: cheapest door in. Great for the ones not ready to commit.
New · recurring
SW
$299/mo
the security retainer

The Standing Watch

"Stay secure as you ship."
ongoing
  • Every month, we review what you shipped — new features, endpoints, and flows
  • Dependency + exposed-secret monitoring, flagged the moment they surface
  • A short written report each month + a walkthrough call
  • Priority "is this safe to ship?" answers between reviews
Note: picks up where a one-time audit ends. Best paired with any tier.
Book an Audit Not sure which? Message us and we'll point you to the right one.
UmbraGlass — ethical hackers at work
Who We Are

We're the ones doing the audit.

UmbraGlass is an ethical group of hackers and software developers — founder-focused, not faceless. We personally review your app by hand to find what scanners and AI miss. When you work with UmbraGlass, you work with real people who want your launch to go right.

A group of ethical hackers and software developers

Trusted by indie teams, studios, and startups worldwide

Confidential, respectful, and founder-focused

The truth before your users find it.

Book your audit today and launch with confidence.

Fast turnaround Founder friendly pricing 100% confidential