Security & Trust
Everything you or your security team needs to assess who we are and how we handle your code, access and data, in one place. No certifications are claimed here, only what is true and independently verifiable.
Who we are
Secvura Limited is registered in England and Wales, company number 17292680, registered office 167-169 Great Portland Street, Fifth Floor, London W1W 5PF. You can confirm our number, registered office and directors on the public Companies House register. We are a two-person firm: you work directly with the co-founders, Amirali Khezrey and Shyueb Sediqi, from the first call to the final fix, with no sales team and no handoffs. We are not VAT registered.
How we handle your access and data
Nothing is tested until you have signed a written authorisation naming the exact systems in scope. We do not act on informal permission, and we do not test anything outside that scope.
Within five working days of an engagement ending, we revoke our access, delete your credentials, and delete scan output and working material, and we confirm that to you in writing. Where we act as a processor for your personal data, a per-engagement Data Processing Agreement is available, and our data handling approach can be shared on request.
How we handle personal data submitted through this site, and held about people we contact, is set out in full in our Privacy Policy, and the terms on which our services and free tools are provided are in our Terms of Use.
Our free tools, and their limits
The free Surface Check is passive and read-only: it reads only what a domain already shows the public internet. When it detects a Supabase or Firebase backend it does not query it; the read-only database check runs only when someone starts it themselves and confirms they are authorised to test that project. We never sign in, never use a secret key, never read the contents of your data, and never write to or change anything. The full scope and permitted use of both tools are set out in our Terms of Use.
The security of our own systems
We publish a Vulnerability Disclosure Policy and a security.txt so a researcher who finds an issue in our systems has a clear, authorised way to report it. We also hold ourselves to the same external check we offer you, and publish secvura.com’s own result.
What you receive
An Application Security Review is a hands-on assessment, by a person and with automated tooling, of your application and the systems behind it. Every finding is written in plain language, scored by severity and by fix effort, with the specific change to make, and sequenced into a remediation roadmap. You can read a full, clearly-fictional sample report before you ever speak to us. Your real report is confidential to you.
Transparent pricing
Our prices are fixed and published in full: £1,200 for an Application Security Review, £1,500 per 20-hour remediation block, and monitoring, when available, is expected to be £300 per month. We are not VAT registered, so the price you see is the price you pay. The full breakdown is on our pricing section.
What we do not claim
We would rather be plain than impressive. We do not currently hold formal certifications such as ISO 27001 or SOC 2, and we do not imply that we do. We do not describe our work as “penetration testing” or “ethical hacking”; it is application security review and remediation. And we do not claim to have assessed anyone’s systems without their written authorisation.
Ready when you are
Start with the free check, or request a review. We reply to every enquiry within one working day.
Request a security review