NullShield Engagements

Consultative pricing for premium security work

NullShield public pricing is structured around audit, verification, and monitoring, not scan-count packages or checkout-first flows.

Recommended engagement path

Premium Security Audit → Fixes → Verification Retest → Monitoring if needed

Start with a scoped baseline, close the highest-risk issues first, verify the fixes, and then decide whether an ongoing retainer fits your release cadence.

Premium Security Audit

Starting at $2,500

Best for teams that need a serious baseline assessment across AI systems, websites, APIs, and key authentication or abuse paths.

  • Attacker-realistic external testing
  • Executive summary and technical findings pack
  • Prioritized remediation guidance
  • Review call with your team
  • One verification retest after fixes

Typical fit: initial baseline, investor or customer diligence, or launch readiness.

Book discovery

Monitoring Retainer

From $299/mo

Built for post-audit continuity when your stack, prompts, integrations, or releases change often enough to justify ongoing visibility.

  • Available monthly or quarterly
  • Regression and change tracking
  • Priority notification for material issues
  • Trend visibility between review cycles
  • Uses the baseline audit as the reference point

Best after the baseline audit establishes what good looks like.

Book discovery

Focused Validation / Retest

Scoped follow-up

A narrower engagement for post-remediation verification, release validation, or existing-client follow-up, not a replacement for the main audit.

  • Ideal for existing clients or known scope
  • Validates fixes before launch or re-release
  • Can cover a new feature, API, or workflow
  • Quoted from agreed scope, never a public checkout flow
  • Useful when you need confidence on a specific change

Typical starting point for existing clients with known context or recent fixes.

Book discovery

What is included, and when

This comparison is built around deliverables and engagement structure, not raw automated test counts.

DeliverablePremium AuditMonitoring RetainerFocused Validation
Primary purposeBaseline risk assessment and decision-grade reportingPost-audit regression visibility and change trackingTargeted retest or scoped follow-up
Best time to use itBefore launch, after major changes, or when trust is uncertainAfter the baseline audit is completeAfter fixes, before release, or for an existing client request
Report styleFull executive and technical deliverableOngoing trend and issue visibilityFocused verification summary tied to scoped work
Verification retestIncluded once after remediationAvailable as part of continuing engagement planningCore deliverable
CadenceOne scoped engagementMonthly or quarterlyAs needed, by agreed scope
Public checkoutNo, discovery-led scoping onlyNo, started after the audit plan is confirmedNo, reserved for scoped follow-up
Optional Support

Common scoped add-ons

These are typically layered onto the main engagement when the business context calls for more depth or support.

Remediation support

Hands-on technical help to close validated issues when your team wants implementation support after the audit.

Quote after findings

Authenticated depth review

Optional limited-access testing when internal workflows or privilege boundaries need deeper validation than external testing alone.

Scoped by surface

Guardrail and policy review

Additional review of AI guardrails, workflow protections, and policy handling for teams shipping agentic experiences.

Scoped add-on

Ready to scope the right engagement?

Tell us what you are shipping and where you need clarity. We'll recommend the right audit path without pushing a self-serve package that doesn't fit.