I look for the weak spots in your website, the way an attacker would.

Hands-on web and API pentests and clear advice for sole traders, SMEs and SaaS start-ups. Always with written permission and a fixed scope.

  • HTB CWESHack The Box, 2026
  • CompTIA Security+2024
  • Mile2 C)SPSecurity Principles, 2022
MindfulSec logo

Services and prices

Prices are indicative and exclude VAT. The exact price follows from the scope in your quote.

Website quick scan

A fast external check of your website, without logging in, using tools and manual review. You receive a short report in plain language with what you can improve straight away.

What I check

  • HTTPS/TLS settings and security headers
  • Visible software and versions (such as CMS and plugins), compared against known vulnerabilities
  • Publicly reachable admin pages, files and folders that should not be online
  • Cookie settings and your domain’s SPF, DKIM and DMARC, against misuse of your email address

A quick scan gives breadth: the weak spots an attacker also sees first. To learn what is possible behind your login, a web pentest is the next step.

from €395

Request a quote

API quick scan

A fast external check of your API, without logging in. You receive a short report with the main risks and what to do about them.

What I check

  • Whether API documentation (such as Swagger or OpenAPI) is unintentionally public
  • Which endpoints respond without authentication and what they return
  • HTTPS/TLS, CORS settings and error messages that reveal too much
  • Whether there is a limit on the number of requests

The biggest API risks often sit in permissions between users: can customer A request customer B’s data? I test that in an API pentest.

from €395

Request a quote

Web pentest

A hands-on test of your web application, the way an attacker would approach it, following OWASP guidance. Includes a report, a debrief and one retest.

What I test

  • Login, password reset and sessions
  • Access rights: can a user reach data or functions that are not meant for them?
  • Input and uploads, such as SQL injection and cross-site scripting (XSS)
  • Your application’s logic, such as orders, payments or discounts

Black-box or grey-box, your choice. Black-box shows what an outsider without prior knowledge can do. Grey-box, with test accounts, goes deeper in the same time. I help you choose.

from €1,950

Request a quote

API pentest

A hands-on test of your REST or GraphQL API following the OWASP API Security Top 10. Includes a report, a debrief and one retest.

What I test

  • Permissions per object and per user: can customer A reach customer B’s data?
  • Authentication, tokens and sessions
  • Excessive data in responses and fields that should not be editable
  • Abuse of functions and missing limits

Black-box or grey-box, your choice. For an API, grey-box, with test accounts and documentation, usually yields the most findings per hour.

from €1,950

Request a quote

Cybersecurity advice

Independent advice to protect your business better.

How I help

  • Before a pentest: what should you test, and how? After it: what do you fix first?
  • An assessment of the security of your website, application or settings (security review)
  • A security policy and an incident response plan: who does what when things go wrong
  • Awareness training: learning to recognise phishing and other traps

from €95 per hour

Request a quote

Introductory rate for my first clients

Web or API quick scan €295, web or API pentest €1,495, advice €75 per hour. In return I ask for permission to publish an anonymised case and a short reference.

Ask for the introductory rate

From first call to retest in six steps

  1. Intro call

    A free 30-minute call about your website, your concerns and your budget.

  2. Scope and permission

    We agree in writing what I test, when, and what is out of scope. Without your signed permission I am not allowed to test, because it would be a criminal offence.

  3. The test

    I search for weak spots by hand, the way an attacker would. Critical findings are reported straight away.

  4. Report

    Clear findings, ranked by risk, with an explanation and a concrete fix. Readable for you and usable for your developer.

  5. Debrief

    We go through the report together. Time for your questions, advice on what to fix first, and how the collaboration went.

  6. Retest

    Fixed the findings? I retest them within three months and confirm what has been resolved. Included with every pentest.

I test your website and API myself, and help you with cybersecurity advice.

I have focused on cybersecurity since 2021. Before that I worked as an account manager at a cybersecurity company, where I learned to explain technical topics to people who are not technical.

At MindfulSec I carry out the web and API pentests myself, from scope to report. I also help you with cybersecurity advice: on its own, or after a test, when I already know your systems. Think of what to fix first, which policy and incident response plan suit you, and how your staff can learn to recognise phishing. You always talk to the person who examined your website.

Certifications

  • HTB Certified Web Exploitation Specialist (CWES), Hack The Box, 2026
  • CompTIA Security+, 2024
  • Mile2 Certified Security Principles (C)SP), 2022

Completed training

  • Hack The Box: Web Penetration Tester and Penetration Tester paths
  • APIsec University: API Penetration Testing
  • PortSwigger Web Security Academy, TryHackMe and LetsDefend

Curious how secure your website is?

Book a free 30-minute intro call. Afterwards you receive a proposal with a scope and a fixed price.

I only use your details to reply. Read the privacy statement.