What it costs, before we get on a call.
We'd rather you know up front whether we're affordable than waste your time on a sales call. Here are the ranges. Specific quotes follow the intake conversation; nothing on this page is a binding offer.
Hourly engagements
For ongoing work without a fixed scope: configuration changes, incident response, ad-hoc audits.
$185 – $275 / hour
Senior engineer rate. Higher end for after-hours / weekend / on-call. Tracked in 15-minute increments. Invoiced monthly with itemized work log.
Retainer engagements
Predictable monthly cost for ongoing operational support — patching, monitoring, periodic audit prep.
$2,500 – $9,500 / month
Sized to staff count + service surface. Includes a fixed hour bucket; overflow at the standard hourly rate. 30-day cancellation; no long-term lock-in.
Fixed-scope projects
For one-time deliverables with a clear shape: cloud migration, mail server self-hosting, security audit + remediation, vertical-specific compliance posture.
$8,000 – $60,000 per project
Quoted after a paid discovery (typically $1,500 – $3,000, credited toward the project if you hire us). Discovery deliverable is yours regardless — you can take it elsewhere.
Discovery / scoping
When the shape is unclear or you're shopping vendors. We produce a written assessment of your current state, top three risks, and a recommended next-step plan.
$1,500 – $3,000, fixed
Two-week turnaround. Yours to keep regardless of next steps.
What a penetration test costs.
Assessment work is priced from a published day rate rather than a range, because a range is not much use when you are comparing two proposals. Here is the whole rate card and the arithmetic.
- $1,600 per engineer-day
- An eight-hour day of senior testing time, billed in half-days. The person testing is the person who scoped it and the person who writes the report.
- $1,200 flat, once per engagement
- Scoping, threat modeling, report synthesis and the readout call. Charged once whether the assessment runs two days or twenty.
- Included
- A retest of high and critical findings within 30 days. Not an upsell, not a second engagement — verifying the fix is part of the job.
- +25%
- Rush turnaround or testing outside business hours. Applied to the testing days and the $1,200 fee, and only when you ask for it. The extended retest below is never rushed, so it is never surcharged.
- $1,000
- Optional. Extends the retest window from 30 to 60 days when a fix has to wait on a release train.
Worked example
A web application with roughly 30 endpoints and two user roles scopes to 6.5 days of testing. That is $10,400 of testing time plus the $1,200 flat fee, so $11,600 — agreed in writing before anything starts, with the retest included. If the scope changes mid-engagement, the price conversation happens before the work does.
The method behind that number is on the services page, and the report it produces is published in full.
What we don't do
- No "call for pricing." If we're a bad fit on price, you should know in 30 seconds, not three phone calls.
- No bait-and-switch. The proposal we send is what you pay; scope changes require a written change order with a new price.
- No long-term lock-in. Retainers are 30-day cancellable. We'd rather earn renewal than collect a termination fee.
- No referral kickbacks. When we recommend a third-party tool or vendor, we are not paid to do so. Recommendations are based on fit.
- No license-arbitrage markup. If we resell software (Microsoft 365, etc.) we pass through at cost.
If our rates don't fit, we'll tell you who does.
We're not a fit for every budget. If you're a 1-2 person practice that needs $50/month tier IT support, you should hire someone other than us — and we'll happily refer. The intake conversation is a free filter that protects your time as much as ours.