Hey there, I work at Accuvant on the application security team. We work with a lot of the top tech companies and Fortune 500. We offer services across the entire spectrum of security consulting. You can see everything we offer here: <a href="http://www.accuvant.com/services/enterprise-consulting" rel="nofollow">http://www.accuvant.com/services/enterprise-consulting</a><p>If you choose an audit from our company for a web app or mobile app, I (or one of my coworkers) would be the one doing the audit, so I can answer literally any question you have about the entire process. I'm not a salesman, and I don't make commission, so I'll speak very candidly about the process.<p>My team (application security) primarily performs application penetration testing and vulnerability assessment where a group of consultants will take a fine comb to your entire tech stack. If you want to give us source code to analyze, all the better, and we will do so both manually and using automated tools. We do not heavily rely on automated tools for any type of testing, and our technical skill is very high overall on the team, with a huge diversity of skillsets and experience.<p>We communicate with clients constantly and send detailed reports at least once a week detailing our progress and any findings. At the end of the assessment, we provide a final deliverable which details everything, along with remediation recommendations and "where to go from here."<p>A serious audit of your web app will run you in the low tens of thousands, figure between $10,000 on the low end and $30,000 on the high end - this is what it will cost at any good firm in the United States. For that price you will get two weeks or so - 80 hours - of comprehensive testing on your application. Expect around $20,000. If you're doing something much more specialized like auditing a cryptosystem or doing reverse engineering, or packaging red teaming/incident response into the assessment, you're going to add quite a bit more.<p>We prefer working on staging or preview environments, but we will test your production environment if you'd rather we do that. We also accommodate different hour requests - for example, only performing automated testing during off-business hours and matching you with a consultant in your time zone.<p>Most of our clients choose to book us remotely, but we can and will go onsite for you if you'd like.<p>My email is in my profile, so if you'd like to talk more you're more than welcome to reach out. Good luck!