48 hour security review: when the clock actually starts
A 48 hour security review is possible on one web app if access works. The clock starts at login, not at the first sales email or the card charge.
A 48 hour security review is a delivery promise, not a dare.
It holds when the target is one application, the rules are written, and a test user can sign in. It fails when five apps hide in one invoice or the SSO invite never arrives.
Short answer: I write the report 48 hours after access works on one app. $2,400 total, $1,200 on the offer page. Window is 24–72 hours if the surface is tiny or unusually wide.
What fits in 48 hours
Login and session. Role checks. The pages a user can see. The APIs those pages already call. Notes by severity. Restore. One later retest of the same URL within 14 days.
What does not fit: source audit, a mobile binary, a phishing campaign, a second product.
How to keep the clock honest
Send staging if production is messy. Grant a guest SSO user instead of a shared password. Name out-of-scope admin tools. Ask for the sample if you want to see the output first.
Same numbers on pricing.
FAQ
Can a security review really finish in 48 hours? +
Yes, on one scoped application after credentials work. A tiny surface can finish sooner. A wide SaaS may take up to 72 hours.
Does payment start the clock? +
No. The $1,200 start payment reserves the work. The clock starts when written scope and working access are in.
What if access is broken? +
I tell you. Time does not run against a login that fails.