Skip to main content
assurance support

Assurance levels

Choose the right depth of review

Every level follows the same published standard. Higher levels add depth, testing, and evidence for applications with more at stake.

Foundation Reviewed

For prototypes, internal tools, and smaller applications.

A structured baseline review that identifies the risks most likely to cause harm in early-stage and internal software.

  • Basic architecture review
  • Secrets and dependency scan
  • Authentication review
  • Backup and logging checks
  • Deployment documentation
  • Major risk identification
Most requested

Business Ready

For applications offered to business customers.

A full production-readiness assessment for software that businesses will rely on, with independent retesting after remediation.

Everything in Foundation Reviewed, plus:

  • Authorization and role testing
  • Database and API review
  • Automated and manual testing
  • Backup and recovery testing
  • Maintainability assessment
  • Deployment and rollback review
  • Security-control verification
  • Remediation and retesting

High Assurance

For sensitive or business-critical applications.

The deepest level of review for applications that handle sensitive data or support critical business operations.

Everything in Business Ready, plus:

  • Threat modeling
  • Penetration testing coordination
  • Detailed audit-log review
  • Encryption and key-management review
  • Disaster-recovery exercise
  • Software bill of materials
  • Load and performance testing
  • Change-control requirements

High Assurance is a rigorous independent technical review. It does not automatically constitute legal or regulatory certification.

Side by side

Detailed comparison

What each assurance level covers, category by category.

Comparison of Foundation Reviewed, Business Ready, and High Assurance levels
Assessment category Foundation Reviewed Business Ready High Assurance
Intended application type Prototypes, internal tools, smaller applications Applications sold to or relied on by business customers Sensitive or business-critical applications
Source-code review Targeted Full Full, with depth targets per domain
Dependency scanning Included Included Included, with SBOM
Secrets scanning Included Included Included
Authentication testing Review Review and testing Review and testing
Authorization testing Role and permission testing Role and permission testing
API review Included Included, with abuse-case testing
Database review Included Included
Backup testing Configuration check Tested Tested
Restore testing Tested Tested, with documented evidence
Architecture review Basic Detailed Detailed, with threat model
Maintainability review Included Included
Automated testing review Included Included
Manual application testing Included Included
Penetration testing Coordinated
Threat modeling Included
Performance testing Load and performance testing
Disaster recovery Recovery testing Full disaster-recovery exercise
Public verification record Included Included Included
Verification duration 6 months 6 months 6 months, with quarterly check-ins

Assessment pricing depends on application size, complexity, and scope. Request a scope review and we will recommend a level and provide a written proposal — there is no charge for the scoping conversation.

Not sure which level fits?

Tell us how your application will be used and who depends on it. We will recommend the right scope.