See your attack surface before attackers do.

DCL tests web apps, APIs, AI systems and connected devices for funded startups. You work directly with the testers doing the work, and you get a certificate your customers and investors can verify.

  • Scoping in 48 hours
  • Engagements from $3,000
  • Retesting built in

Three surfaces, one team.

Most firms cover one of these well. Startups shipping AI features on connected hardware need all three tested together, by people who talk to each other.

Application & infrastructure

Vulnerability assessment and penetration testing across everything your users touch.

  • Web and mobile apps
  • APIs and integrations
  • Network and cloud configuration

From $3,000

AI security

Testing for the failure modes that arrive with LLMs and agents, before your users find them.

  • Prompt injection and jailbreaks
  • Agent and tool misuse
  • Data leakage through model outputs

From $8,000

IoT security

Hardware, firmware and the radios in between, tested the way an attacker with the device in hand would.

  • Firmware extraction and analysis
  • Hardware debug interfaces
  • BLE, Zigbee and MQTT

From $8,000

How an engagement runs.

Every engagement follows the same five steps, so you always know what happens next and who is doing it.

  1. Scope

    A 30-minute call, then a fixed-price scope in your inbox within 48 hours.

  2. Test

    Manual testing backed by tooling, run against an agreed window and environment.

  3. Walk through

    A report written for engineers, plus a live call with the testers to go through every finding.

  4. Fix and retest

    Your team patches. We confirm each fix actually holds.

  5. Certify

    You receive a verifiable certificate, valid for six months.

Proof you can share, not a PDF in a drawer.

Investors and enterprise buyers ask whether you've been tested. The certificate answers in seconds, and its expiry date keeps your security from going stale.

Unique ID
Every certificate is issued against one engagement and one scope.
QR check
Anyone can scan it to confirm it's genuine and still valid.
Six months
When it expires, a retest renews it.

Sample layout. Real certificates carry a live verification code.

Priced for startups that are scaling.

Fixed prices agreed before testing starts. Half up front, half on delivery of the report.

Starter VAPT

$3–5K

One web app or API. Good for a first test before a fundraise or launch.

Standard VAPT

$6–8K

App, API and cloud together. The usual fit for Series A teams.

AI or IoT

$8–10K

LLM features, agents, or a connected device and its firmware.

Enterprise

$25K and up

Multiple products and surfaces, scoped around your roadmap.

70% of the original feeSingle retest, whenever you need it.
50% of the original feePer retest on an annual contract, two or more retests a year.

You talk to the testers.

No account managers in between. The people who found the issue explain it, and they're the ones who check your fix.

Security that keeps up.

Your product changes every sprint. Six-month certificates and built-in retests keep your assurance current, not frozen at one date.

Written for builders.

Findings come with the request, the impact and the fix, in language your engineers can act on the same day.

Tell us what you're shipping.

Send a line about your product and what's coming up. A fundraise, an enterprise deal, an AI launch. We'll come back with a scope within 48 hours.