It does not scan. It musters the scanners you already have, and turns them into one number you can hand to somebody.
Six tools that run when a person remembers them are worth less than two that run themselves. Apex Muster assembles the checks, scores the whole estate in one place, and prints the coverage next to the score, so a number is never read as more than it is.
The sample opens with fabricated findings for a business that does not exist, and it says so on the page. No real client’s report is ever published, which is why the sample is fabricated rather than redacted. The full offering, and what a review does not cover, is on the security page.
A count is not a measurement.
Forty-seven issues found tells you nothing about Monday. Neither does a green tick from a tool that could not reach half of what it was pointed at, which is the more expensive of the two, because it gets believed.
A number with no coverage beside it
Ninety six sounds like a pass. Ninety six across forty percent of a business is one tidy corner and a lot of unopened doors, and nothing on the screen says which one you are looking at.
A check that broke, shown as a check that passed
The most expensive failure in this practice’s history is always the same shape: a broken check that reads as a clean one. It stays wrong for as long as nobody thinks to look, because there is nothing to look at.
An accepted risk that quietly became permanent
Somebody decides to live with a finding, writes it down, and it leaves the list forever. A year later nobody can say whether it is still true, and nobody is going to ask.
Four measured substrates, each carrying a stated weight.
Nothing here is a new scanner. These are the checks that already exist, run on a cadence instead of on a memory, and rolled into one score. The score is weighted across the substrates that are measured, the weight beside each one is what it is worth, and the weight of anything that did not report is what your coverage is missing.
Posture
Row-level security on every table, policies that resolve to true for everyone, what the anonymous role can execute. The only class of finding that leaks records with no second step.
Secrets
A live credential in history is already published, and rotation is the only fix. Findings record that a credential exists at a path, never the credential.
Filesystem
Silent insecure fallbacks, backup files left in a public directory, fast password hashes, admin keys reachable from a browser bundle.
Dependencies
Published advisories against what is actually installed, rather than against what the manifest says should be.
Three of these read a filesystem, a git history and a package manager, so they run against a checkout rather than inside a serverless function. The fourth runs inside the database, which means it still runs on a day when the website does not.
Four rules, enforced where every caller has to pass.
These are not conventions the team tries to follow. They are constraints in the database, so a surface that wanted to render a friendlier version of the truth would have to get past them first, and it cannot.
Error is never a pass
A check that could not run reports an error, not zero findings. A failed run carries no score at all, enforced by a database constraint, so no screen can render one. The report shows a dash and the word unknown, because an unknown is a thing you act on and a low number is a thing you argue with.
Coverage travels with the score
The share of the estate that reported is stored beside the number and printed beside it everywhere it appears. Ninety six on forty percent of a business is not a ninety six, and the insurable test folds coverage into itself so the question cannot be asked without it.
An accepted risk expires
Any finding somebody decides to live with carries an expiry, capped, with no permanent option. When it runs out the finding returns to the open list by itself rather than waiting for anyone to remember it.
Findings carry locations, never secrets
The secrets check reports that a credential exists at a path and a commit. It never reports the credential. Redaction runs on the collector and again on the server, and the database caps the field as a blunt backstop.
A dated report, at a link only you were given.
The report is a live page rather than a file emailed once, so it shows the run it describes rather than the run somebody last remembered to export. It prints as a dated PDF, which is the copy you hand to a client, a buyer, or an insurer.
The score, and the coverage, at the same size
One number for the estate, the share of it that was measured beside it, and the sensors that did not report named individually with the weight each one took with it.
Findings a person can act on
Each one carries where it is, what it means for you, and what closes it. Ranked so that anything an untrusted caller can already reach sits at the top, rather than sorted by a severity label a tool assigned.
The insurable line, against your bar
A complete run, full coverage, and a score at or above the threshold written into your own record. All three, or the answer is no. Your threshold is yours, and it is not somebody else’s number applied to you.
A link that expires by itself
The report opens from a sealed link, not from a guessable address, and the link runs out on its own. Ask for a new one and the old one stops working.
One thing to be plain about the word insurable: it is our own internal threshold, not an insurer’s. No insurer has reviewed or endorsed it, it is not an underwriting decision or a representation about anyone’s insurability, and Teal Apex Solutions LLC carries no professional liability or cyber liability insurance.
Open the sample report to see the shape before you buy one. Its findings are fabricated and it says so at the top.
Three depths. One of them closes itself.
The entry tier is a fixed price because its scope is fixed: one site or one app. Above that, scope is the whole question, so the price is confirmed after a short scoping call rather than guessed at before one.
Security Scan
One site or one app, already live or about to be.
- Every row-level security policy read as SQL, table by table, because a policy that resolves to true passes every automated lint
- A live isolation test: we sign in as one account and try to reach another account's records
- Your client bundle searched for the service-role key, which bypasses every policy you wrote
- Your pinned framework version mapped against published advisories, including the ones that bypass middleware
- Every finding ranked by how exploitable it is today, with the failure scenario and the specific fix
- Dated PDF report you can hand to a client or an insurer
- One free re-test after you ship the fixes
Security Review
An app with accounts, a database, and an API. Where the money and the records are.
- Everything in the Scan
- Authentication and session handling, end to end
- Database row-level security and policy review, table by table
- API and server route review, including what fails open
- One re-test after you ship the fixes
Deep Security Review
A portfolio of apps, or one multi-tenant product where one tenant must never see another.
- Everything in the Review, across every app in scope
- Tenant isolation testing: can customer A reach customer B's data
- Secrets, build pipeline, and deploy configuration
- A prioritised remediation plan your team can work through
- 30 days of re-tests as fixes land
8 areas, and the hours are printed against each one.
About 12.5 to 14 hours of senior review. An area with nothing found is not an area that was skipped: the clean ones are listed in your report on purpose, because looked at it, it was fine is information you paid for.
Identity and session
1.0 hourWho the application thinks you are, and how hard that is to lie about.
Database and row-level security
3.5 to 4 hoursThe layer where one missing policy exposes every customer at once.
Secrets and configuration
1.5 hoursThe keys, and every path by which one reaches a browser or a commit.
Exposed surface
1.0 hourEverything reachable from the open internet that you did not mean to publish.
Browser hardening
0.75 hourWhat a single injected script is able to do once it is running on your page.
Data and transport
1.0 hourWhere customer records live at rest, and who can reach them.
Supply chain and delivery
2.0 to 2.5 hoursThe code you did not write, and the pipeline that ships it.
The report, and the re-test
1.5 hoursThe part you actually keep, and the part that proves the fixes landed.
The full checklist under each area, and the stated boundary of a review sit on the security page, where they are part of the document rather than part of a conversation nobody recorded.
What is running, and what is not.
A security practice that oversells its own coverage has argued against itself better than any competitor could. So this is the state of the thing being sold, on the date printed above, including the parts that are not in service.
- In serviceApex Muster is built and running against our own estate. The scoring, the coverage rule, the insurable line and the accepted-risk expiry all live in the database, so they apply to every caller including us.
- In serviceIt is multi-tenant. Each estate carries its own collector key, its own evidence, and its own insurable thresholds, so one client's bar can never answer another client's question.
- Not yetClient report links are not being issued yet. The report page is built and so is the expiring link that opens it, and the step that hands a client their own link is the next piece of this work rather than something running today. When it runs, the report will be a live page rather than a file emailed once, and it will print as a dated PDF.
- Not yetNo client estate is being monitored on a schedule today. Where an engagement includes Muster, the collector is set up against your estate as part of that engagement, and the cadence is written into the scope rather than assumed here.
- Not yetNone of this is a penetration test, a certification, an attestation, or an audit opinion. Where a framework requires one of those, it requires a separate qualified provider.
Find out from a review, not from a customer.
Seven questions, about four minutes. You get a private portal immediately, and a confirmed scope before anything is charged.