Pentest Remediation

Turn pentest findings into fixes your team can verify.

For testing firms, fractional CTOs, and SaaS teams with an existing report. I implement agreed application fixes, check the affected behavior, and prepare clear evidence for independent retesting.

Tony St. Pierre16+ years of software development experience

Application findings, subject to review

Your report is the starting point.

When your team needs capacity to act on a report, I take on agreed application repairs. The original finding and acceptance criteria guide the work.

My focus is TypeScript/JavaScript, React and Next.js applications, and relevant AWS application and identity configuration, including authentication and sessions.

Examples of findings that may fit

  • Missing or incorrect server-side authorization checks.
  • Authentication or session-handling defects.
  • Unsafe input or output handling.
  • Scoped dependency vulnerabilities with a feasible, compatible repair.
  • Application configuration, cookie, or security-header findings.

A server-side security failure needs a repair at the relevant enforcement point. A frontend-only change is not sufficient.

  • SaaS CTOs and engineering leads

    I work with your engineers on a defined set of repairs, with reviewable changes and focused checks of legitimate behavior. We agree a schedule around your retest or customer commitment before starting.

  • Fractional CTOs and agencies

    I help establish which repairs fit a bounded engagement, what they depend on, and what needs a broader scope. Your developers receive the changes and instructions for taking them forward.

For independent pentesters and testing firms

Engineering support that respects your client relationship.

We can agree a referral or subcontract arrangement when your client needs help implementing your findings. Client-facing communication happens only as agreed.

  • One agreed technical contact

    We establish who engages me, who authorizes access, and who receives updates before work begins.

  • Keep the finding intact

    I retain your finding IDs, clarify technical questions with you, and connect each repair to the reported behavior and test conditions.

  • Keep verification responsibilities clear

    I handle the agreed implementation and internal checks. The independent testing provider determines the retest result; our quote defines my response to feedback.

What you receive

Reviewable repairs. Evidence for the retest.

Your engineers can review the repair. Your tester can trace the original finding to the change, the checks, and the remaining work.

  1. Reviewable changes

    A pull request or equivalent code and configuration changes in the authorized repositories, tied to the agreed findings.

  2. A record for each finding

    The original finding ID, what changed and its code reference, verification results and environment, remaining uncertainty or action, and current status.

  3. Focused regression checks

    Tests where practical; documented checks where automation is unsuitable. Both cover the reported behavior and agreed legitimate application paths.

  4. Deployment and rollback guidance

    Relevant release steps, configuration requirements, and instructions for reverting the changes, aligned with the agreed deployment responsibilities.

  5. Remaining actions and limitations

    Dependencies, incomplete work, and verification gaps, with the conditions and evidence needed for an independent retest.

Start with the affected areas.

Start with the stack, affected areas, and retest date. Report transfer follows a fit check.

Discuss a remediation scope

Each status has a specific meaning.

Implemented
Changes are prepared. Verification is still required.
Internally verified
I’ve checked the reported behavior and legitimate paths under the agreed conditions and recorded the results.
Ready for independent retest
Agreed checks are complete and evidence is ready for the tester. Their independent result is pending.

I do not label a finding independently retested or closed unless the appropriate testing provider confirms that result. My checks are not independent certification.

Incomplete repairs and checks blocked by access are recorded explicitly; their status reflects that limitation.

Tony St. Pierre

Your implementation engineer

Repairs your team can maintain.

I’m Tony St. Pierre. I bring 16+ years of software development experience across production web and mobile applications.

  • Identity and application boundaries

    I’ve built authentication, MFA, account recovery, and session controls, alongside multi-tenant systems and security-sensitive workflows.

  • Testing and controlled delivery

    My work includes automated testing, security analysis, penetration-testing remediation, and controlled web and mobile delivery.

AWS Certified Solutions Architect – Professional View my systems experience

Scope, price, and process

Agree the repairs before implementation.

I review the relevant findings, affected application, access requirements, and expected verification before giving a fixed quote.

Scoped remediation projects

From $3,000USD

The fixed price covers named findings and affected instances. It is not an entire-report fee or a price per vulnerability.

I prioritize work that can reasonably fit within 1–2 scheduled weeks. The schedule is agreed after scoping.

If a responsible repair quote needs substantial technical investigation, I propose a separately agreed paid investigation first.

The fixed quote makes responsibility explicit.

Findings and affected instances
Each quote names the finding IDs, components, and affected instances included. One finding may span several endpoints or roles; finding count alone does not establish effort.
Verification criteria
We agree reproduction evidence, test conditions, and acceptance criteria before implementation.
Deployment
The quote names who reviews, merges, and deploys the changes. Production deployment requires separate agreement.
Independent retesting
My agreed implementation checks are included. The quote separately names the independent retesting provider, who arranges the retest, and any separate fees.
Tester feedback and corrections
The quote defines the included response to tester feedback and how corrections against the agreed repair criteria are handled. New findings, affected instances, or requirements need separate scope.
  1. Confirm fit and scope

    I start with your summary, arrange confidential report access, then define the included findings and checks with your technical contact before quoting.

  2. Implement the repairs

    I make the agreed changes in authorized repositories and environments, preserving the finding’s technical meaning.

  3. Verify the changes

    I check that the reported behavior no longer reproduces under the agreed conditions and that legitimate behavior still works.

  4. Prepare the handoff

    I hand over the changes, finding records, verification evidence, and remaining actions for your team and the independent tester.

Additional findings, newly discovered issues, or expanded requirements receive separate scope before implementation.

Major architectural changes need a separate engagement. Broad network, Active Directory, infrastructure assessment, and mobile reverse-engineering work are outside this application-focused service.

Before we begin

A few practical questions.

Do I need an existing pentest report?

Yes: relevant report sections or equivalent finding documentation from your testing provider. Send a high-level summary first. We arrange confidential transfer after initial contact.

Can you work with our original testing provider?

Yes, with agreed authorization and communication. I clarify the reported behavior and acceptance criteria with them, then prepare evidence for their independent retest.

Can a testing firm refer or subcontract an engagement?

Yes, through an agreed arrangement for a defined scope. We establish the client’s authorization, technical contact, communication, and responsibilities before work begins.

Which stacks and findings fit?

Application-layer findings in TypeScript/JavaScript, React, Next.js, and relevant AWS application and identity configuration. Authorization, authentication, sessions, input/output handling, compatible dependency repairs, and configuration findings may fit, subject to review of the actual report.

Is retesting included?

My agreed implementation checks are included. The quote separately names the independent retesting provider, who arranges the retest, and any separate fees. The quote also defines the response to tester feedback included in my engagement. I cannot guarantee a retest result, security certification, or acceptance in an audit or customer review.

What if a repair requires broader changes?

I explain the dependency or architectural change before implementing it. Additional findings, newly discovered issues, or expanded requirements receive separate scope before implementation. Substantial investigation also requires a separate agreement.

Who handles deployment?

The quote names who reviews, merges, and deploys the changes. Production deployment requires separate agreement. Your handoff includes the relevant deployment and rollback instructions.

How is the fixed quote determined?

Projects start at $3,000. I assess the included endpoints, roles, components, checks, and response to tester feedback. Finding count alone does not determine the price. If a responsible repair quote needs substantial technical investigation, I propose a separately agreed paid investigation first.

Start with a summary

Tell me what needs remediation.

Send a short summary and your timing; technical details are optional. I’ll confirm fit, arrange confidential review of the relevant findings, then provide a fixed quote or propose a separately agreed paid investigation.

In your email, include what you know:

  • Role and company
  • Application stack (if known)
  • Affected areas (high-level summary)
  • Approximate number of findings needing help (if known)
  • Original tester available for retesting (if known)
  • Desired timing or target retest date
Discuss a remediation scope contact@tonystpierre.com

Please omit report attachments, exploit details, credentials, and customer data. After initial contact, we can agree a confidential method for transferring relevant report sections.