HikmShield

Know exactly where you stand on security.

Fixed-price security assessments and plain-English reports for whatever you run: AI systems, patient data, DoD contracts, insurance renewals, the code you ship. Prices on the page.

Proprietary Engine + Expert Review

56
Engine Rules
22
Categories
A–F
Letter Grade
5 Days
Full Review
A precision mechanism of nested calibrated rings, one component lit from within

The HikmShield Engine

The Engine Runs the Checks. Its Author Makes the Calls.

Proprietary, built in-house, and the pre-deploy gate on every project Hikm ships.

Engine Scan

56 rules across 22 categories of JS/TS code, OWASP-mapped. Deterministic, reproducible.

Expert Review

The person who wrote the rules reviews what a scanner cannot, on any stack.

Report

Letter grade, prioritized fixes, plain English. Free re-scan verifies your fixes.

22 Categories

SecretsRLSAuthValidationAccess controlInjectionPath traversalXSSCSRFDependenciesRate limitingWebhooksCryptoJWTLLM injectionCookiesAI securityCORSFile uploadExposureSilent failuresHeaders

The Report Is the Product. Read One First.

The engine generated this report from a demo app seeded with known vulnerabilities. Baseline Scan shown.

HikmShield Security ReportGrade F
  • critical — hardcoded Anthropic API key in source
  • high — dangerouslySetInnerHTML without visible sanitization
  • medium — LLM API call without max_tokens
  • … 68 more findings, each with location + fix
Three machined metal blocks of ascending height, the middle one outlined in green

Fixed Prices, Published.

Between a $200 automated scan and a five-figure penetration test.

Four unmarked instrument bezels in a metal panel, one lit green

Assessments

Expert-led assessments of whatever needs assessing: AI deployments, HIPAA, CMMC Level 1, cyber insurance. Each delivered as the same engine-built graded report. See a Sample Assessment.

AI Deployment Security

A chatbot, agent, or automation in production.

$5,000

7 business days

Prompt injection, tool permissions, data flow, cost controls. Mapped to the OWASP LLM and Agentic Top 10.

Book This Assessment

HIPAA Security Risk

Dental, therapy, chiro, specialty clinics.

$3,500

10 business days

The Security Rule risk analysis 45 CFR 164.308 requires, and the gap OCR cites most.

Book This Assessment

CMMC Readiness

DoD suppliers holding federal contract information.

$4,500

10 business days

MET or NOT MET on all 15 Level 1 requirements, plus an SPRS submission walkthrough.

Book This Assessment

Cyber-Insurance Readiness

Facing a carrier questionnaire or renewal.

$3,000

7 business days

MFA, EDR, backups, email auth: the controls carriers gate coverage on. We prepare the evidence; your broker places the coverage.

Book This Assessment

Code Review

Next.js + Supabase first; Express and TypeScript/Node covered.

Baseline Scan

$500

2 business days

  • 56-rule engine scan, OWASP-mapped
  • Letter-graded report, findings ranked, each with a fix
  • $500 credited toward a Full Review within 30 days
Book Baseline Scan
Flagship Review

Full Review

$1,800

5 business days

  • Everything in Baseline Scan
  • Author-led review: RLS logic, auth flows, business logic
  • Remediation plan plus optional walkthrough call
  • Free re-scan within 30 days
Book Full Review

Review + Fix

$4,000

10 business days

  • Everything in Full Review
  • Critical and high findings fixed by us, one repo
  • Verification re-scan, updated grade
Book Review + Fix

Reviews and assessments, not penetration tests or certifications. No active exploitation.

There is no “HIPAA certified.” We are not a C3PAO; only your SPRS affirmation or a C3PAO assessment creates a CMMC status.

You get documented evidence: act on it, attach it to a questionnaire, or hand it to a carrier or regulator.

You Talk to the Person Who Built the Engine.

Hikm Systems builds and runs it. The engineer behind the engine writes every finding.

A jeweler's loupe and a machined part resting on a dark workbench
Is this a penetration test?

No. Non-destructive checks plus expert analysis. Attach the report to a security questionnaire as evidence.

What do you need from me?

Repo read access for reviews. Policies and an hour of walkthrough for assessments.

What happens to my code?

We scope access to the review and remove it after delivery.

Ship It Knowing What's in It.

Tell us what you run. We reply within one business day.