Authorization-first cybersecurity Lexington, KY · Remote engagements +1 (224) 974-3213

LUMEN / 01 Exposure desk

Weblume Labs

Illuminate weak points. Harden what matters.

Security audits, vulnerability assessments, authorized penetration testing, and configuration work—scoped in writing, executed with care, delivered as clear reports.

LUMEN / 02

What we place under the light

Weblume Labs LLC provides cybersecurity services that help businesses identify vulnerabilities, assess security risks, and strengthen the protection of their digital systems. Every engagement begins with a defined boundary and written authorization.

LUMEN / 03

Scope Bench

Choose a surface and an engagement mode. The bench shows what gets illuminated, what stays out of frame, and a starting price.

Surface
Mode
ILLUMINATED SCOPE

Web application · Security audit

STARTING FROM $4,500
    DELIVERABLES

    OUT OF FRAME

    Request this scope

    LUMEN / 04

    Engagements

    Starting prices reflect typical U.S. boutique cybersecurity floors for the scopes below—one revision on written recommendations included. Final quotes follow a short fit review.

    ENG-01

    Security Audits

    From $4,500

    A structured posture review of information-security controls for one defined environment—not a certification or SOC 2 attestation.

    • Control checklist across people, process, and tech in scope
    • Gap notes vs. a stated baseline (e.g. CIS-aligned expectations)
    • Written findings summary and prioritized recommendations

    Starting scope: 1 environment · ~3–5 analyst days · excludes continuous monitoring and formal certification

    ENG-02

    Vulnerability Assessment

    From $3,500

    Discovery and ranking of known weaknesses across an agreed host or URL set, with manual triage of scanner noise.

    • Up to 25 hosts or URLs
    • Authenticated scanning where credentials are provided
    • Severity-ranked findings and remediation guidance

    Starting scope: non-destructive assessment · no exploitation · not a penetration test

    ENG-03

    Authorized Penetration Testing

    From $6,800

    Human-led, permissioned testing against one target class under written rules of engagement—web app or external perimeter at the starting price.

    • Written RoE required before work
    • Typically up to 5 tester-days for the starting scope
    • Evidence-backed report plus remediation priorities

    Starting scope: 1 target class · quotes below ~$4,000 in this market are usually scans, not manual tests

    ENG-04

    Security Configuration

    From $2,800

    Hardening pass focused on protective mechanisms for one agreed stack, with a clear before/after map.

    • Baseline vs. desired configuration map
    • Hardening changes within the agreed stack
    • Operator handoff notes for your team

    Starting scope: 1 stack (perimeter, IAM, or endpoints) · ~2 analyst days · excludes ongoing admin or MDR

    ENG-05

    Recommendations & Reports

    From $1,800

    A standalone recommendations package and security report for technical and business readers. Included at no extra charge when bundled with ENG-01 to ENG-04.

    • Executive-readable summary
    • Technical finding detail
    • Remediation priority order

    Starting scope: rewrite from findings you supply or from prior work · no new testing

    ENG-06

    Remediation Planning Session

    From $2,400

    A working session that turns existing findings into an ordered, owner-assigned fix plan your team can execute.

    • One half-day remote workshop
    • 30-day written remediation plan
    • Owner and priority assignments

    Starting scope: planning only · excludes implementation of fixes

    ENG-07

    Re-test / Validation Pass

    From $2,800

    Post-fix verification that previously reported issues were addressed, under renewed or still-valid written authorization.

    • One target class re-checked
    • Per-finding status: closed, partial, or open
    • Short validation addendum

    Starting scope: 1 target class · often ~35–40% of the original test when booked after our ENG-03 · no new discovery

    ENG-08

    Security Awareness Briefing

    From $1,800

    A readout for leadership and technical staff on current exposure, risk language, and sensible next steps.

    • Executive readout
    • Technical readout
    • Slide deck and discussion notes

    Starting scope: 2 sessions · no testing · no phishing simulation campaign

    LUMEN / 05

    Method

    A short path from authorization to documented findings.

    1. 01

      Authorize

      Confirm ownership, contacts, and written permission for the systems in scope.

    2. 02

      Frame

      Lock targets, windows, intensity, and out-of-scope items before any testing begins.

    3. 03

      Illuminate

      Run the agreed audit, assessment, pen test, or configuration work inside that frame.

    4. 04

      Document

      Deliver findings, recommendations, and a report your team can act on.

    LUMEN / 06

    Boundaries

    Clarity protects both sides. Weblume Labs does not invent authority we do not have.

    • No testing without written authorization and an agreed scope
    • Not a certification body, insurer, or managed SOC
    • No 24/7 monitoring, breach response retainers, or guaranteed outcomes
    • No legal advice; compliance decisions remain with your organization
    • Destructive testing, social engineering, or physical entry only if explicitly contracted

    LUMEN / 07

    FAQ

    Do you only work with written authorization?

    Yes. Authorized penetration testing and any intrusive assessment require written rules of engagement and confirmation that you control the targets in scope.

    What do we receive at the end of an engagement?

    A written security report with findings, severity context where applicable, and prioritized recommendations. Configuration work also includes handoff notes for the changes made.

    Are the listed prices final?

    No. Listed figures are starting floors for the scopes described and sit in the typical U.S. boutique range for that work. Larger estates, cloud-heavy scopes, multi-app pen tests, or tighter windows are quoted after a short intake review.

    Where is Weblume Labs based?

    The company address is 710 E Main Street, Lexington, KY 40502. Engagements are typically delivered remotely for United States clients.

    Can you guarantee we will not be breached?

    No. Security work reduces risk and improves clarity; it does not guarantee immunity from incidents.

    LUMEN / 08

    Request intake

    Tell us what you want illuminated. We reply with fit questions and a scoped proposal—not an automated quote.

    Address
    710 E Main Street
    Lexington, KY 40502
    United States