How an external assessment works
We start where an attacker starts: your public-facing footprint. The difference is we report to you, safely, and tell you how to close the gaps.
- 01
Authorisation
Before anything runs, you sign a short authorisation confirming you own the domain and giving us permission to test it. This is a hard gate: no signed authorisation, no scan. It protects both of us.
- 02
Discovery
We find every system connected to your name: subdomains, mail servers, cloud services, forgotten staging sites. Most owners are surprised how much is out there.
- 03
Fingerprinting
For each live system we identify what software and versions are running, what ports are open, and how your email and domain are configured. All passive: we look, we do not touch.
- 04
Checks
We run non-intrusive checks for known weaknesses (published vulnerabilities, misconfigurations, exposure). Denial-of-service and anything that risks availability is excluded by default.
- 05
Human review
For paid assessments, an engineer reviews every finding to remove false positives and add the context a scanner cannot: what it means for your business, and what to do first.
- 06
Report
You get a ranked, plain-English report. Free tier is the automated snapshot; paid tiers add verification, remediation guidance, and a re-test.
Start with your domain.
One second, no signup. Then take the full free snapshot from the result.
Check my domainPrefer to talk it through first? Book 25 minutes