External Surface ReviewSecurity audit
What this package is
Basic tells you what your site is leaving open, checked entirely from the outside, without touching the inside or taking anything down.
I scan against the OWASP Top 10 categories, check the SSL certificate, security headers and configuration that opens doors, and measure the speed of the main page on both mobile and desktop. You get a PDF report ranked by severity with a fix written for each finding.
This is the cheapest and fastest thing I sell, and plenty of people use it to see how I work and how I write before committing to a five-figure job. That is what it is there for.
See it working
The scanner is free and open to anyone. It works entirely from the outside and never touches the inside of your site. What this package adds is the full report in the second tab, ranked by severity with a fix for each finding and a summary written twice, once for people and once for engineers, instead of showing three findings and locking the rest.
Both pages are live on this site rather than mock-ups. You can use them from inside the frame.
Everything you get
This list is the entire scope of the package. Nothing is hidden in a contract.
- OWASP Top 10 testing against your public site
- SSL, security headers, and settings that are open when they should not be
- Speed check on your main page, mobile and desktop
- PDF report in English, sorted by severity, with the fix written out for each finding
- Contract in English covering scope, delivery date, and who owns what I produce
- 60 days to ask me follow-up questions after handover
- Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
- A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
- Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
- Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
- Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.
Questions about this package
Will the scan take my site down?
No. This package is non-intrusive testing from the outside: it looks at what your site already exposes, without heavy traffic or any attempt to break in. If there is a window where extra traffic is unwelcome, tell me and I will work around it.
How is this different from the free scanner on this site?
The free one runs a surface version of the same checks, shows three findings and locks the rest. This package covers all of it, ranks findings by what they would actually cost your business, and writes a fix for each one that any engineer can follow. Try the free scanner in the demo on this page before deciding.
If you find something, do I have to hire you to fix it?
No. The report is written so any engineer can act on it, not so that only I can. Hand it to your own team if you have one. If you would rather I fixed it, the Fix package exists, but the report is not designed as a sales tool for it.
Is there paperwork before you start?
Yes. I require written confirmation that you are entitled to have the site tested, every time and with no exceptions even where we know each other well, because testing without permission is illegal and the document protects us both.
Could what you find leak?
No. The report goes only to the people you name. I do not turn it into a case study without asking, and if you do allow it, the name and address are removed entirely. The sample report published on this site is invented from end to end.