How it works
From the initial scoping conversation to the post-remediation re-test, every phase of a SurfaceShield assessment is predictable, transparent, and non-destructive.
Written authorization precedes every packet
We never probe arbitrary targets or launch unannounced tests. Mutual authorization ensures legal compliance, protects third-party hosting terms, and prevents accidental interference with production services.
Understand
We begin with a brief exploratory review of your business operations. What web properties do you own? Do you operate an online store, customer portal, or public APIs? Where are your primary DNS records hosted?
Scope
Every assessment requires an explicit, bounded target schedule. We catalog all relevant subdomains, IP ranges, and services. We explicitly separate customer-owned assets from shared multi-tenant SaaS providers.
Authorize
Both parties sign a formal Authorization to Test agreement. This legal document establishes testing windows, emergency contact protocols, authorized source IP addresses, and explicit boundaries.
Assess
We execute polite, observational scans and manual evaluations across the approved perimeter. We test DNS integrity, mail protocols, TLS suites, open ports, application security headers, and information leakage.
Report
You receive the finished assessment report. We hold a 1:1 video consultation with your leadership and technical staff to explain findings, business impact, and answer questions directly.
Verify
After your developers implement the recommended patches or firewall rules, we conduct a targeted verification re-scan to confirm the exposure has been successfully resolved.
Initiate your assessment lifecycle
We will review your public digital footprint and draft an authorized target schedule for your review.