External Security Exposure Assessment
A meticulous, evidence-backed inspection of everything your company connects to the public internet. Designed specifically for small businesses to eliminate external blind spots without operational disruption.
Perimeter & Asset Discovery
Passive DNS resolution, certificate transparency monitoring, apex domain enumeration, autonomous system correlation, and orphaned subdomain discovery.
External Network & Service Probing
Polite TCP/UDP port scanning across common administrative, remote management, database, and message broker ports. Service banner extraction and version verification.
Web Application Perimeter Analysis
Security header verification (CSP, HSTS, X-Content-Type-Options), session cookie hygiene (Secure, HttpOnly, SameSite), open directory indexing, and publicly reachable admin consoles.
Email Infrastructure & Anti-Spoofing
Syntax and alignment audit of SPF (Sender Policy Framework), DKIM public keys, and DMARC enforcement policies (p=none vs p=quarantine/reject). Identification of spoofing vectors.
Transport Layer Security (TLS/HTTPS)
Cryptographic cipher suite strength, deprecation check for TLS 1.0 and 1.1, certificate chain validity, revocation mechanism status (OCSP), and forward secrecy configuration.
Unintentional Information Disclosure
Inspection for exposed repository directories (.git), environment secret configuration files (.env), unlinked database backups, Swagger/OpenAPI interactive consoles, and verbose debug logs.
Request Your Scoping Proposal
We review your initial public domains, compile an exact target schedule, and provide a fixed-scope engagement agreement with zero sales pressure.