Whatever is reachable from the outside gets found, by vulnerability search engines as much as by automated attacks. A security scan shows you that picture before others use it.

What we check

  • External attack surface: domains, subdomains, open ports, exposed services, forgotten test systems.
  • Web applications: known vulnerability classes, outdated components, misconfigurations, security headers, TLS.
  • Mail security: SPF, DKIM, DMARC and MTA-STS, so your domain cannot be abused for phishing against others.
  • Public traces: credentials in leaks, leftover source code, metadata in published documents.

How it works

  1. Scoping: together we define which systems are in scope and obtain your written authorisation.
  2. Scan and verification: automated checks, then manual confirmation of every relevant finding. No raw 400-line dumps.
  3. Report and walkthrough: findings by severity, with evidence and a concrete fix. Delivered as tickets on request.
  4. Re-scan: after remediation we verify and document the new state.

What you do not get

No penetration test with active exploitation and no social engineering against your staff. For the latter there are phishing simulations with AutoPhish.

Ask about this service