Exposed surface
Open ports, forgotten subdomains, admin panels, debug pages and files that should not be public.
An audit of your website, servers and APIs, written up as a report you can act on: what is exposed, what is out of date, what is misconfigured — ranked by risk, each finding with its fix. Then, if you want, I apply the fixes, test your APIs the way an attacker would, and keep watching.
A fixed-price look at what an outsider can see and what a careless default can open. No agent to install: public checks plus read-only access you grant for the review.
Open ports, forgotten subdomains, admin panels, debug pages and files that should not be public.
Certificates and protocols, security headers, DNS, and SPF, DKIM and DMARC so nobody sends mail as you.
SSH and firewall configuration, brute-force protection, users and permissions, services running that do not need to be.
WordPress core, plugins and themes, packages and runtimes checked against known vulnerabilities (CVEs).
Logins, roles, two-factor, API keys and tokens, secrets sitting in code or in public files.
Do they exist, are they off-site and encrypted, and has anyone ever restored one.
The report ranks every finding by risk and gives the fix for each. One website or application and its server; larger estates are quoted after a short scoping call.
Each of these is quoted per scope, usually from the audit findings.
The fixes from the report, applied and verified: configuration, updates, access, headers, backups. You get a before-and-after.
Your APIs and authentication tested the way an attacker would, against the OWASP API Security Top 10: broken authorization, token handling, rate limits, data exposure.
Monthly: CVE watch on your stack, patches staged before production, a patch report, emergency patching for critical advisories.
The basic audit report is $1,500 CAD. Tell me what you run and I will confirm the scope before anything starts.
This site uses Google Analytics to count visits. It loads only if you accept. Details in the privacy policy.