§ 00 / services / security

Security. Find the holes before someone else does.

An audit of your website, servers and APIs, written up as a report you can act on: what is exposed, what is out of date, what is misconfigured — ranked by risk, each finding with its fix. Then, if you want, I apply the fixes, test your APIs the way an attacker would, and keep watching.

what it is
security audit, hardening and testing
audit report
$1,500 CAD
deliverable
written report, findings ranked by risk
scope
websites · servers · APIs · WordPress
beyond
hardening · pentest · monitoring, on quote
AI
chatbot, LLM and MCP endpoints reviewed too
§ 01 / basic audit report

One report, $1,500 CAD.

A fixed-price look at what an outsider can see and what a careless default can open. No agent to install: public checks plus read-only access you grant for the review.

01 /surface

Exposed surface

Open ports, forgotten subdomains, admin panels, debug pages and files that should not be public.

02 /tls

TLS, headers, email

Certificates and protocols, security headers, DNS, and SPF, DKIM and DMARC so nobody sends mail as you.

03 /server

Servers

SSH and firewall configuration, brute-force protection, users and permissions, services running that do not need to be.

04 /deps

CMS and dependencies

WordPress core, plugins and themes, packages and runtimes checked against known vulnerabilities (CVEs).

05 /auth

Access and secrets

Logins, roles, two-factor, API keys and tokens, secrets sitting in code or in public files.

06 /backup

Backups

Do they exist, are they off-site and encrypted, and has anyone ever restored one.

The report ranks every finding by risk and gives the fix for each. One website or application and its server; larger estates are quoted after a short scoping call.

§ 02 / beyond the report

Fix it, test it, keep it fixed.

Each of these is quoted per scope, usually from the audit findings.

01 /harden

Hardening

The fixes from the report, applied and verified: configuration, updates, access, headers, backups. You get a before-and-after.

02 /pentest

Pentest and API testing

Your APIs and authentication tested the way an attacker would, against the OWASP API Security Top 10: broken authorization, token handling, rate limits, data exposure.

03 /watch

Ongoing monitoring

Monthly: CVE watch on your stack, patches staged before production, a patch report, emergency patching for critical advisories.

§ 03 / how it works

Four steps, no surprises.

1 · scope
a short call to agree what is in the audit
2 · access
public checks, plus read-only access you grant and revoke
3 · report
findings ranked by risk, each with its fix, walked through with you
4 · next
fix it yourself, or have me harden, test and monitor it
§ 04 / next step

Know where you stand.

The basic audit report is $1,500 CAD. Tell me what you run and I will confirm the scope before anything starts.