๐Ÿ” Security Audit

Find Your Vulnerabilities
Before Attackers Do

Automated scanning + expert review of your web-facing attack surface. Security headers, SSL, DNS, subdomains, exposed files, and JS secrets โ€” full written report with evidence and exact fixes.

Written report ยท Screenshot evidence ยท Fix verification included ยท Web surface only

Every check we actually run

These are real, automated checks we run on your domain โ€” not marketing bullets. Every finding includes the exact evidence we found.

๐Ÿ›ก๏ธ

Security Headers

CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and CORS. We check presence and validate values โ€” like whether CSP allows unsafe-inline or HSTS has a too-short max-age.

๐Ÿ”’

SSL/TLS Configuration

Certificate validity, days until expiry, negotiated protocol (TLS 1.0/1.1 flagged), cipher strength, and whether HTTP correctly redirects to HTTPS. We verify the full chain.

๐Ÿ“‚

Exposed Files & Paths

We probe 40+ common sensitive paths: .env, .git/config, wp-config.php, phpinfo.php, backup archives, admin panels, .htpasswd, and Dockerfile. Any that return HTTP 200 are flagged with severity.

๐Ÿ“ง

DNS: SPF, DMARC & DKIM

We query your DNS records and validate SPF (including dangerous +all wildcards), DMARC policy enforcement level, and DKIM presence across common selectors. Missing or misconfigured records enable email spoofing from your domain.

๐ŸŒ

Subdomain Discovery & Takeover

We enumerate subdomains via Certificate Transparency (crt.sh) and check each for takeover fingerprints โ€” GitHub Pages, Vercel, Netlify, S3, Azure, Heroku, and more. A dangling CNAME pointing to an unclaimed service is an open door.

โš™๏ธ

JavaScript Secret Scanning

We fetch and scan your JS bundles and inline scripts for embedded API keys, tokens, passwords, and secrets. We check for Google API keys, AWS access keys, Stripe secrets, GitHub tokens, Slack tokens, SendGrid keys, and more.

๐Ÿ–ฑ๏ธ

Clickjacking Protection

We verify that your site cannot be embedded in an iframe on a third-party domain โ€” checking for X-Frame-Options: DENY and CSP frame-ancestors directives.

๐Ÿ”—

HTTP Redirect Chain

We follow your redirect chain from HTTP and flag long chains (3+ hops), redirects that pass through plain HTTP mid-chain, and mixed-content redirect issues.

๐ŸŒ

Server Information Disclosure

Server header version leakage and X-Powered-By technology disclosure โ€” both tell attackers exactly what vulnerabilities to target.

Honest Scope โ€” What This Covers and What It Doesn't

โœ“ What We Audit
  • Your public-facing website and subdomains
  • HTTP response headers from your servers
  • SSL/TLS certificate and protocol config
  • DNS records (SPF, DMARC, DKIM)
  • Exposed files at common sensitive paths
  • Client-side JavaScript (bundles + inline)
  • Subdomain takeover via CT log enumeration
  • Redirect chain and clickjacking protection
โœ— What This Is Not
  • Internal network or infrastructure pentesting
  • Social engineering or phishing simulation
  • Physical security assessment
  • Manual exploitation of application logic
  • Database or backend code review
  • Authentication bypass testing

Need manual penetration testing? See our Pentest page โ†’

Automated scan + expert review

Our tool runs the checks. A human reviews every finding before it goes in the report.

1

You send us your domain

That's it. No credentials, no access, no installs. We work from the outside โ€” the same view an attacker has.

2

We run the full audit

Our audit tool runs all checks automatically: headers, SSL, DNS, subdomains, exposed files, JS secrets. Takes 10โ€“30 minutes per domain.

3

Expert review

We review every finding, remove false positives, add context, and rate severity based on actual exploitability โ€” not just automated output.

4

Written report delivered

You get a full HTML + Markdown report with evidence screenshots, severity ratings, and copy-paste fix instructions for every finding.

5

Fix and verify

Make the fixes. We rerun the checks and issue written confirmation that each issue is closed. No open questions left.

A report you can actually act on

Not a raw scanner dump. A real report reviewed by a human before it reaches you.

โœ“

Full Written Report

Every finding documented with severity rating, evidence, business impact context, and step-by-step fix instructions.

โœ“

Evidence for Every Finding

Exact HTTP responses, header values, DNS record data, and JS snippets โ€” nothing is claimed without proof.

โœ“

Copy-Paste Fix Instructions

Exact config lines, header values, DNS record formats, and code changes. Your developer can implement each fix directly.

โœ“

Retest Included

After you fix the findings, we rerun the audit and issue written confirmation. Every closed issue is verified, not assumed.

โœ“

Executive Summary

Plain-language overview for non-technical stakeholders โ€” risk posture, critical findings, and recommended priority order.

โœ“

HTML + Markdown Format

Reports in both formats. HTML for sharing with clients and stakeholders. Markdown for your engineering team and docs.

Every finding rated by real-world exploitability

Critical
Immediate exploitation risk. Exposed credentials, subdomain takeover, expired cert.
High
No clickjacking protection, missing HSTS, missing SPF/DMARC, wildcard CORS.
Medium
CSP with unsafe-inline, DMARC set to p=none, short HSTS max-age.
Low
Missing Referrer-Policy or Permissions-Policy, server version disclosure.

Flat rate. No surprises.

You know exactly what you're getting and what you're paying before we start.

Starter
$497

Core web surface audit for any site

  • Security headers (all 6 headers)
  • SSL/TLS cert + protocol check
  • Exposed sensitive files (40+ paths)
  • DNS: SPF, DMARC, DKIM
  • Subdomain discovery + takeover check
  • JS secret scanning
  • Clickjacking + redirect chain
  • Written report with evidence
  • One retest included
Get Starter Audit

Most sites have at least one high-severity finding.

Most owners never know. Send us your domain and we'll show you what's there โ€” written report, evidence included, fixes provided.

Get a Security Audit

Starter $497 ยท Pro $997 ยท Retest included ยท Web surface only, no credentials needed