Free assessment
Free external security assessment
We look at what an attacker can see of you from the outside and send back what we find. No charge and no obligation.
Ask us to run it
Happy to take a look. Where should we start?
Four short questions, and only so we know where to look and where to send the findings. There is no charge and no obligation to do anything with what we send you.
Entirely passive and external. We will not touch anything that needs your authorisation. Findings go to your named contact only, are never published, and your details are not sold, shared or added to a mailing list.
What you tell it
- Your primary domain
- Any other domains or brands you want included
- A contact who can receive the findings
What you get back
- Exposed services, admin panels and forgotten hosts we could reach
- Certificate, DNS and email authentication problems, including SPF, DKIM and DMARC
- Credentials belonging to your domain found in public breach data
- A short written summary of what we would fix first and why
How we run it
- 1
Entirely passive and external. We do not touch anything that would need your authorisation.
- 2
Run by an engineer, not just a scanner. The write up is written by the person who looked.
- 3
Nothing is published and nothing is shared. Findings go to your named contact only.
- 4
If we find something genuinely serious we call you rather than waiting for the report.
Where this stops being useful
This is reconnaissance, not a penetration test. It shows you the outside of the building. It says nothing about what is happening inside it.
Other tools
- Compliance effort estimatorWork out roughly how many person days a certification will take your team before you commit to a date.Open it
- Compliance cost estimatorA budget range for getting certified and staying certified, with the recurring costs people forget until year two.Open it
- VAPT and security testing cost estimatorPrice a penetration test properly, by counting the things that actually drive effort rather than by counting IP addresses.Open it
What this assessment actually looks at
It examines what an attacker can see from outside without touching anything they should not: your externally resolvable names, the services answering on them, certificate and transport configuration, email authentication posture, and whether anything is exposed that looks like it was not meant to be.
That is a genuinely useful picture and it is deliberately a narrow one. Everything here is passive or low touch reconnaissance against assets you own. No exploitation, no authenticated access, no attempt to reach anything behind a login.
We are explicit about this because the phrase free security assessment is used across the industry to mean anything from a full test to a sales call with a report template. Knowing the boundary is what makes the output trustworthy.
What it reliably finds
- Subdomains and services that are exposed and forgotten, which is the most common finding on any estate
- Email authentication left incomplete, most often DMARC at p=none years after SPF and DKIM were done
- Transport security misconfiguration and certificates approaching expiry
- Administrative interfaces reachable from the internet that were meant to be internal
- Software versions in banners that indicate an unpatched position
- Inconsistency between your asset register and what is actually resolving
What it cannot find, and why that matters
Everything that requires being inside. Authorisation flaws between accounts, business logic abuse, privilege escalation, and anything reachable only with a valid session. In our engagements those are the findings that change launch dates, and none of them are visible from outside.
It also cannot tell you whether a finding matters. An exposed service is a fact; whether it is a risk depends on what it reaches, and that requires understanding your architecture.
So treat the output as a starting position rather than a security posture. An estate that comes back clean here can still be seriously exposed, and we would rather say that plainly than let a clean external result be mistaken for assurance.
What happens with the result
You get the findings, with what each one is and what to do about it, whether or not you engage us afterwards. The report is yours.
If we find something urgent, you hear about it immediately rather than in a scheduled follow up. That is not a sales tactic, it is the only defensible way to handle it.
The follow up conversation, if you want one, is thirty minutes with an engineer about what the results mean and what would be worth testing properly. Occasionally that conversation concludes that nothing is, and we would rather say so than scope work to fill a proposal.
What we do with your details
We need a contact and the domains you want looked at. That is genuinely all, and the details go to an engineer rather than into a sequence of marketing emails.
We only assess assets you tell us you own. If a domain in the list does not appear to belong to you, we ask before touching it rather than assuming, because testing something you do not control is not ours to authorise.
The findings are yours whether or not you engage us afterwards, and if we find something urgent you hear about it immediately rather than in a scheduled follow up.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












