Skip to content
Services

Security Audits

An external, non-intrusive check of what an attacker can see from outside your site, with no risk to your live service.

For businesses who want a clear-eyed external view of their exposure. This is not a penetration test, and we are precise about that difference.

Part of the £395 Baseline Review · See full pricing

What is included

  • Passive reconnaissance limited to public signals and paths the site itself links to
  • External fingerprinting of publicly exposed software and services
  • A signed scope letter agreed and filed before any check begins
  • A written report ranking findings by real-world risk, not by how alarming they sound

How we work it

  1. Agree and sign a scope letter defining exactly what is in scope, so nothing is checked without your consent
  2. Run passive, external, non-intrusive checks against the agreed scope only
  3. Never attempt authenticated testing, exploitation, denial-of-service or intrusive scanning, and never brute-force paths
  4. Write up findings in plain English, ranked by likely impact

What you receive

  • A signed scope letter on file before work begins
  • A written external security report
  • A prioritised list of findings with recommended next steps

External and non-intrusive only, in scope only, and never before a signed scope letter is filed. We report software versions as indicators, not confirmed vulnerabilities, because banner-derived versions cannot see backported patches and are often wrong.

Ready to see the data?

Start a conversation