The findings from outside
We go through the free check with you first: what is visible, what it means, and what fixing it takes. Most of these fixes take minutes once they are named.
The security review finds what an attacker or a mistake would find first, and puts the fixes in order.
It starts from the outside, with no access to anything of yours, and goes only as deep as you choose. We never ask for your passwords. When the review goes inside, you drive and we read.
Send us your website address. We read what is public, the way an attacker reads it, and email you what we find within two working days.
What the check covers: whether anyone can send email that carries your name, whether your site's encryption is current and set up properly, which software versions your site shows in public and whether any of them has known holes, whether an old subdomain still points at a server you no longer control, and whether anything is reachable that should not be, like a backup file or a configuration file.
Ask for one check and you get all three: tracking, security and site health, run together on your address, one set of findings by email.
Nothing is installed and nothing is attempted. The check reads public records and loads pages the way a browser does, so it does not break or slow anything.
Already have your findings? Leave a number and we go through them with you, whether or not you fix them with us.
We go through the free check with you first: what is visible, what it means, and what fixing it takes. Most of these fixes take minutes once they are named.
Screen shared, you drive, we read. Who has admin on what. Whether two-step sign-in is on for the accounts that matter. Which apps were granted access to your mailbox and your files, and when. Where your customer data actually sits, and what access a person keeps after they leave.
Each one says what it exposes, what fixing it takes, and who can do it. Some you fix in an afternoon, some we fix, some can wait. The list says which is which.
The records that stop it are missing or wrong. Someone can invoice your clients from an address that carries your name, and most mail systems will deliver it.
The version is readable in public, and the list of what it is vulnerable to is public too. Attacks against these are automated. Nobody has to choose you to find you.
A server was switched off and the address still points at where it was. Whoever gets that spot next can put a page there that carries your name.
A former employee still has admin somewhere. An app authorised years ago still reads the mailbox. Each one is a door that is not being watched.
We do not attempt to break in. No password guessing, no attacks on your systems, nothing that touches what runs.
We do not certify anything. If your bank, your insurer or a large customer requires a certified penetration test, this review is not that. We will say so and point you at people who do it.
And we do not hold your credentials. Where a check genuinely needs an account, you create it in your own console, scoped to read only, and you revoke it when we are done.
Most findings are small once they are named, and the list says which ones matter first.
You can fix them yourselves from the list. We can do the fixes, quoted per project. And the outside check can be re-run on a schedule, so you hear when something changes instead of finding out later. That re-run is part of a care plan.
| What | Cost |
|---|---|
| The outside check: email records, encryption, versions, exposure | No charge |
| The full review: the session, the findings in writing, in order | Quoted per project |
| The fixes, where we do them | Quoted per project |
| The outside check re-run on a schedule, with an alert on change | Part of a care plan, from R7,000 a year |
What moves the price: how many systems you run, how many people have accounts, and whether your customer data sits in one place or five. The number is in the proposal before anything starts.
The numbers, in one place
No, and we will not take them. The free check reads only what is public. In the full review you drive your own screens and we read. Where a check needs an account, you create a read-only one in your own console and revoke it afterwards.
Nobody has to pick you. Most of what reaches a small business is automated: software scanning every address on the internet for a known hole, then reporting where it found one. The question is not whether you are interesting. It is whether anything of yours is on that list.
No. It reads public records and loads pages the way a browser does. Nothing is installed and nothing is attempted. Your site cannot tell the check from a visitor.
No. A penetration test attempts break-ins under contract and ends in a certificate. This review reads what is reachable, sits beside you inside your own accounts, and gives you the list in plain words. If you are asked for a certified test, we say so and step aside.
The next step
Email records, encryption, software versions and what is exposed, in your inbox within two working days, in plain words.