See what an attacker sees

We run a black-box security scan against your public surface and send you the findings. No agent to install, no access to your infrastructure — only what is already reachable from the internet.

Request a scan

Two steps: your details, then a code we email to confirm the address.

Your email address has to be on the same domain as the target. That is how we confirm you can authorise the test — a personal address on a free provider cannot be accepted.

How it works

Four steps, and a human reviews every report before it reaches you.

  1. 01

    Request

    Tell us the target and confirm you are authorised to have it tested. We only accept a work email on the target's own domain.

  2. 02

    Verify

    We email a six-digit code to that address. Entering it proves you control a mailbox at the domain you asked us to scan.

  3. 03

    Review

    Nothing runs automatically. An engineer reads the request and starts the scan by hand — the approval gate is a person, not a queue.

  4. 04

    Report

    You get the findings with severity, evidence and a remediation note for each one. We review the report before sending it.

What we test

A black-box pass over your public surface, from the outside, with no credentials.

In scope

  • TLS configuration, certificate chain and protocol support
  • Security headers, cookie flags and CORS policy
  • DNS hygiene, SPF, DKIM and DMARC records
  • Exposed paths, directory listings and stale endpoints
  • Known CVEs in fingerprinted, publicly visible components
  • Subdomain enumeration and dangling-record takeover risk

Out of scope

  • Anything requiring credentials or a session
  • Denial-of-service and load testing
  • Social engineering and phishing against your staff
  • Physical security and on-premises assessment
  • Third-party services you do not control
  • Any host other than the one you named and authorised

Active security testing without authorisation is unlawful in most jurisdictions. That is why we require a work email on the target's own domain and an explicit authorisation before anything runs, and why an engineer approves every scan by hand.