We run a black-box security scan against your public surface and send you the findings. No agent to install, no access to your infrastructure — only what is already reachable from the internet.
Four steps, and a human reviews every report before it reaches you.
Tell us the target and confirm you are authorised to have it tested. We only accept a work email on the target's own domain.
We email a six-digit code to that address. Entering it proves you control a mailbox at the domain you asked us to scan.
Nothing runs automatically. An engineer reads the request and starts the scan by hand — the approval gate is a person, not a queue.
You get the findings with severity, evidence and a remediation note for each one. We review the report before sending it.
A black-box pass over your public surface, from the outside, with no credentials.
Active security testing without authorisation is unlawful in most jurisdictions. That is why we require a work email on the target's own domain and an explicit authorisation before anything runs, and why an engineer approves every scan by hand.