Passive external review
We check HTTPS, the certificate, and public domain and email settings.
Security and resilience
The first review uses public information and low-impact methods. Deeper testing starts only after the systems and boundaries have been agreed in writing.
How we work
A public signal does not prove a vulnerability by itself. The report separates confirmed observations from checks that require the company's permission.
We check HTTPS, the certificate, and public domain and email settings.
Systems, timing, and permitted methods are agreed in advance. We stay within those boundaries.
We fix confirmed issues, then check whether the change addressed the cause.
We review backups and prepare the steps needed to restore the system after an interruption.
External review
Enter the website address for a public summary. The review does not attempt authentication and does not test whether a possible issue can be exploited.
Passive review
Enter the company websiteNo review has started.External summary
Enter the company website.
Anonymous summary
We separate what was observed, what could not be confirmed, and what would require an authorized assessment.
The detailed report is private. Email verification grants access to the report; it does not authorize security testing.
The pre-authorization boundary
Business continuity and security
If your website, online shop, or internal system matters to day-to-day operations, we can check what is visible externally and what deserves a closer look. Deeper testing requires written authorization.