WitnessOps reviews

Start with the situation you need to resolve.

Choose one bounded problem. We agree the authority, inputs, scope, result, price, timing and evidence handling before review work begins. Start with a non-secret fit check. These reviews do not grant compliance certification.

A customer security questionnaire is delaying a sale or vendor review.

Customer Security Review Sprint

A response package for one questionnaire and one product scope, including proposed answers, evidence references, qualifications, open items and a cover note for your approval.

Price
From €1,600 after a non-secret fit check
Timing
Approximately three working days after scope, owners, required inputs and evidence access are confirmed
Boundary
The customer owns the final answers and submission. WitnessOps does not guarantee customer acceptance, certification or compliance.

One technical action, finding or handoff needs to be explained and supported.

Bounded Workflow Review

A bounded report or proof package naming the authority, work performed or reviewed, evidence references, limitations and unresolved items.

Price
From €1,500
Timing
Confirmed during the non-secret fit check
Boundary
The exact workflow and verification mechanism are named in the engagement. A report alone is not described as independently verified.

You need a clear, read-only picture of one authorised Linux host.

One Server Security Check

Posture, findings, report and, where agreed, a signed proof package with offline verification path — what was checked, what evidence supports it, what remains unresolved.

Price
€950 standard after a non-secret fit check
Timing
Within two business days after the authorised collection window
Boundary
No exploitation, secret collection, compliance certification, or host-security guarantee. One named host, read-only, authorised collection only.

See what one public-facing system exposes from the internet.

External Exposure Assessment

Manually reviewed, evidence-linked findings with practical remediation guidance.

Price
€1,500 paid pilot — one public-facing domain/application
Timing
Within 3 working days after payment, accepted scope, authority, required inputs, and the collection window are confirmed
Boundary
No exploitation, credentials, destructive testing, certification, or security guarantee. Unauthenticated outside-in checks only, within the agreed fixed scope.

You need a before/after decision for one launch host and an approved baseline.

Launch Readiness Check

Baseline and candidate snapshots, drift notes, findings, readiness report and, where agreed, a signed proof package with offline verification.

Price
€2,500–€7,500
Timing
Four business days after candidate collection
Boundary
No launch approval, security guarantee, remediation, or arbitrary cloud review. Bounded readiness package only.

You need a bounded review of custody or wallet-operations controls without touching funds.

Key, Access and Custody Review

Sanitised posture, completeness notes, findings and, where agreed, a signed proof package — supported claims vs gaps, no keys or balances in the package.

Price
€3,000–€15,000
Timing
Confirmed during the non-secret fit check
Boundary
No keys, seed phrases, balances, fund movement, taking custody, or solvency claim. Documentation and agreed non-secret observations only.

You need a bounded readiness record for one named incident scenario and environment.

Incident Readiness Review

Sanitised readiness observations, posture, findings and open gaps in a package another owner can inspect — not live incident command.

Price
€5,000–€25,000
Timing
Confirmed during the non-secret fit check
Boundary
No hack-back, exploitation, destructive testing, live incident command, secret intake before handling is agreed, compromise claim, root-cause or attribution.

Shared service principles

One bounded scope

The engagement names what is included, what is excluded and where authority stops.

No secrets first

The fit check uses plain-language, sanitised information only.

A checkable result

The delivery names the evidence references, receipt or verifier where one exists, and the limitations that still apply.

Methods under the package — not infinite product cards

WitnessOps maintains a large operator toolkit: collectors, validators, feed cross-checks, dependency lookups, receipt packaging and more. Those scripts are methods. The catalog only lists buyer situations with a handover package — not one card per capability.

Choose by situation

Pick the bounded problem you need to resolve. Scope, authority, price and exclusions are agreed before substantive work.

Tools stay inside the package

Whatever checks run for the engagement stay named in the deliverable with limits. A script is never sold as “you are safe.”

Inspect labelled examples

Samples show how methods land in a package. They are not live customer evidence or a product catalogue of every tool.

Not sure which review fits?

Describe the situation without files, secrets, credentials, logs, screenshots or customer evidence. The first step only checks fit.

Start a review

Start a review

Primary route: /review/request

Fallback contact: engage@mail.witnessops.com

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.