External Exposure Assessment
See what the internet sees.
A manually reviewed outside-in security review of one authorised public-facing system.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
For SaaS teams facing an enterprise security request, a recent launch or infrastructure change, or an upcoming pentest.
What we review
- One authorised public-facing system, identified by a domain, application, API, public IP, or public cloud endpoint.
- One public-facing domain or application, with up to 10 first-party hostnames, 3 customer-attributed public IP addresses, and 20 public service endpoints inside that accepted boundary.
- If we discover related assets outside the agreed boundary, we can record them, but we won’t test them without explicit authorisation.
- Public cloud-hosted services can be included when they are reachable from the internet and belong to the agreed system. Cloud accounts, IAM, private networks, and provider infrastructure are not reviewed.
- passive discovery plus explicitly approved low-impact DNS, TLS, HTTP(S), service-identification, and allowlisted exposure checks
- unauthenticated, outside-in perspective only
What you receive
- authority, scope, approved-check, exclusion, and stop-condition record
- external exposure map for the confirmed scope
- prioritised findings linked to observation evidence
- remediation guidance and explicit unknowns
- buyer-readable executive report and technical appendix
- evidence manifest and artifact hashes
- signed receipt and offline verifier where the supported path is produced
- 45-minute handover and one focused retest within 30 days
How it works
1. Request
Tell us what public-facing system you want reviewed and provide your authority to request the review. Do not send secrets or production evidence.
2. Scope acceptance
WitnessOps accepts or rejects the boundary asynchronously, confirms capacity, and records payment. No sales call is required.
3. Review
Perform only the accepted passive and low-impact checks, then manually validate, deduplicate, prioritise, and link findings to evidence.
4. Delivery and retest
Deliver the reports and inspection package within three working days after every start condition is complete, then retest the agreed reported findings once within 30 days.
What is claimed
This review produces a bounded outside-in picture of one authorised public-facing system: what was checked, which observations support the findings, and what remains unknown. It is not a penetration test, certification, or proof that the system is secure.
How to inspect the result
Inspect the delivered scope record, reports, evidence manifest, artifact hashes, and — where the supported path is produced — the signed receipt and offline verifier. Package integrity does not prove security or completeness.
Boundaries
- No exploitation, authenticated application testing, password testing, brute force, credential collection, social engineering, denial of service, destructive activity, persistence, malware, customer-data collection, or data exfiltration.
- No source-code, mobile, smart-contract, cloud-account, IAM, private-network, provider-infrastructure, or open-ended subdomain or IP-range review.
- This is not a penetration test, compliance certification, security attestation, or guarantee that the system is secure, complete, compliant, or free of vulnerabilities.
- Targets outside the confirmed first-party scope remain untouched. Third-party or shared infrastructure requires separate written authority.
Not included
- exploitation or credential attacks
- authenticated application testing
- destructive or denial-of-service testing
- customer-data collection
- internal, cloud-account, source-code, mobile, or smart-contract review
- open-ended asset discovery
- compliance certification or a security guarantee
Start a review
Primary route: /review/request
Fallback contact: engage@mail.witnessops.com
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.