External Attack Surface Review
See what your public-facing system exposes.
Review one authorised internet-facing system. Find unexpected exposure and misconfiguration, with evidence and remediation priorities. No exploitation. This is not a penetration test.
- Price
- €1,900 · excluding VAT
- Delivery
- Within 3 working days after payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed
No sales call required. We confirm scope and authority before work begins.
What you get
- External attack-surface map: exposed hosts, services and endpoints.
- Evidence-backed findings and prioritised remediation guidance.
- Executive report, technical appendix and explicit unknowns.
- Scope and stop-condition record, evidence manifest and artifact hashes; signed receipt and offline verifier where supported.
- 45-minute handover and one focused retest within 30 days.
Scope and limits
One authorised public-facing system. Low-impact, unauthenticated checks. This is not a penetration test.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
SaaS and technology teams preparing for a launch, customer security review or infrastructure change.
Company background
WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →
Your part in the engagement
What do you need from me?
Name one public-facing system and your authority to request the review. We confirm the target list, scope, collection window and start conditions asynchronously; no sales call is required.
What access is required?
No login to your systems: agreed low-impact checks use the public, unauthenticated surface only. Written authority is required before testing; payment alone does not authorize it.
What happens after delivery?
A 45-minute handover explains the findings. Your team implements fixes; one focused retest of the agreed findings within 30 days is included.
How the engagement works
1. Request
Name the authorised internet-facing system and why the external attack surface matters now. Provide your authority to request the review, but do not send secrets or production evidence.
2. Scope acceptance
WitnessOps accepts or rejects the boundary asynchronously, confirms capacity, and records payment. No sales call is required.
3. Review
Use passive discovery where applicable, then perform only the explicitly approved, low-impact DNS, TLS, HTTP(S), service-identification, and allowlisted exposure checks against the signed target schedule. Manually validate, deduplicate, prioritise, and link findings to evidence.
4. Delivery and retest
Deliver the reports and inspection package within three working days after payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed, then retest the agreed reported findings once within 30 days.
Full scope and exclusions
€1,900 · excluding VAT for one authorised public-facing system. No sales call required. Payment is due in full before the delivery clock starts. Payment alone does not authorise testing. One focused retest within 30 days is included; an additional or late retest is €550 · excluding VAT.
- One authorised public-facing system, identified by a domain, application, API, public IP, or public cloud endpoint.
- Inside that accepted system boundary: up to 1 registrable root domain, up to 10 first-party hostnames, 3 customer-attributed public IP addresses, and 20 public service endpoints.
- If we discover related assets outside the agreed boundary, we can record them, but we won’t test them without explicit authorisation.
- Public cloud-hosted services can be included when they are reachable from the internet and belong to the agreed system. Cloud accounts, IAM, private networks, and provider infrastructure are not reviewed.
- It uses passive discovery where applicable, followed by explicitly approved, low-impact checks against the signed target schedule.
- Approved low-impact classes are DNS, TLS, HTTP(S), service-identification, and allowlisted exposure checks.
- unauthenticated, outside-in perspective only
- No exploitation, authenticated application testing, password testing, brute force, credential collection, social engineering, denial of service, destructive activity, persistence, malware, customer-data collection, or data exfiltration.
- No source-code, mobile, smart-contract, cloud-account, IAM, private-network, provider-infrastructure, or open-ended subdomain or IP-range review.
- This is not a penetration test. It is not compliance certification, a security attestation, or a guarantee that the system is secure, complete, compliant, or free of vulnerabilities.
- Targets outside the confirmed first-party scope remain untouched. Third-party or shared infrastructure requires separate written authority.
Not included
- exploitation or credential attacks
- authenticated application testing
- destructive or denial-of-service testing
- customer-data collection
- internal, cloud-account, source-code, mobile, or smart-contract review
- open-ended asset discovery
- compliance certification or a security guarantee
Service reference: OFFSEC-EXTERNAL-EXPOSURE
Example and technical details
What the result supports
This review produces a bounded outside-in picture of one authorised public-facing system: what was checked, which observations support the findings, and what remains unknown. It is not a penetration test, certification, or proof that the system is secure.
How to inspect the result
Inspect the delivered scope record, reports, evidence manifest, artifact hashes, and, where the supported path is produced, the signed receipt and offline verifier. Package integrity does not prove security or completeness.
No sales call required. We confirm scope and authority before work begins.