One Server Security Check
One authorised Linux host. A clear, read-only security picture.
You need a clear, read-only security picture of one authorised Linux host before a customer ask, hardening step, or internal review.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
Founders and operators who need a reliable snapshot of one named Linux host before hardening, migration, a customer ask, or a deeper review — without a penetration test.
What you receive
- posture from agreed read-only checks
- deterministic findings with evidence references
- report with named limits and unresolved items
- signed proof package where agreed
- buyer walkthrough and offline verification path
How it works
1. Fit check
Name the host class and goal without sharing credentials or production secrets.
2. Authority
Confirm customer authority, named host, read-only window, profile and exclusions before collection.
3. Collection and assembly
Run allowlisted read-only checks and assemble the package under the admitted boundary.
4. Delivery
Hand over report, package and walkthrough so another person can verify offline without trusting the operator workspace.
What is claimed
This review produces a bounded, read-only picture of one authorised Linux server: what was checked, which evidence supports the result, and what remains unresolved. It is not a penetration test or certification.
How to inspect the result
Inspect the delivered report, receipt, and hash manifest. Structural web verify may apply when the receipt uses a supported schema; offline byte checks stay on the operator path when named.
Boundaries
- No exploitation, secret collection, compliance certification, or host-security guarantee.
- One named host, authorised read-only collection, agreed checks and explicit exclusions.
- valid on a receipt means named verifier checks passed — not that the host is secure or uncompromised.
- Secrets, credentials and private keys are never requested in the fit check.
Not included
- exploitation
- secret collection
- fund movement
- unapproved hosts
- compliance certification
Start a review
Primary route: /review/request
Fallback contact: engage@mail.witnessops.com
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.