One Server Security Check
Know what needs attention on one Linux server.
Preparing a Linux server for a customer review or hardening? Get a read-only security snapshot of one authorised host, with findings and clear next steps.
- Price
- €950 standard · excluding VAT
- Delivery
- Within two business days after the authorised collection window
Start with a short description. We confirm fit and scope before work begins.
What you get
- A snapshot from agreed read-only security checks.
- Findings linked to evidence, with limits and unresolved issues.
- A report and walkthrough; signed package and offline verification where agreed.
Scope and limits
One authorised Linux host. Read-only checks; no exploitation or guarantee that the host is secure.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
Founders and operators preparing one Linux host for hardening, migration or a customer review.
Company background
WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →
Your part in the engagement
What do you need from me?
Describe one Linux host and what you need to decide. We agree the host, owner, checks and collection window before requesting any access.
What access is required?
Only authorized, agreed read-only checks on the named host. Access and handling are arranged separately; never paste credentials into the enquiry.
What happens after delivery?
You receive findings and a walkthrough of the report and agreed package. Your team owns remediation; the review does not certify that the server is secure.
How the engagement works
1. Fit check
Name the host class and goal without sharing credentials or production secrets.
2. Authority
Confirm customer authority, named host, read-only window, profile and exclusions before collection.
3. Collection and assembly
Run allowlisted read-only checks and assemble the package under the admitted boundary.
4. Delivery
Hand over report, package and walkthrough so another person can verify offline without trusting the operator workspace.
Full scope and exclusions
Standard line after a non-secret fit check for one authorised host.
- No exploitation, secret collection, compliance certification, or host-security guarantee.
- One named host, authorised read-only collection, agreed checks and explicit exclusions.
- valid on a receipt means named verifier checks passed, not that the host is secure or uncompromised.
- Secrets, credentials and private keys are never requested in the fit check.
Not included
- exploitation
- secret collection
- fund movement
- unapproved hosts
- compliance certification
Service reference: OFFSEC-LOCAL-AUDIT
Example and technical details
What the result supports
This review produces a bounded, read-only picture of one authorised Linux server: what was checked, which evidence supports the result, and what remains unresolved. It is not a penetration test or certification.
How to inspect the result
Inspect the delivered report, receipt, and hash manifest. Structural web verify may apply when the receipt uses a supported schema; offline byte checks stay on the operator path when named.
Start with a short description. We confirm fit and scope before work begins.