Back to services

One Server Security Check

One authorised Linux host. A clear, read-only security picture.

You need a clear, read-only security picture of one authorised Linux host before a customer ask, hardening step, or internal review.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Who it is for

Founders and operators who need a reliable snapshot of one named Linux host before hardening, migration, a customer ask, or a deeper review — without a penetration test.

What you receive

  • posture from agreed read-only checks
  • deterministic findings with evidence references
  • report with named limits and unresolved items
  • signed proof package where agreed
  • buyer walkthrough and offline verification path

How it works

  1. 1. Fit check

    Name the host class and goal without sharing credentials or production secrets.

  2. 2. Authority

    Confirm customer authority, named host, read-only window, profile and exclusions before collection.

  3. 3. Collection and assembly

    Run allowlisted read-only checks and assemble the package under the admitted boundary.

  4. 4. Delivery

    Hand over report, package and walkthrough so another person can verify offline without trusting the operator workspace.

What is claimed

This review produces a bounded, read-only picture of one authorised Linux server: what was checked, which evidence supports the result, and what remains unresolved. It is not a penetration test or certification.

How to inspect the result

Inspect the delivered report, receipt, and hash manifest. Structural web verify may apply when the receipt uses a supported schema; offline byte checks stay on the operator path when named.

Boundaries

  • No exploitation, secret collection, compliance certification, or host-security guarantee.
  • One named host, authorised read-only collection, agreed checks and explicit exclusions.
  • valid on a receipt means named verifier checks passed — not that the host is secure or uncompromised.
  • Secrets, credentials and private keys are never requested in the fit check.

Not included

  • exploitation
  • secret collection
  • fund movement
  • unapproved hosts
  • compliance certification

Start a review

Primary route: /review/request

Fallback contact: engage@mail.witnessops.com

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

One Server Security Check | WitnessOps