← All services

One Server Security Check

Know what needs attention on one Linux server.

Preparing a Linux server for a customer review or hardening? Get a read-only security snapshot of one authorised host, with findings and clear next steps.

Price
€950 standard · excluding VAT
Delivery
Within two business days after the authorised collection window
Scope this review

Start with a short description. We confirm fit and scope before work begins.

See a sample review →

What you get

  • A snapshot from agreed read-only security checks.
  • Findings linked to evidence, with limits and unresolved issues.
  • A report and walkthrough; signed package and offline verification where agreed.

Scope and limits

One authorised Linux host. Read-only checks; no exploitation or guarantee that the host is secure.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Who it is for

Founders and operators preparing one Linux host for hardening, migration or a customer review.

Company background

WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →

Your part in the engagement

What do you need from me?

Describe one Linux host and what you need to decide. We agree the host, owner, checks and collection window before requesting any access.

What access is required?

Only authorized, agreed read-only checks on the named host. Access and handling are arranged separately; never paste credentials into the enquiry.

What happens after delivery?

You receive findings and a walkthrough of the report and agreed package. Your team owns remediation; the review does not certify that the server is secure.

How the engagement works
  1. 1. Fit check

    Name the host class and goal without sharing credentials or production secrets.

  2. 2. Authority

    Confirm customer authority, named host, read-only window, profile and exclusions before collection.

  3. 3. Collection and assembly

    Run allowlisted read-only checks and assemble the package under the admitted boundary.

  4. 4. Delivery

    Hand over report, package and walkthrough so another person can verify offline without trusting the operator workspace.

Full scope and exclusions

Standard line after a non-secret fit check for one authorised host.

  • No exploitation, secret collection, compliance certification, or host-security guarantee.
  • One named host, authorised read-only collection, agreed checks and explicit exclusions.
  • valid on a receipt means named verifier checks passed, not that the host is secure or uncompromised.
  • Secrets, credentials and private keys are never requested in the fit check.

Not included

  • exploitation
  • secret collection
  • fund movement
  • unapproved hosts
  • compliance certification

Service reference: OFFSEC-LOCAL-AUDIT

Example and technical details

What the result supports

This review produces a bounded, read-only picture of one authorised Linux server: what was checked, which evidence supports the result, and what remains unresolved. It is not a penetration test or certification.

How to inspect the result

Inspect the delivered report, receipt, and hash manifest. Structural web verify may apply when the receipt uses a supported schema; offline byte checks stay on the operator path when named.

Scope this review

Start with a short description. We confirm fit and scope before work begins.

One Server Security Check | WitnessOps