External Attack Surface Review

Tell us what you want to check

Name the authorised internet-facing system and why its external attack surface matters now. We’ll confirm the exact boundary and authority before any target-facing check begins. This is not a penetration test.

Selected offer: External Attack Surface Review

Price: €1,900 · excluding VAT

Timing: Within 3 working days after payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed

Domain, hostname, public IP, API, application, or public cloud endpoint. No credentials or secrets.

An approximate date is enough. We’ll confirm delivery timing after agreeing scope.

Next, confirm your email with a code. We’ll then review the fit and reply with the next step.

Submitting this form begins asynchronous scope acceptance only. Target-facing work starts only after payment, the SOW, authority, fixed scope, required inputs, and the collection window are confirmed.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

What happens next and scope
Selected situation

Review one authorised internet-facing system. Find unexpected exposure and misconfiguration, with evidence and remediation priorities. No exploitation. This is not a penetration test.

What happens next
  1. 01We check the named public-facing system, your authority, first-party boundary, exclusions, and operator capacity.
  2. 02We accept or reject the scope asynchronously. No sales call is required.
  3. 03After payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed, the three-working-day delivery clock starts.
First message only

Do not submit secrets, credentials, private keys, MFA codes, source exports, full logs, screenshots, customer records, or unrelated production data. Name evidence types only; source materials are handled after scope is agreed.

Commercial scope

€1,900 · excluding VAT. Payment is due in full before the delivery clock starts. Timing, capacity, and evidence handling are confirmed during asynchronous scope acceptance.

No work or target-facing check starts from this form.

No customer evidence is accepted until scope is agreed.

Typical bundle
  • ✓exposure-map.json
  • ✓findings.json
  • ✓evidence-register.json
  • ✓evidence-manifest.json
  • ✓MANIFEST.sha256
Inspect External Attack Surface Review sample
Boundary kept clear

This is not a penetration test.

No exploitation, credential testing, destructive activity, or persistence.

Not a certification, attestation, completeness claim, or security guarantee.

Need help? Support./Disclosure: Security.
What the review includes
What the External Attack Surface Review delivers
01
External attack-surface map

Confirmed attacker-visible hosts, services, and endpoints inside the accepted first-party boundary.

02
Evidence-backed findings

Prioritised observations with affected targets and inspectable evidence references.

03
Remediation priorities

Practical fix-now and fix-next recommendations for the reported findings.

04
Limits and unknowns

What was not tested, not established, stopped, excluded, or left for deeper work.

Tell Us What You Need Reviewed | WitnessOps