Tell us what you want to check
Name the authorised internet-facing system and why its external attack surface matters now. We’ll confirm the exact boundary and authority before any target-facing check begins. This is not a penetration test.
Selected offer: External Attack Surface Review
Price: €1,900 · excluding VAT
Timing: Within 3 working days after payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed
What happens next and scope
Review one authorised internet-facing system. Find unexpected exposure and misconfiguration, with evidence and remediation priorities. No exploitation. This is not a penetration test.
- 01We check the named public-facing system, your authority, first-party boundary, exclusions, and operator capacity.
- 02We accept or reject the scope asynchronously. No sales call is required.
- 03After payment in full, an accepted SOW, written authority, fixed scope, required inputs, and the approved collection window are confirmed, the three-working-day delivery clock starts.
Do not submit secrets, credentials, private keys, MFA codes, source exports, full logs, screenshots, customer records, or unrelated production data. Name evidence types only; source materials are handled after scope is agreed.
€1,900 · excluding VAT. Payment is due in full before the delivery clock starts. Timing, capacity, and evidence handling are confirmed during asynchronous scope acceptance.
No work or target-facing check starts from this form.
No customer evidence is accepted until scope is agreed.
- ✓exposure-map.json
- ✓findings.json
- ✓evidence-register.json
- ✓evidence-manifest.json
- ✓MANIFEST.sha256
This is not a penetration test.
No exploitation, credential testing, destructive activity, or persistence.
Not a certification, attestation, completeness claim, or security guarantee.
What the review includes
Confirmed attacker-visible hosts, services, and endpoints inside the accepted first-party boundary.
Prioritised observations with affected targets and inspectable evidence references.
Practical fix-now and fix-next recommendations for the reported findings.
What was not tested, not established, stopped, excluded, or left for deeper work.