External Exposure Assessment

Start your External Exposure Assessment

Tell us what public-facing system you want reviewed. We’ll confirm the exact boundary and authority before any testing begins.

Fallback contact: send the same non-secret fit check to engage@mail.witnessops.com. Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Selected offer: External Exposure Assessment

Price: €1,500 paid pilot — one public-facing domain/application

Timing: Within 3 working days after payment, accepted scope, authority, required inputs, and the collection window are confirmed

Start your External Exposure Assessment.

Tell us what public-facing system you want reviewed. We’ll confirm the exact boundary and authority before any testing begins.

Domain, hostname, public IP, API, application, or public cloud endpoint. No credentials or secrets.

Submitting this form begins asynchronous scope acceptance only. Target-facing work starts only after payment, the SOW, authority, fixed scope, required inputs, and the collection window are confirmed.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

What the External Exposure Assessment delivers
01
Exposure map

Confirmed public services and assets inside the accepted first-party boundary.

02
Evidence-linked findings

Prioritised observations with affected targets and inspectable evidence references.

03
Remediation priorities

Practical fix-now and fix-next recommendations for the reported findings.

04
Limits and unknowns

What was not tested, not established, stopped, excluded, or left for deeper work.

Tell Us What You Need Reviewed | WitnessOps