External security audit

Your whole domain, reviewed by a human.

The free checkers look at one surface of one page. This is the full external attack surface — every subdomain we can find, the configuration on each, what is exposed, and whether your domain can be spoofed — filtered of false positives by a person and delivered as a fix-first report.

One domain

€290

One-off audit, PDF report in three business days, 30-minute walkthrough, free re-check after you fix.

Agency portfolio

€149 / month

Up to 10 client domains (+€12 each beyond), re-scanned monthly, white-label reports, regression and clone alerts. First audit credited to month one.

What the audit covers

  • Every subdomain we can find from public certificate history, classified and checked — not just the homepage
  • Security headers, Content-Security-Policy, cookie flags and TLS configuration on each live host
  • Exposed files and panels: .git, .env, backups, debug endpoints, directory listings
  • Leaked secrets and API endpoints visible in your own JavaScript
  • Email authentication: SPF, DKIM, DMARC and whether your domain can be spoofed
  • Technology fingerprint with a CISA KEV overlay — known-exploited issues first, no version guessing
  • Optional, under separate written authorization: active checks (open redirect, path traversal, default credentials, login rate limiting, XSS)

What you get

  • A PDF report ordered by what to fix first, not by scanner output
  • Every finding in plain English for the owner, with the exact configuration change for whoever implements it
  • False positives filtered out by a human before you see them — we cut the noise, not the truth
  • A 30-minute call to walk through the report and answer questions
  • A free re-check of the fixed items within 30 days

How it works

01

Request

Tell us the domain and confirm you're authorized. One minute.

02

Pay

We reply within one business day with a card payment link or an invoice — your choice.

03

We scan and review

The engine runs, then a human reviews every finding. No automated report goes out unread.

04

Report + call

PDF within three business days, plus a 30-minute walkthrough and a re-check after you fix.

Not sure it's worth it? Run the free Website Security Score and the Subdomain Finder first. If they come back clean, tell us when you request the audit — we will say so rather than take the work.

Request an audit

What do you need?

No payment now. We reply within one business day with a payment link or an invoice; nothing is scanned until you confirm.

Questions

What exactly do I get for €290?
A full external audit of one domain: every subdomain we can discover from public certificate history, then per-host checks of security headers, Content-Security-Policy, cookies, TLS, exposed files and leaked secrets, plus email authentication for the domain and a known-exploited-vulnerability overlay. The output is a PDF ordered by what to fix first, written so the owner understands the risk and the developer knows the exact change. You also get a 30-minute call and a free re-check of the fixed items within 30 days. The price is per domain and includes the human review — that review is most of the work, and it is the reason the report has no filler.
How is this different from the free checkers?
The free checkers each look at one surface of one page: headers, cookies, CSP, TLS, email, login rate limiting, subdomains. They are instant, passive and genuinely free, and for many sites they are enough. The audit covers the whole domain rather than the homepage, adds checks that cannot be offered safely as an open self-serve tool (exposed files, leaked secrets, known-exploited-vulnerability context), and — the part no tool gives you — a person decides what actually matters for your site, removes false positives, and sequences the fixes. If the free checkers come back clean, say so when you request the audit and we will tell you honestly whether it is worth paying for.
Do you need access to my servers or admin accounts?
No. The standard audit is entirely external and passive: it uses the same requests a visitor's browser makes, plus public records such as DNS and certificate transparency logs. No credentials, no agent, no code on your servers. Two optional extras do need more: active checks (open redirect, path traversal, default credentials, rate limiting, XSS) run only under separate written authorization from the domain owner, and the deep authenticated audit needs two test accounts you create for us. Both are opt-in, quoted separately, and never run without a signed scope.
What does the Agency Portfolio include?
€149 per month covers up to 10 client domains (additional domains €12 each). Every domain is re-scanned monthly, and you get a report per client that carries your agency's branding, not ours — something you can forward or attach to a retainer report. You also get alerts when something regresses between scans, for example a security header disappearing after a deploy or a DMARC policy weakening, and clone, lookalike-certificate and typosquat monitoring for each domain. If you start with a single audit and then sign up, the audit fee is credited against your first month.
Is a one-off audit really useful, or do I need monitoring?
An audit is a snapshot: it tells you what is wrong today and how to fix it, which is exactly what you need before a launch, after inheriting a site, or when a client asks a security question you cannot answer. What it cannot do is notice that a deploy next month removes your security headers, or that someone registers a lookalike domain in October. That is what the monthly portfolio plan and the free Domain Monitor are for. Most people should start with one audit, fix what it finds, and only then decide whether continuous coverage is worth a subscription.

Scope and method are documented in How we scan; limits and liability in the disclaimer. Invoiced by DZZD MARKET PULSE (VAT BG181450814, Burgas, Bulgaria). Active and authenticated testing runs only under separate written authorization.