The services

Service 04 · Security & Compliance

Find out where you stand.
Before someone else does.

The security industry sells fear by the day rate. Most small businesses respond the only sensible way: they ignore all of it, because they cannot tell the real risks from the theatre. The trouble is that some of it is real, and the difference between the two is precisely what nobody selling to you will say plainly.

What an audit is

A fixed-scope examination of what you actually have: your website and its software, your DNS and email authentication, your exposure as an attacker would map it, and the governance around who can change what. It ends in a written report with a plain verdict and a prioritised list — what is urgent, what can wait, and what you are being oversold elsewhere.

The recommendation is honest even when it is unprofitable. Our flagship audit found a critical, actively exploited flaw on a live site, closed it, and then recommended against the expensive rebuild the client had assumed they needed. An audit is worth buying precisely because it will tell you things you did not want to hear, including that you do not need the expensive thing.

What it costs

The first look is free: a short call, the top-line risks, one page. The full audit is quoted in writing before it starts, because its report is the product. Remediation, if any is needed, is quoted separately, and we are equally content if your own people do it with our list in hand.

THE EVIDENCE · Confidential ยท US financial services · June 2026 Security & Compliance

An informal favour that turned up a critical, actively exploited vulnerability on a live site. The audit's main recommendation was to spend less, not more.

CVSS severity of the flaw found

CVSS 9.8

The first look is free, and the verdict is plain either way.

Request the first look