Skip to content

Security audit for small and medium businesses

The free check reads the signals your website publishes to anyone who asks. An audit goes where a reading cannot: behind the login, through the business logic, and into the places where two small problems combine into one real one.

What the free check cannot see

This is true of every automated scanner, ours included. It is the honest reason an audit exists.

Anything behind a login
The check never authenticates. Customer areas, admin panels and dashboards are exactly where the damaging problems live, and an unauthenticated reading cannot reach any of them.
Business logic
Whether one customer can open another customer's invoice by changing a number in the address. No scanner knows what your numbers mean; a person testing it does.
Privilege escalation
Whether an ordinary account can reach something only an administrator should. This needs at least two accounts and someone comparing what each one can do.
Chained findings
Three low-severity items that are harmless alone and serious together. A scanner scores them separately because it has no way to try them in sequence.

What the audit includes

  • A written scope agreed before anything begins: which applications, which roles, which dates, and what is explicitly out of bounds.
  • Written authorisation from whoever owns the systems. This is a requirement, not paperwork — it is what separates a test from an intrusion.
  • Manual testing against a published methodology: the OWASP Web Security Testing Guide and NIST SP 800-115.
  • A report with each finding, its severity, the evidence behind it, and the steps to fix it — written so the person who has to apply the fix can act on it without translation.
  • A walkthrough of the report with whoever maintains the site, because a report nobody understood is a report nobody acts on.
  • A retest of the findings you fix, so the result is a record of what was closed rather than a list of what was found.

How scope and price are agreed

A penetration test is priced by its scope, and the scope is yours: one application or four, an authenticated area or none, two roles or six. A figure printed on a page without knowing any of that is either wrong or bait, so there isn't one here.

You get the figure before anything starts
Scope, dates and price are agreed in writing first. There is no variable cost that appears later.
Scope is adjustable, which is what makes it affordable
A first engagement covering the public application and one authenticated role costs a fraction of one covering everything, and it is usually where the findings are. Small businesses can start there and widen later.
Ask, and you get an answer with a number in it
Tell us what you run and what worries you. The reply is a scope and a price, not a discovery call.

What an audit does not promise

  • It does not find everything. Any test is bounded by time, scope and what was reachable on those dates, and anyone telling you otherwise is selling something.
  • It is not a certification. There is no badge at the end, because no badge would mean anything.
  • A clean report does not mean the system is secure. It means what was tested, in that scope, on those dates, held up.

Where to start

Run the free check first — it costs nothing, takes a minute and needs no account. If the result raises questions, write and we will scope an audit around what you actually need.

Related