Six phases. One person reviewing every result.
The scan itself is automated - the same tool runs the same checks every time. What you're paying for is the review that happens after it finishes.
What a scan covers
Every assessment runs the same six-phase pipeline against your domain.
DNS Reconnaissance
Full DNS record enumeration (A, AAAA, MX, NS, TXT, SOA) plus subdomain discovery - surfaces forgotten staging environments and services you didn't know were publicly resolvable.
Port Scanning
Scans your common service ports, identifies what's listening, and risk-rates each open port - a database port or admin service exposed to the internet is treated differently to an expected 443.
SSL/TLS Analysis
Certificate validity, expiry, protocol version, and cipher suite - flags self-signed certificates, weak protocols, and anything that would make a browser warn your visitors.
Web Security Headers & Sensitive Paths
Checks for six security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and probes known-sensitive paths - .env files, exposed .git directories, backup dumps, admin panels, and API docs left open.
CVE Lookup
Cross-references any service banners picked up during the scan against the National Vulnerability Database for known, published vulnerabilities.
Manual Review & Report
This is the part a scanner can't do. I go through every finding myself, drop what's noise, prioritize what's real, and write it up in plain English.
How it runs
No self-service scanning. No dashboard. No account to manage. You send a domain, I send back a report - the manual review in the middle is the entire point.
Ready to see what's actually exposed?
Get AssessmentAlready spoken with me about a scan? Submit written authorization to get it scheduled - this comes after that initial conversation, not instead of it.