A proper security check-up - plain English, no enterprise price tag.

Six technical phases run in the background - DNS, ports, certificates, headers, known vulnerabilities. What actually lands in your inbox is the plain-English version: what's exposed, why it matters, and what to fix first.

I go through every finding myself before it reaches you - no dashboard, no automated score, just one person reviewing the results so an exposed port or a forgotten staging subdomain gets caught and explained, not buried in a raw scan dump.

What a scan covers

Every assessment runs the same six-phase pipeline against your domain.

PHASE 01

DNS Reconnaissance

A full map of your domain's DNS records (A, AAAA, MX, NS, TXT, SOA) plus a search for forgotten subdomains - the old staging environment or service you didn't know was still publicly visible.

PHASE 02

Port Scanning

Scans your common service ports, identifies what's listening, and risk-rates each one - a database or admin service left open to the internet is flagged as far more serious than the normal, expected web traffic port (443).

PHASE 03

SSL/TLS Analysis

Certificate validity, expiry, protocol version, and cipher suite - flags self-signed certificates, weak protocols, and anything that would make a browser warn your visitors.

PHASE 04

Web Security Headers & Sensitive Paths

Checks for six security headers your browser relies on to keep you safe (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), and probes for commonly-forgotten sensitive files - .env files, exposed .git directories, backup dumps, admin panels, and API docs left open to anyone who knows where to look.

PHASE 05

CVE Lookup

Cross-references any service banners picked up during the scan against the National Vulnerability Database for known, published vulnerabilities.

PHASE 06

Manual Review & Report

This is the part a scanner can't do. I go through every finding myself, drop the noise, prioritize what's real, and write it up in plain English.

Compare services

Every service includes a manual review of the results by me, and every report is delivered as a PDF.

What each Fieldnote Security service includes, and its starting price
What's checked Vulnerability Assessment DNS Health Email Security Script Audit Accessibility GDPR
DNS record & subdomain reconnaissance Included Included Not included Not included Not included Not included
Port / attack-surface scan Included Included Not included Not included Not included Not included
SSL/TLS certificate analysis Included Not included Not included Not included Not included Not included
Security headers & sensitive-path checks Included Not included Not included Not included Not included Not included
CVE (known vulnerability) lookup Included Not included Not included Not included Not included Not included
Overall Risk Score (0-100) Included Not included Not included Not included Not included Not included
Email authentication check (SPF/DKIM/DMARC) Not included Not included Included Not included Not included Not included
Third-party script & tracker inventory Not included Not included Not included Included Not included Not included
Automated accessibility scan (WCAG 2.1 AA) Not included Not included Not included Not included Included Not included
Cookie consent, privacy policy & data-retention review Not included Not included Not included Not included Not included Included
Structured data-practices questionnaire Not included Not included Not included Not included Not included Included
HTTPS / data-in-transit check Not included Not included Not included Not included Not included Included
Starting price From £800 £0 (bundle) £0 (bundle) From £75 From £400 (bundle) From £400 (bundle)

How it runs

You submit your domain → I run the assessment & review it myself → You get a prioritized PDF report

No self-service scanning. No dashboard. No account to manage. You send a domain, I send back a report - the manual review in the middle is the entire point.

Ready to see what's actually exposed?

Request an assessment

Already spoken with me about a scan? Submit written authorization to get it scheduled - this comes after that initial conversation, not instead of it.