Six phases. One person reviewing every result.

The scan itself is automated - the same tool runs the same checks every time. What you're paying for is the review that happens after it finishes.

What a scan covers

Every assessment runs the same six-phase pipeline against your domain.

PHASE 01

DNS Reconnaissance

Full DNS record enumeration (A, AAAA, MX, NS, TXT, SOA) plus subdomain discovery - surfaces forgotten staging environments and services you didn't know were publicly resolvable.

PHASE 02

Port Scanning

Scans your common service ports, identifies what's listening, and risk-rates each open port - a database port or admin service exposed to the internet is treated differently to an expected 443.

PHASE 03

SSL/TLS Analysis

Certificate validity, expiry, protocol version, and cipher suite - flags self-signed certificates, weak protocols, and anything that would make a browser warn your visitors.

PHASE 04

Web Security Headers & Sensitive Paths

Checks for six security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and probes known-sensitive paths - .env files, exposed .git directories, backup dumps, admin panels, and API docs left open.

PHASE 05

CVE Lookup

Cross-references any service banners picked up during the scan against the National Vulnerability Database for known, published vulnerabilities.

PHASE 06

Manual Review & Report

This is the part a scanner can't do. I go through every finding myself, drop what's noise, prioritize what's real, and write it up in plain English.

How it runs

You submit your domain I run the assessment & review it myself You get a prioritized PDF report

No self-service scanning. No dashboard. No account to manage. You send a domain, I send back a report - the manual review in the middle is the entire point.

Ready to see what's actually exposed?

Get Assessment

Already spoken with me about a scan? Submit written authorization to get it scheduled - this comes after that initial conversation, not instead of it.