Everything facing the internet in your name
Domains, subdomains and services, including the forgotten test site or old booking page nobody remembers putting up. You cannot look after what you do not know you own.
We map what is already public about your business: what is reachable, what is exposed, and what someone could learn before they ever touch anything. Nothing is probed and nothing is scanned. You get a ranked list of what to close first, in plain English.
Part of the wider AI and automation work. See everything we do
Six things, all of them already public. No traffic reaches your systems.
This is the homework someone does before they try anything. Doing it first, on purpose, is the cheapest security work available to a small business.
Domains, subdomains and services, including the forgotten test site or old booking page nobody remembers putting up. You cannot look after what you do not know you own.
Where a site or mail server runs software with a published vulnerability at the exact version you are on. This is the most common way small business sites get defaced, and the version is usually sitting in the page source.
Emails and passwords caught in past third-party breaches and circulating online, ready to be tried against your accounts. Almost always a surprise, and almost always still valid somewhere.
The records that stop someone sending a fake invoice in your name. Missing them means a customer receiving that invoice has no way to tell it is not from you.
Documents, logins and dashboards reachable by anyone who looks, plus whatever search engines have already indexed and cached.
The staff and social footprint someone would draw on to write a phishing email that sounds like it came from inside the business.
Three steps. Nothing to schedule, nothing to approve, nothing that can break.
Active testing has its place and we do it, but only once it is scoped and authorised in writing. The first pass is entirely passive, which is why it can happen this week without a change window or any risk to a system that is running fine.
Everything above is gathered from public sources only. Nothing is probed, scanned or touched, so there is no risk to anything you run.
Everything comes from public sources: search engines, public records, breach databases and what your own site publishes about itself. No traffic reaches your systems, so there is nothing to schedule, nothing to approve, and nothing that can break.
A short list of what is actually exposed, in the order worth doing something about, in plain English. Not a compliance checklist and not a hundred pages of severity ratings you have to interpret.
Fix it yourself, hand it to whoever looks after your systems, or ask us. If there is nothing worth reporting we will tell you that, which is a perfectly good outcome.
Optional, scoped, and never assumed. The first review stands on its own.
None of this is bundled in or assumed. It is here so you know where it can go if the first review turns up something worth chasing.
Active testing of a site or app: actually trying the doors rather than noting they look unlocked. Scoped and authorised in writing first, always.
Not just a list handed over. Patching, hardening and reconfiguring the things that matter, either directly or alongside whoever already looks after your systems.
Ongoing checks for new exposure, fresh credential leaks and changes to your footprint, so something is caught while it is cheap rather than after it bites.
Tell us your domain and we will take a look. If there is nothing worth reporting we will say so, and it costs you nothing either way.