Security + GDPR. One fixed price.
The full scan chain — surface mapping, web security, SSL, email hygiene, and GDPR posture — is built in Go and runs with goroutine-based concurrency for fast, efficient coverage. Every result is checked manually for false positives and delivered as a professional PDF report. One-off scans are available, but most clients choose monthly coverage: passive checks run daily, critical alerts fire immediately, and you receive one consolidated PDF each month.
Security + GDPR
One-off scan also available at the same price. Monthly covers daily passive checks, immediate critical alerts, and a consolidated PDF report each month.
- ✓ Subdomain discovery
- ✓ DNS records review
- ✓ Technology stack detection
- ✓ Vulnerability scan with severity & affected URLs
- ✓ CVE findings & exposure validation
- ✓ Email security (SPF / DKIM / DMARC)
- ✓ TLS / SSL configuration audit
- ✓ Security headers audit
- ✓ WAF & CDN bypass detection
- ✓ Privacy policy & cookie consent review
- ✓ Third-party tracking & data flow analysis
- ✓ External data risk indicators
- ✓ Professional PDF report with executive summary
Why scan regularly?
Plugins update. Configs drift. Monthly visibility matters.
A clean bill of health today doesn't mean next month. WordPress plugins, third-party scripts, DNS changes, and new misconfigurations appear continuously. Most SMB breaches happen not because a business was initially vulnerable — but because something changed and nobody noticed.
A monthly cadence catches that drift earlier. At this price point, daily passive checks with immediate critical alerts and one clear monthly PDF is a small cost compared with even a short incident window.
Plugin vulnerabilities
A plugin updated by its developer can introduce a new exposure. You won't know unless something is checking from the outside.
Configuration drift
SSL renewals lapse, headers get removed during deployments, new subdomains get left exposed. Small changes accumulate.
Third-party risk
Scripts, analytics, and embedded tools change. A third party you embedded two years ago may now be a risk you're not aware of.
Reputation cost
For SMBs, a breach isn't just a technical problem. Lost client trust and the reputation damage it carries often outlast the incident itself.
Common questions
What people usually ask before getting in touch.
Do you need access to my website or servers?
No. Every scan is passive and runs entirely from the outside. All we need is the domain name — no credentials, no SSH access, nothing installed.
Will the scan affect my site's performance or uptime?
No. Passive scanning observes what is publicly visible — it doesn't hammer endpoints or attempt exploitation. Your site will not notice the scan running.
Can I get a one-off scan rather than committing to monthly?
Yes. The scan is priced at the same €149 with no contract. Many clients start with a one-off, then move to monthly coverage with daily passive checks, immediate critical alerts, and one PDF report each month.
How long does a scan take?
The scan chain typically runs within a few hours. The manual verification and report writing adds a day or two. Most clients receive their PDF within 2–3 business days of scope being agreed.
Who is the report written for?
Both. Every report has an executive summary in plain language for business owners and a technical findings section with evidence and remediation guidance for developers or IT teams.
Ready to get started?
Send the domain. We'll confirm scope and have a report back to you within a few business days.
No contract. No access required. Cancel or pause any time.