Thompson Industries

Free Security Snapshot

See where your company is exposed.

We check what is already public. DNS records, old breach data, and the code on your home page. You get a short report in two business days. It is free, and you owe us nothing.

Passive onlyNo credentialsNo strings attached
Security Snapshot · Request

We only read what is already public. You will hear back in two business days.

01Operator

Who we are

We break into software, document it and help you fix it for a living.

Jack Thompson leads the work. Jack holds a BS in Computer Science and an MS in Cyber Security from Worcester Polytechnic Institute. He serves in the Army National Guard as a Cyber Warfare Officer and has worked in the private sector as a cyber engineer, where his work has been in vulnerability research and exploit development.

Two jobs we can point to. We got admin access at a social media start-up. We showed them how we did it, then helped them close it. We also helped an MSP that serves CPA firms assess their security posture, and make the neccessary changes to improve it.

Every job runs the same way. We define the scope of testing first, before we do anything hands on with your application. After we agree on the rules we attack your company just like a hacker would. We document everything we find, where you are strong, and more importantly where you are weak. We come back to you with 3 documents. An executive summary, a technical report and a letter of attestation.

What makes us different? We don't just tell you where your problems are and let you deal with it. We work with your engineers and developers to fix the problems and then retest to make sure that the issue is resolved.

Jack ThompsonLinkedIn
02Deliverable

What you get

A first look at how your company looks from the outside. Use it before you pay for a full test. It is free, you've got nothing to lose and you get:

A short report on what the web shows about your company emailed to you.

A call to talk it through the findings and what to do about them, if you want one.

We check DNS records, certificate logs, and old breach data.

We read the code on your home page. We look for keys or secrets left there by mistake.

03Scope

What this is not

This is not a scan, and it is not a penetration test. Everything we find is already out in the open. We read DNS records, certificate logs, and old breach data. Your home page is the one thing we load, and we load it once. It is the same page your own browser loads when you visit.

  • No credentials
  • No payloads
  • No port scanning
  • No vulnerability testing

This is one of our hard rules. It is against the law to test a system you do not own, and that is why for the free security assessment we stay in what is public. That is why you can ask for one with no contract and no access.

04Audience

Who it's for

Small software teams

You run a small team. You still write code. You ship fast on tools like Supabase, Vercel, and Next.js. Then a big client, an investor, or an insurer asks about security.

Professional services firms

You do accounting, legal, or advisory work. You hold client data that matters. No one has looked at your website in years. You also have rules to follow, like the FTC Safeguards Rule and IRS Pub 4557.

Both end up in the same spot. Someone asked about your security. The report shows where you stand before you write back.

05Next steps

What comes after

The snapshot shows what the outside world can see. That is all it does. If you want more, or the client who asked wants more, here is what we sell.

External Security Assessment
$495
Security Baseline Assessment
Scoped and quoted per engagement
Penetration testing — external, internal, and web application
Scoped and quoted per engagement

Some firms want help all year. We do that too. Not sure what you need? Email us and we will tell you straight. We will say so if you do not need us yet.

Request

Request your Free Security Snapshot.

You know who we are and how we work. Just fill out the form, and the report is yours in two business days. Read it, then take a call if you want one. No strings attached.

Security Snapshot · Request

We only read what is already public. You will hear back in two business days.