Free Security Snapshot
See where your company is exposed.
We check what is already public. DNS records, old breach data, and the code on your home page. You get a short report in two business days. It is free, and you owe us nothing.
Who we are
We break into software, document it and help you fix it for a living.
Jack Thompson leads the work. Jack holds a BS in Computer Science and an MS in Cyber Security from Worcester Polytechnic Institute. He serves in the Army National Guard as a Cyber Warfare Officer and has worked in the private sector as a cyber engineer, where his work has been in vulnerability research and exploit development.
Two jobs we can point to. We got admin access at a social media start-up. We showed them how we did it, then helped them close it. We also helped an MSP that serves CPA firms assess their security posture, and make the neccessary changes to improve it.
Every job runs the same way. We define the scope of testing first, before we do anything hands on with your application. After we agree on the rules we attack your company just like a hacker would. We document everything we find, where you are strong, and more importantly where you are weak. We come back to you with 3 documents. An executive summary, a technical report and a letter of attestation.
What makes us different? We don't just tell you where your problems are and let you deal with it. We work with your engineers and developers to fix the problems and then retest to make sure that the issue is resolved.
What you get
A first look at how your company looks from the outside. Use it before you pay for a full test. It is free, you've got nothing to lose and you get:
A short report on what the web shows about your company emailed to you.
A call to talk it through the findings and what to do about them, if you want one.
We check DNS records, certificate logs, and old breach data.
We read the code on your home page. We look for keys or secrets left there by mistake.
What this is not
This is not a scan, and it is not a penetration test. Everything we find is already out in the open. We read DNS records, certificate logs, and old breach data. Your home page is the one thing we load, and we load it once. It is the same page your own browser loads when you visit.
- No credentials
- No payloads
- No port scanning
- No vulnerability testing
This is one of our hard rules. It is against the law to test a system you do not own, and that is why for the free security assessment we stay in what is public. That is why you can ask for one with no contract and no access.
Who it's for
Small software teams
You run a small team. You still write code. You ship fast on tools like Supabase, Vercel, and Next.js. Then a big client, an investor, or an insurer asks about security.
Professional services firms
You do accounting, legal, or advisory work. You hold client data that matters. No one has looked at your website in years. You also have rules to follow, like the FTC Safeguards Rule and IRS Pub 4557.
Both end up in the same spot. Someone asked about your security. The report shows where you stand before you write back.
What comes after
The snapshot shows what the outside world can see. That is all it does. If you want more, or the client who asked wants more, here is what we sell.
Some firms want help all year. We do that too. Not sure what you need? Email us and we will tell you straight. We will say so if you do not need us yet.
Request
Request your Free Security Snapshot.
You know who we are and how we work. Just fill out the form, and the report is yours in two business days. Read it, then take a call if you want one. No strings attached.
