Cybersecurity + infrastructureSecurity Hot Page · Live notices ↗Security Hot Page ↗Evidence-ledArchitecture-led
← Compare all packagesFIXED SCOPE / WEB-EXTERNAL-1

External application security

Website Security Assessment

Understand the visible security weaknesses of one public website before they become unanswered risk.

Published package price and scope. Availability, authorization, and final applicable terms are confirmed before work begins; public self-registration is not currently available.

Service overview

A bounded service for a specific decision.

This package examines one exact, authorized public website origin from an external perspective. It is designed for a bounded question: what security-relevant conditions are visible on this website, which findings are credible, and what should be addressed first?

Automated observations are reviewed by TechGeeks staff before delivery. The result is a usable assessment record rather than an unfiltered scanner export, with scope, evidence, priority, and remediation direction kept together.

What this service clarifies

Three questions the work is designed to answer.

The package stays useful by keeping the evidence, output, and decision inside a defined boundary.

  1. 01

    Which externally visible website conditions warrant action?

  2. 02

    Which observations are credible within the approved origin?

  3. 03

    What should the website owner or development team address first?

Delivery framework

Controlled from intake through handoff.

Staff time includes preparation, analysis, customer interaction, and reporting—not only meeting time.

  1. 01

    Confirm the target

    Record the exact origin, ownership or authorization, timing, and any operational constraints.

  2. 02

    Establish the baseline

    Assess the approved origin using bounded, non-destructive external techniques.

  3. 03

    Review and prioritize

    Validate material observations, remove obvious noise, and connect findings to affected scope.

  4. 04

    Deliver and retest

    Provide reviewed reports and, when eligible, verify the same approved scope after remediation.

What you receive

Artifacts that preserve scope, evidence, and next ownership.

Exact output reflects the accepted scope and available evidence. Every package retains the boundaries needed to interpret the result responsibly.

01

Executive summary

A concise account of material observations, overall context, and recommended priorities.

02

Reviewed findings register

Finding-specific evidence, affected location, severity context, and remediation guidance.

03

Multi-format report set

PDF, DOCX, and HTML outputs for leadership, internal tracking, and technical review.

04

Eligible same-scope retest

One bounded verification cycle under the package timing and scope conditions.

Scope record

What is included—and what is not.

Payment alone does not authorize access, testing, or production change. Named scope, consent, access, timing, and any safety conditions are confirmed before activity begins.

INCLUDED
  • External website assessment
  • Staff-reviewed findings and PDF, DOCX and HTML reports
  • One baseline and one eligible same-scope retest
REQUIRED BEFORE DELIVERY

An exact authorized origin. Additional subdomains or origins require separate scope.

NOT INCLUDED

Authenticated testing, manual penetration testing, destructive testing, remediation and continuous monitoring are not included.

Service window: Intake is due within 30 days after payment. The service term runs for 90 days after scope acceptance, subject to the accepted order terms. These are service windows—not guaranteed turnaround times.

Good fit when

The package matches the question and boundary.

  • One public website origin needs a focused baseline
  • A development or operations team needs a prioritized findings record
  • A recent change or remediation effort needs bounded verification

Choose a tailored scope when

The requirement extends beyond the package.

  • You need authenticated workflow testing
  • You need manual exploitation or business-logic penetration testing
  • You need continuous monitoring across multiple applications or subdomains

Service questions

Practical answers before you proceed.

01Does one origin include every subdomain?

No. The package covers one exact approved origin. Other origins and subdomains are separate targets and require additional scope.

02Is this a penetration test?

No. It is a focused external website security assessment. Manual exploitation, authenticated workflows, destructive actions, and broader attack-path validation are outside this package.

03What does the retest cover?

The eligible retest is limited to the same accepted origin and the conditions identified during the baseline. It does not add targets or create a new assessment scope.

Customer dashboard

Review the package, then continue through the controlled service process.

Existing customers can view the service catalog in the dashboard. Need access? Use the project brief to request customer access without sending credentials or sensitive evidence by email.

View services in customer dashboard Request customer access