Service
Security Audit
An independent, read-only look at your hosting, your systems, your website and your code, and a plain statement of where you actually stand.
Problems it addresses
If any of this sounds familiar, it is worth a conversation.
The site was built a few years ago and nobody has looked at what has gone out of date since.
Staff and contractors have come and gone, and nobody is certain who still has access to the hosting, the domain or the admin.
You have added AI features or integrations, and nobody has asked what they could be talked into doing.
You have backups, and nobody has ever restored one to find out whether they work.
What we deliver
A working outcome, not a slide deck.
All four come out of one fixed-scope review. The report is yours, and it is written so another provider could act on it if you would rather they did.
Fixed-Price Security Review
A read-only review across hosting, environment, website and code. We look, we record, and we change nothing. Nothing is exploited and nothing is taken offline to produce the findings.
Ranked Findings Report
Written for a decision-maker rather than an engineer, and ordered by what each finding would cost your business if it happened, which is rarely the same order a scanner would give you.
Prioritised Fix List
What to do this month, what can wait, and who owns each item: you, us, your host or your software vendor. The order matters as much as the list, and we explain why each one sits where it does.
Scope Statement
What we examined and, just as plainly, what we did not. An audit that implies more coverage than it has is worse than no audit, because you will make decisions on the strength of it.
The engagement
What's involved
A fixed-scope review. Here is what is involved, activity by activity, so you can see what is actually covered.
| Activity | What's involved |
|---|---|
| Scope and access | Agreeing what is in scope and what is out, and getting read-only access to the right places |
| Hosting and accounts | Who can log in and how they authenticate, who controls the domain and DNS, and where backups actually live |
| Environment review | Patch levels, what is reachable from the internet, and the old staging sites and subdomains nobody retired |
| Website review | The platform, its themes and plugins and their known vulnerabilities, admin accounts, forms and file handling |
| Code and dependency review | Out-of-date libraries with published vulnerabilities, credentials committed to source control, and how access is enforced |
| AI integration review | What each AI feature can reach, and what happens when somebody tries to talk it into something else |
| Backup and recovery check | Whether a backup exists, how far back it reaches, and whether anybody has ever restored one |
| Report, ranking and fix list | Findings written for a decision-maker, ranked by business impact, with an ordered fix list, owners and the scope statement |
Fixing what the review finds is scoped separately, from the fix list it produces.
Delivery process
How an engagement runs.
Scope and access
We agree what is in scope and what is not, get read-only access to the right places, and put in writing what we will not touch. Nothing starts before that is settled.
The review
Hosting and the accounts that control it, the environment and what it exposes, the website and what it runs on, the code and its dependencies, and anything connected to an AI model.
Report and fix list
Ranked findings, an ordered fix list with owners, and the scope statement. Anything genuinely serious reaches you the day we find it, not a fortnight later in a document.
Fix and retest
On your sign-off we fix what we found, or work alongside whoever will, then retest and confirm in writing what has actually changed.
Pricing approach: discovery is a fixed fee. Build work is quoted as a fixed scope and price once discovery is complete, so you decide with the numbers in front of you. Ongoing support is a monthly retainer you can stop at any time.
The Shadow AI Audit covers the other half of this: which AI tools your team has already started using, and what they are putting into them. Twenty-four questions, about fifteen minutes, free.
Questions
Frequently asked.
Will this take our website down?+
No. The review is read-only: we look at how things are configured and what you are running, rather than trying to break in. We do not exploit what we find. If anything intrusive is genuinely warranted, it happens only with your written agreement, at a time you pick, with a way back.
Is this a penetration test?+
No, and the difference is worth being clear about. A penetration test tries to break in and demonstrates what an attacker could reach. This is a review of how you are set up and what you are running. For most small businesses a review finds the things a penetration test would find in its first hour, for far less effort. If what you actually need is a formal penetration test or a certification, we will tell you that rather than sell you this instead.
We are a small business. Are we really a target?+
Rarely a chosen one, and that is the point people miss. Most of what arrives at a small business site is automated and indiscriminate: it finds an address, tries a list of known weaknesses, and moves on if nothing works. Being uninteresting is not protection. Being up to date is.
How is this different from the free Shadow AI Audit?+
They answer different questions and barely overlap. The Shadow AI Audit is about people: which AI tools your team has started using and what they are putting into them. This is technical: your hosting, your environment, your website and your code. Plenty of businesses should do both, and the free one is a sensible place to start.
We have AI features on our site. Does that change anything?+
Yes, and it is the part most reviews still skip. Anything that takes text from the public and passes it to a model can be talked into behaving in ways you did not intend, and anything that gives a model access to your systems can reveal more than you meant through an ordinary-looking answer. We look at what each AI feature is allowed to reach, and what happens when somebody tries to push it past that.
What happens if you find something serious?+
You hear about it the day we find it, with what to do about it, even when the answer is that somebody other than us should do it. Serious findings do not wait for the report.
What does it cost?+
The review is fixed-price, so you know where you stand before committing to anything further. Remediation is quoted from the fix list, which means you are approving specific work rather than an open-ended engagement. Book a call and we will scope it properly.
Further reading: How small business websites actually get hacked · 7 minute read, What Australian privacy law asks of you · 7 minute read
Related services
Server & Database Optimisation
Your business system is slow. We find out why, and fix it. Human-framed, AI-accelerated.
Code Takeover & New Features
Somebody else built it and you need a feature added, a stalled build finished, or a fault fixed properly. We read the code, work out how it fits together, and then do the work.
Web & Platform Development
A modern, fast web platform that works as hard as your team does, and grows with your business.
Tell us what you are running, and we will tell you where you stand.
We will tell you honestly whether this is the right answer for it.
Book a Security Review →