Skip to main content
Black-box assessmentSoftware Development

External exposure report — black-box security test

The exact assessment an outside attacker would run against your live site — no source code, no credentials. We map what you expose before someone else does.

Every business has an attack surface it cannot see: the subdomains it forgot, the staging server still on the public internet, the .env file one deploy left readable, the API key that shipped inside a frontend bundle. Attackers map this surface constantly and cheaply. Most companies have never looked at it once.

The external exposure report is that look, done properly. It is the same reconnaissance an outside attacker performs — from the public internet, with no source code, no credentials, and no server access — turned into a written, prioritized report you can act on before it becomes an incident.

From $1,999 · fixed-price external exposure report

Outside-in, exactly as a stranger sees you

This is the counterpart to the AI-built codebase audit. That one reads your source from the inside; this one assumes nothing and starts where a real adversary starts — with your domain name and a search box. What can be discovered, enumerated, and probed about your systems without ever touching a file you gave us?

The answer is almost always more than the business expected. That gap is the point of the exercise: you cannot defend an exposure you do not know you have.

What we map

Forgotten and stale assets: subdomains, staging and development environments, and old deployments still reachable from the internet. Outdated software with known CVEs, missing or weak security headers, and weak TLS configuration. Accidentally exposed files — readable .env or .git directories — and secrets shipped in your public frontend bundle.

We also check whether the guarantees you think you have actually hold: is your row-level security really enforced when the public API is hit directly, or only when the UI politely asks? And we surface injection and OSINT exposure discoverable without touching a single file.

Non-intrusive by default, authorized before anything active

Reconnaissance is non-intrusive: it observes what is already public. Any active testing — anything that sends traffic designed to probe rather than merely to browse — happens only inside a signed, countersigned scope of work, and only once we have confirmed the target is yours to test. We begin no scanning of any kind until that authorization is in place.

That discipline is not bureaucracy. Testing systems you are not authorized to test is a crime, and a firm that is casual about authorization is a firm that will eventually be casual with your systems too.

From one-time report to continuous monitoring

The report is a point-in-time snapshot: here is what you expose today, ranked by severity, with a remediation step for each finding. But your attack surface changes every time you ship. Continuous exposure monitoring attaches after the initial report and re-runs the assessment on a recurring cadence, flagging newly exposed assets and misconfigurations as they appear — from $499/month, under the same signed authorization.

The goal is simple: be the one who finds the forgotten staging server, not the one who reads about it in a breach notification.

FAQ

Common questions.

How is this different from the AI-built codebase audit?
The codebase audit is inside-out — we read your source. The external exposure report is outside-in — no source, no credentials, exactly what a stranger on the internet can discover and probe. They cover different risks, and many clients run both.
Is this a penetration test?
It is the external, black-box portion of one. Reconnaissance is non-intrusive by default; any active testing happens only inside a signed scope of work, after we confirm the target is yours. For deeper, authenticated testing we scope a fuller engagement.
How much does an external exposure report cost?
From $1,999 as a fixed-price one-time report. Continuous exposure monitoring, which re-runs the assessment on a recurring cadence, starts at $499/month and attaches after the initial report.
Will the test take my site down?
No. Default reconnaissance only observes what is already public and sends no probing traffic. Anything active is agreed in writing, scheduled, and scoped to avoid disruption — we never run aggressive scans against a live production system without your explicit sign-off.
Do I need to prove I own the site?
Yes. We confirm the target is yours to test and get written, countersigned authorization before any active testing. It protects you and us, and it is a firm requirement, not a formality.