Free External Penetration Test

See your company the way an attacker sees it. Before they do.

Every company has an outside: a website, a mail server, a handful of domains, everything the whole internet can reach. Attackers study that outside for a living. Most companies have never looked at it once. We will, for free, and show you exactly what we find.

No credentials. No software to install. No disruption. No cost.

What We Do

We attack your front door. Politely, and with permission.

We probe your public-facing presence the way an outside attacker would: your website domains and your email. Everything we use is already public or observable from the outside. We never ask for a password, never touch your internal network, and never change a thing. A typical assessment looks at:

Exposed services

Open ports, exposed admin panels, and internet-facing services that shouldn't be reachable, the low-hanging fruit attackers scan for first.

Outdated, visible software

Web servers, plugins, and platforms whose versions are readable from outside and carry known, published vulnerabilities.

Email spoofing gaps

Whether SPF, DKIM, and DMARC are set up correctly, or whether an attacker can send email that looks like it came from your own domain.

Leaked credentials

Company email addresses and passwords already sitting in public breach data, ready for anyone to try against your logins.

Information leakage

Sensitive details exposed in DNS records, metadata, and public pages that quietly hand attackers a map of your environment.

Certificate & encryption

Expired or misconfigured SSL/TLS that undermines trust and can break the padlock your customers look for.

The Catch (There Isn't One)

Why we give this away.

The honest answer: this is how we introduce ourselves. Most companies have no idea what their external exposure looks like, and a real report about their own business persuades better than any pitch we could write.

So we show you, for free, no strings. Like what you see, and we can talk about fixing it or running a deeper audit. Don't, and you keep the report and we part on good terms. Either way you walk away knowing something about your business you didn't know this morning.

How It Works

Three steps. Days, not weeks.

1 · One-page authorization

You sign a short authorization confirming these are your assets and that you're permitting the test. That's what keeps it above board: authorized testing, not hacking.

2 · We run the assessment

We test from the outside using public information only. Nothing to install, nobody in your office, no downtime.

3 · You get the report

A plain-English written report of what we found and what it means, usually within days. We'll walk you through it if you'd like.

Straight About Scope

What this is, and what it isn't.

What it is

  • A free, external, outside-in security test
  • A point-in-time snapshot of your public exposure
  • Non-intrusive: nothing touched, nothing changed
  • A confidential written report that's yours to keep

What it isn't

It isn't a full internal audit. It doesn't look inside your network, your Microsoft 365 tenant, your backups, or your cyber-insurance readiness, because it never asks for access.

When you're ready to go deeper, that's our paid Security Audit, and its fee is credited back if you engage us on any ongoing service.

Fair Questions

What everyone asks first.

Is it really free?

Yes. The assessment and the report cost nothing. Anything beyond the report, remediation or a deeper audit, is separate and only if you want it.

Do you need our passwords?

Never. The test is external and non-intrusive, so there's nothing to install and nothing to disrupt. No credentials, no internal access, no exceptions.

Is it legal?

Yes. You sign a one-page authorization first, confirming the assets are yours and that you're permitting the test. That's precisely what makes it authorized.

What if the report looks bad?

Then you found out from us instead of from an attacker, which is the entire point. We'll explain every finding in plain English and what it would take to fix.

Find out what the internet already knows about you.

It takes one signed page to start and costs you nothing. Worst case, you get a clean report and peace of mind. Best case, you catch something before someone else does.