The twelve things
that actually get you breached
A weighted 12-point audit covering the fundamentals that account for most real incidents at this size, with findings ranked by severity and fixes quoted separately.

Small sites do not get breached by sophisticated attacks. They get breached by an exposed API key, an unpatched dependency and an admin route with no 2FA.
A weighted 12-point audit covering the fundamentals that account for most real incidents at this size, with findings ranked by severity and fixes quoted separately.
What you get
- 12-point weighted audit
- Security header analysis
- Dependency CVE scan
- Secrets exposure check
- Auth & admin route review
- DNS, SPF, DKIM, DMARC
- Severity-ranked findings report
- Free re-test within 30 days
| Starting from | $1,400 fixed + $95/hr fixes |
| Typical timeline | 5 working days |
| Discipline | Frontier |
| Markets served | 8 countries |
| Ownership | 100% yours on payment |
| Support after launch | 30 days included |
Written response within 24 hours. No card required.
See it working
Not a screenshot — a live build you can click through right now, in your
own browser, before you pay us anything.
Cybersecurity Basics — questions answered
Is this penetration testing?
No, deliberately. We cover fundamentals that account for most incidents at small scale. Full pen testing needs a specialist and we will refer you rather than pretend.
What is in the 12 points?
HTTPS enforcement, security headers, secrets in the client bundle, dependency CVEs, server-side validation, rate limiting, admin auth and 2FA, tested backups, upload validation, error page leakage, DNS records and access review.
How long does it take?
Five working days — one day recon, one automated scan, two manual review, one report. Fixes are quoted separately so you can triage or do them yourself.
Do you fix what you find?
If you want us to, at $95/hour with a fixed estimate per finding. Many clients fix the easy ones internally and hire us for the rest. Re-test is free within 30 days.
Will this make us compliant?
No. Compliance certification like SOC 2 or ISO 27001 needs an accredited assessor. This is the practical layer underneath that.



