Authorized baseline
One registered domain and one primary web application. Any additional targets or authenticated work require a separate scope and authorization.
Build a deeper external baseline for one authorized website or web application, including its public attack surface, observable services, configuration, technology risks, and reviewed findings.
One registered domain and one primary web application. Any additional targets or authenticated work require a separate scope and authorization.
You receive a prioritized report through your verified client account after the assessment is completed and reviewed.
After the completed baseline is published, Advanced website monitoring can compare the same site's response, HTTPS and certificate posture, selected security headers, destination consistency, and technology banner signals.
Recurring checks are bounded comparisons of baseline observations. They do not repeat the entire advanced assessment or add new application testing.
We can explain the findings, help prioritize your next steps, or discuss other technology challenges affecting your business. You do not need to know where to start.
Ask SunTzu for helpAsking a question does not commit you to paid work. Any proposed scope and cost will be explained first.
An assessment reflects the evidence collected at that time. We recommend ongoing monitoring and scheduled reassessments to identify meaningful changes and verify agreed fixes.
Discuss ongoing monitoringWe will help define the assets, checks, schedule and notification process that fit your needs.