Skip to main content
Our Services

Comprehensive Security Services

From discovery to remediation, we provide end-to-end cybersecurity services designed to actually improve your security posture - not just generate reports.

What We Offer

External Attack Surface Assessment

Understand what attackers can see from the internet.

Our assessment identifies exposed infrastructure, externally accessible services, web-facing assets, technology exposure, configuration weaknesses, and externally observable risks that may increase organizational exposure.

Includes:
  • External infrastructure discovery
  • Service identification and analysis
  • Web surface discovery
  • TLS and certificate review
  • Exposure analysis
  • Risk prioritization and reporting

Email Security Assessment

Email remains one of the largest attack surfaces for organizations.

We assess your email infrastructure to identify weaknesses that may increase susceptibility to spoofing, phishing, impersonation, and delivery failures.

Includes:
  • Email infrastructure analysis
  • SPF evaluation
  • DKIM evaluation
  • DMARC review
  • Mail provider analysis
  • Email exposure assessment
  • Risk scoring and reporting

Web Application Security Assessment

Identify externally observable weaknesses within internet-facing applications.

Our assessments evaluate exposed applications and services to identify security concerns that may increase organizational risk.

Includes:
  • Application discovery
  • Security configuration review
  • Web surface mapping
  • Exposure identification
  • Risk analysis and reporting

Infrastructure Security Assessment

Understand the security posture of externally accessible infrastructure.

Assessments focus on identifying infrastructure weaknesses, exposed services, configuration issues, and externally observable risk indicators.

Includes:
  • Infrastructure mapping
  • Service enumeration
  • Configuration analysis
  • Exposure review
  • Security posture assessment

Subscription Security Monitoring

Available now

Recurring, authorized assessments for security conditions that change over time.

Our subscription service uses scheduled SunTzu assessments to identify newly observed risks, persistent conditions, resolved findings, configuration drift, and changes to the externally observable attack surface. Scanner observations require correlation and review before becoming client-facing findings.

Includes:
  • Weekly or monthly authorized reassessments
  • Automatic recovery with bounded retry limits
  • New, changed, persistent, and resolved condition tracking
  • Coverage and degraded-scan reporting
  • Human-reviewed findings and remediation guidance

Executive Reporting and Risk Tracking

Security findings are only valuable if they can be understood and acted upon.

Our reporting provides visibility into findings, trends, historical changes, and risk prioritization.

Includes:
  • Executive summaries
  • Technical reporting
  • Historical trending
  • Risk prioritization
  • Relationship-based tracking

Our Services

Comprehensive security assessments tailored to your infrastructure

Network Infrastructure

External network infrastructure security assessment

  • Port and service analysis
  • Service enumeration
  • Network device identification
  • Configuration exposure review

Web Applications

Externally accessible web application security assessment

  • Application discovery
  • Configuration review
  • Exposure analysis
  • Security header assessment

Email Infrastructure

Email security configuration and exposure assessment

  • SPF/DKIM/DMARC evaluation
  • Mail server configuration
  • Email security posture
  • Deliverability analysis

Cloud Services

Cloud infrastructure exposure and configuration assessment

  • Public cloud resource discovery
  • Configuration review
  • Exposure identification
  • Security posture evaluation

How We Work With You

Discovery Phase

We start by thoroughly understanding your infrastructure and running comprehensive scans

Our discovery phase involves mapping your entire attack surface - from network infrastructure to web applications, databases, and cloud resources.

  • Asset inventory and mapping
  • Initial vulnerability scanning across all assets
  • Configuration baseline assessment

Ready to Get Started?

Let's discuss your security needs and create a custom plan for your organization