€450
FLAT FEE, PER TARGET
(Ex. Vat)
3 Days
REPORT TURNAROUND
61k
PORTS PROBED PER HOST
0
AGENTS TO INSTALL
WHAT THE SCAN COVERS
Port & Service Discovery
Full TCP sweep plus the top UDP services across every address in scope. Each open port is banner-grabbed and fingerprinted to a product and version, so the report names the daemon rather than the number.
CVE and patch level
Every fingerprinted version is matched against the NVD and vendor advisories, then cross-checked against CISA’s exploited-in-the-wild catalogue. Findings carry a CVE ID, a CVSS v3.1 vector and the fixed version number.
TLS & certificates
Protocol versions, cipher suites, key exchange, chain of trust, hostname mismatch and expiry across every listener that negotiates TLS — not only port 443. Renewal dates are listed for the next 90 days.
Web application pass
An unauthenticated OWASP-style crawl of each web host: injection and traversal probes, security headers, cookie flags, CORS policy, verbose error handling and known-vulnerable framework or plugin versions.
Exposed interfaces & default credentials
Management panels, databases, remote access and CI endpoints that should never have faced the internet — tested against vendor default credential sets with a single attempt per account, so nothing locks out.
The Deliverable
One PDF, plus the raw findings
Findings are ranked by exploitability against your actual exposure, not by scanner score alone. Each one states the affected host and port, the evidence we captured, the fix, and how long the fix should take. False positives are removed by hand before the report ships.
You also get the machine-readable findings as JSON and CSV, so they can go straight into a ticket queue.
Pricing
Straightforward, per target
€450 (ex vat) per target: one IP address, one CIDR /29 or smaller, or one web host / url with its subdomains. Everything above is included; nothing is held back for an upsell.
Larger estates, internal ranges and recurring schedules are quoted separately — tell us the scale in the form below and we will price it.
You also get the machine-readable findings as JSON and CSV, so they can go straight into a ticket queue.
What this is not
This is an automated external vulnerability assessment with analyst triage. It is not a penetration test: we do not chain findings, pivot between hosts, attempt privilege escalation, social-engineer your staff, or exploit anything beyond the proof needed to confirm a finding exists.
It sees what an unauthenticated attacker on the public internet can see. It will not find flaws in authenticated application logic, in code we cannot reach, or on hosts you do not list. It is a point-in-time snapshot — your exposure changes the next time something is deployed.
If you need an attestation for ISO27001, NIS2, DORA or a cyber insurance renewal, say so before we start: some of those require a test with a scope we would have to quote.
Need a test built around a specific compliance mandate? See our penetration testing service.
Request a Scan
Tell us what you want tested
We reply within one business day with a scope confirmation, a scan window and an authorisation form. Nothing is probed until that form comes back signed.
Scan window
Off-hours by default. Rate-limited to stay well under production load.
Your data
Evidence is encrypted at rest and deleted 90 days after delivery.
FAQ's
Is this the same as a penetration test?
No. This is an automated external vulnerability assessment with analyst triage on top. It does not chain findings, pivot between hosts, attempt privilege escalation, or exploit anything beyond the proof needed to confirm a finding exists.
How long does it take, and when do you start scanning?
We reply within one business day with scope confirmation, a scan window, and an authorisation form. Nothing is probed until that form is signed and returned. Once scanning begins, the report is delivered within 3 days, off-hours by default and rate limited to stay well under production load.
Do we need to install anything or give you access?
No. We require no agents and no console. It only sees what an unauthenticated attacker on the public internet can see, so it will not find issues in authenticated application logic, code it cannot reach, or hosts not listed in scope. Written authorisation is required before the scan can begin.
