Security scanning
An authorised scan of your web application or API that finds the common, well known weaknesses before someone else does, with a report your developers can act on. We confirm you control the target and agree the scope in writing before anything runs.
Most breaches start with something ordinary that nobody got around to fixing: a component with a known flaw, a missing security header, a login that never locks out, a server that gives away more than it should. Automated scanning is good at finding exactly this class of problem, quickly and repeatably, across your whole surface.
We run that scanning as a service so you do not have to stand up and maintain the tools yourself. Every engagement begins with proof that you control the target and a written scope that sets what we test, when, and how hard. Nothing is scanned without both, because testing a system you do not own is illegal and we will not do it.
What does a scan cover?
Known vulnerabilities
We check your application and its components against a large, maintained library of known weaknesses, the same classes of issue an attacker looks for first.
Configuration and headers
Missing or weak security headers, server settings that leak information, and transport security that is out of date or misconfigured.
Exposed surface
Endpoints, files and services that are reachable but should not be, and software versions that reveal more than they need to.
A report you can act on
Each finding carries a severity, a plain explanation, and the fix. No wall of raw tool output, and no padding the list to look busy.
A free retest
After you fix the findings we scan again to confirm they are closed, so you know the work landed.
Proof of authorisation
Ownership verification and a signed scope are recorded for every engagement, so you keep a clean record that the testing was authorised.
Questions
What do people ask about security scanning?
Is this a penetration test?
No, and we will not call it one. This is automated security scanning. It finds known weaknesses and misconfigurations very well, but it does not include a person testing your business logic by hand. If you need a full manual penetration test, usually for a compliance requirement, tell us and we will be honest about what we do and do not offer.
Will a scan break our site?
By default we run a non destructive profile: rate limited, no denial of service tests, no actions that change your data. We also agree a testing window with you in advance. A more thorough active scan is a separate conversation with its own written scope.
How do you know we are allowed to scan it?
You prove you control the target first, by placing a token we give you in your DNS or on your site, and you sign a short scope document. Only then can a scan run. This protects you as much as it protects us.
What do we get at the end?
A report listing each finding with its severity and how to fix it, written so a developer can act on it without translating tool output. Once you have fixed the issues we retest at no extra charge to confirm they are closed.
Tell us what you are trying to fix
Send a short description of the problem rather than a feature list. If we are a fit, we will come back with an approach and a price. If we are not, we will say so.
Ascendryx