Skip to main content
FREE · NO LOGIN · NO CARD

Free Security Check for Your Business

See what a hacker can see about your business. No login. Report in your inbox within 2 business days.

A plain-English report on every security gap visible from the public internet — open ports, expired certificates, email spoofing risks, known software weaknesses. No card. No drip campaign — at most 3 relevant emails over 6 months, and STOP kills it forever.

REQUEST YOUR FREE SCANBOOK A 15-MIN FIT CALL

Personally reviewed · Australian-owned · ABN 34 318 502 254

$ nmap -sV --top-ports 15 [redacted].com.au
PORT STATE SERVICE VERSION
443/tcp open ssl/http nginx 1.18.0 (TLSv1.3 OK · cert 41d to expiry)
3306/tcp open mysql MySQL 5.7.42 -> EOL Oct 2023, unsupported, public CVEs apply
21/tcp open ftp vsftpd -> cleartext auth, exposed to public internet

Every line is a real fingerprint pattern I surface. Findings on your scan are anchored to a reproducible nmap command and matched to NVD.

I Ran This Check on Myself First

If my own business's check had come back clean before I published it, I'd have been the only compliance operator with no story to tell. It didn't. Six findings, all published verbatim. Four resolved or accepted with reasoning since; two remain open.

RESOLVED

Missing Content-Security-Policy

CSP shipped via <meta http-equiv> in app/layout.tsx. default-src 'self' + script/style 'unsafe-inline' for Next.js inline blocks + /cdn-cgi/scripts/ for Cloudflare. connect-src extended to https://api.titanos.tech so the /scan-request form can POST cross-origin.

RESOLVED

Missing X-Frame-Options

X-Frame-Options: SAMEORIGIN now served by Cloudflare Managed Transform ‘Add security headers’.

OPEN

Missing X-XSS-Protection

Header is deprecated in modern browsers (Chrome/Edge ignore it). CSP covers the same threat model in 2026 browsers. Not planning to add.

RESOLVED

Missing Referrer-Policy

Referrer-Policy: same-origin (stricter than recommendation) served by Cloudflare Managed Transform. Belt-and-braces <meta name='referrer'> in app/layout.tsx.

PARTIAL

Missing Permissions-Policy

Site uses none of those APIs. Cloudflare Transform Rule to deny them is queued. No functional risk in the interim.

OPEN

Information disclosure — Server header

Trade-off: keeping Server: cloudflare lets clients debug DNS/CDN issues. The disclosure is harmless because Cloudflare's role here is verifiable from any whois / DNS lookup anyway.

Full scan run 2026-06-01 · TLS 1.3 · 0 open ports (Cloudflare-fronted) · 0 cleartext services · 0 DB exposure. Last re-verified 11 July 2026 — TLS 1.3 confirmed, certificate valid through 30 August 2026.

Want to see what a full evidence pack looks like? See my own evidence pack, published in full →

What It Is · Who It's For

What It Is

  • A check of what a hacker can see about your business from the public internet — every finding reproducible with one command
  • 90-day window before any finding is published — your time to fix it first
  • No break-in attempts, no password guessing, no overloading your site — ever
  • Every finding verifiable: I show you the exact check I ran so you can confirm it yourself
  • Personally reviewed before delivery — no auto-generated noise

Who It's For

  • Any AU/NZ/SG business with a website that wants to know what a hacker can see
  • Business owners who have heard about the December 2026 privacy deadline and want to understand their gaps
  • IT leads or founders about to roll out new software and want an outside check first
  • Businesses about to renew a managed IT contract — verify what you're actually getting
  • Anyone who wants a plain-English report, not a sales pitch

The Full Process

Five steps from form-submit to report-in-inbox. No mystery, no opaque hand-offs.

Tell me your domain

Your domain, your name, anything I should know. Under a minute.

I queue your scan

You’re placed in the daily scan queue. No payment, no waiting-list game.

Scan runs

Standard port scan, encrypted-connection check (TLS/SSL), email security records (SPF/DKIM/DMARC), certificate lookups, and known software vulnerability matching by version.

Report delivered

Hosted HTML report linked from an email to your inbox — within 2 business days.

You decide what’s next

Fix it yourself, escalate to your host, or ask me for help. No pressure, no auto-renewal.

What's Inside the Report

One report, every finding ranked, every finding reproducible.

  • Services visible from the internet — what ports are open and what software is running on them
  • Database exposure flags — any database port reachable from the public internet (a serious risk)
  • Encrypted connection check — certificate validity, expiry, and protocol versions (TLS/SSL)
  • Known software vulnerability matches — any published weakness in the software versions you're running
  • Email security records — SPF, DKIM, DMARC, CAA (the records that stop hackers spoofing your domain)
  • Host split — what you control vs what your hosting provider controls (so you know who needs to fix what)
  • Severity ranking (Critical / High / Medium / Low / Info) with a plain-English remediation step per finding
  • Verification command for every finding — run the same check yourself in 30 seconds

How the Check Works

I only read what your server already broadcasts to the public internet — the same information a hacker sees. Nothing invasive.

What I Check

Open ports and services (standard port scan)

Encrypted connection check (TLS/SSL)

Email security records + certificate lookups

Known software vulnerabilities, by version

What I Never Do

Log in or try passwords

Attempt to break in

Overload your site

Access or extract your data

Full methodology

Request Your Free Scan

Fill the form. Report lands in your inbox within 2 business days, sent personally. Prefer a call? Book a 15-min instead.

By requesting a scan you consent to receive your report plus up to 3 related follow-ups over 6 months. Reply STOP to anything and you're suppressed forever. I never sell your data.

Delivered within 2 business days.

Prefer a call? Book a 15-min fit call →

What Comes After the Scan

Most teams use the free scan to decide whether they need the Compliance engagement or an AI build. Here’s where each fits.

Titanos Monitor

If the check is clean today but you want to know when something changes, Monitor re-checks your business every month and emails you what’s new — plus a briefing on any privacy law updates relevant to your industry. AU$149/mo. Cancel in one click.

See Monitor

Privacy Act Compliance

If the check finds gaps and the 10 December 2026 privacy law deadline matters to you, the compliance engagement is the next step. One done-with-you call where I apply every change with you — privacy policy, email security, login security, the works.

See the compliance pack

AI That Does Your Manual Work

If the security check is clean and your real bottleneck is a manual task eating your team’s week, scope an AI build with me. Free call first, fixed-price quote, shipped working.

See AI Implementation

Questions I Get

See What a Hacker Can See — for Free

Personally reviewed, delivered within 2 business days. No card, no login required.

REQUEST YOUR FREE SCANBOOK A 15-MIN FIT CALL

Built with AI assistance. Every scan finding is reviewed and signed off by Kyle Deligny (ABN 34 318 502 254) before delivery. My ABN is on every page — the accountability is mine.

Book Free AI Audit Call