By emailing or booking, you're requesting your scan report. We'll also send up to 3 related follow-ups over 6 months — reply STOP at any point and you're suppressed forever. We never sell your data.
WHAT COMES AFTER THE SCAN
Most teams use the free scan to decide whether they need the Compliance engagement or an AI build. Here’s where each fits.
PRIVACY ACT + ESSENTIAL EIGHT COMPLIANCE
If the scan surfaces gaps and the 11 December 2026 Privacy Act deadline matters to you, the compliance engagement is the next step. One done-with-you call where we apply the changes together.
If the scan shows you’re solid on basics and your real bottleneck is an AI capability you can’t free up engineering hours to ship, scope a build with us. Quoted by scope, fixed-price SOW.
Your scan is queued the moment you submit. The report is delivered to your inbox within 1 business day. Most run faster than that — the SLA is just the worst-case promise.
The scan still works. We split findings into what you control vs what your hosting provider controls, so you don’t walk away with a list of things you can’t fix. Host-controlled findings come with the exact escalation language to send the provider.
No. External-only — no exploitation, no credential attempts. We probe what the public internet can already see — service banners, TLS posture, DNS records, certificate transparency. No authentication attempts. No exploit attempts. No DoS. No data exfiltration. Full methodology at /methodology.
Scan results are kept for our scan corpus so we can show longitudinal exposure trends. Your email goes only into our lead store — never sold, never shared with third parties, suppressed forever if you reply remove.
READY TO SEE WHAT AN ATTACKER SEES?
Free, expert-reviewed, delivered within 1 business day. No card, no login, no follow-up sequence.