See what a hacker can see about your business. No login. Report in your inbox within 2 business days.
A plain-English report on every security gap visible from the public internet — open ports, expired certificates, email spoofing risks, known software weaknesses. No card. No drip campaign — at most 3 relevant emails over 6 months, and STOP kills it forever.
Personally reviewed · Australian-owned · ABN 34 318 502 254
EXAMPLE OUTPUT · REDACTED
$ nmap -sV --top-ports 15 [redacted].com.au
PORT STATE SERVICE VERSION
443/tcp open ssl/http nginx 1.18.0 (TLSv1.3 OK · cert 41d to expiry)
3306/tcp open mysql MySQL 5.7.42 -> EOL Oct 2023, unsupported, public CVEs apply
21/tcp open ftp vsftpd -> cleartext auth, exposed to public internet▋
Every line is a real fingerprint pattern I surface. Findings on your scan are anchored to a reproducible nmap command and matched to NVD.
I Ran This Check on Myself First
If my own business's check had come back clean before I published it, I'd have been the only compliance operator with no story to tell. It didn't. Six findings, all published verbatim. Four resolved or accepted with reasoning since; two remain open.
RESOLVED
Missing Content-Security-Policy
CSP shipped via <meta http-equiv> in app/layout.tsx. default-src 'self' + script/style 'unsafe-inline' for Next.js inline blocks + /cdn-cgi/scripts/ for Cloudflare. connect-src extended to https://api.titanos.tech so the /scan-request form can POST cross-origin.
RESOLVED
Missing X-Frame-Options
X-Frame-Options: SAMEORIGIN now served by Cloudflare Managed Transform ‘Add security headers’.
OPEN
Missing X-XSS-Protection
Header is deprecated in modern browsers (Chrome/Edge ignore it). CSP covers the same threat model in 2026 browsers. Not planning to add.
RESOLVED
Missing Referrer-Policy
Referrer-Policy: same-origin (stricter than recommendation) served by Cloudflare Managed Transform. Belt-and-braces <meta name='referrer'> in app/layout.tsx.
PARTIAL
Missing Permissions-Policy
Site uses none of those APIs. Cloudflare Transform Rule to deny them is queued. No functional risk in the interim.
OPEN
Information disclosure — Server header
Trade-off: keeping Server: cloudflare lets clients debug DNS/CDN issues. The disclosure is harmless because Cloudflare's role here is verifiable from any whois / DNS lookup anyway.
Full scan run 2026-06-01 · TLS 1.3 · 0 open ports (Cloudflare-fronted) · 0 cleartext services · 0 DB exposure. Last re-verified 11 July 2026 — TLS 1.3 confirmed, certificate valid through 30 August 2026.
›A check of what a hacker can see about your business from the public internet — every finding reproducible with one command
›90-day window before any finding is published — your time to fix it first
›No break-in attempts, no password guessing, no overloading your site — ever
›Every finding verifiable: I show you the exact check I ran so you can confirm it yourself
›Personally reviewed before delivery — no auto-generated noise
Who It's For
›Any AU/NZ/SG business with a website that wants to know what a hacker can see
›Business owners who have heard about the December 2026 privacy deadline and want to understand their gaps
›IT leads or founders about to roll out new software and want an outside check first
›Businesses about to renew a managed IT contract — verify what you're actually getting
›Anyone who wants a plain-English report, not a sales pitch
The Full Process
Five steps from form-submit to report-in-inbox. No mystery, no opaque hand-offs.
I
Tell me your domain
Your domain, your name, anything I should know. Under a minute.
II
I queue your scan
You’re placed in the daily scan queue. No payment, no waiting-list game.
III
Scan runs
Standard port scan, encrypted-connection check (TLS/SSL), email security records (SPF/DKIM/DMARC), certificate lookups, and known software vulnerability matching by version.
IV
Report delivered
Hosted HTML report linked from an email to your inbox — within 2 business days.
V
You decide what’s next
Fix it yourself, escalate to your host, or ask me for help. No pressure, no auto-renewal.
What's Inside the Report
One report, every finding ranked, every finding reproducible.
✓Services visible from the internet — what ports are open and what software is running on them
✓Database exposure flags — any database port reachable from the public internet (a serious risk)
Most teams use the free scan to decide whether they need the Compliance engagement or an AI build. Here’s where each fits.
Titanos Monitor
If the check is clean today but you want to know when something changes, Monitor re-checks your business every month and emails you what’s new — plus a briefing on any privacy law updates relevant to your industry. AU$149/mo. Cancel in one click.
If the check finds gaps and the 10 December 2026 privacy law deadline matters to you, the compliance engagement is the next step. One done-with-you call where I apply every change with you — privacy policy, email security, login security, the works.
If the security check is clean and your real bottleneck is a manual task eating your team’s week, scope an AI build with me. Free call first, fixed-price quote, shipped working.
Your scan is queued the moment you submit. The report is delivered to your inbox within 2 business days. Most run faster than that — the SLA is just the worst-case promise.
The scan still works. I split findings into what you control vs what your hosting provider controls, so you don’t walk away with a list of things you can’t fix. Host-controlled findings come with the exact escalation language to send the provider.
No. I only read what the public internet can already see — service names and versions, certificate details, email security records. No login attempts. No break-in attempts. No overloading your site. No data access. Full methodology at /methodology.
Scan results are kept in my database so I can track how exposure patterns change across AU businesses over time. Your email goes only into my contact list — never sold, never shared with third parties, suppressed forever if you reply remove.
See What a Hacker Can See — for Free
Personally reviewed, delivered within 2 business days. No card, no login required.
Built with AI assistance. Every scan finding is reviewed and signed off by Kyle Deligny (ABN 34 318 502 254) before delivery. My ABN is on every page — the accountability is mine.