Free Cybersecurity Audit

We check your domain against seventeen external security tests and ask a few questions about the things no external test can see. You get a scored report in about a minute.

Everything we examine is already public — DNS records, certificate transparency logs, and published scan data. We do not attempt to access, probe, or log into anything you own.

About your organisation

The domain your website and email use, for example aetsolutions.ca

We email a link to confirm the address. Your report is not shown until you click it.

We only assess information that is already public, but we still need your confirmation before we begin.

If your website sits behind Cloudflare or a similar service, the addresses we can see belong to that provider rather than to you. Telling us your own addresses lets us check them for exposed services and known vulnerabilities. Public addresses only — never internal ones such as 192.168.x.x.

Identity and access

This is the single most effective control against account takeover, and it cannot be observed from outside.

Including IT staff, service accounts used by people, and third-party support access.

Operational resilience

An untested backup is a hope, not a control. This is where most ransomware recoveries actually fail.

Ransomware deliberately targets backups reachable from the network it has compromised.

For example Windows Server 2012, or an unsupported line-of-business application.

People and preparedness

The question that matters at 2am is not whether a plan exists, but whether anyone can find it.