Frequently asked questions

Straight answers before you provide access or authorize testing.

These questions cover the engagement model shared across services. Service pages contain additional questions specific to audits, malware response, server reviews, penetration testing, and ongoing care.

Never send credentials, private keys, backup archives, or confidential source code through this website.

Testing
Authorized and manually validated
Production
Constraints agreed before active work
Access
Temporary and least privilege
Credentials
Never submitted through this website

Choosing a service

Audit, incident response, penetration testing, or ongoing care?

Your situationStarting point
You want to find weaknesses before an incidentWordPress security audit
You run a WooCommerce store and need the store-specific reviewWooCommerce security audit
The site is redirecting, infected, suspended, or repeatedly compromisedMalware removal and hardening
You need host-level review of Linux, SSH, web server, PHP, or isolationLinux web server security audit
You need adversarial testing of custom behavior, roles, or APIsWordPress penetration testing
Cloudflare sits in front of the site and nobody owns its configurationCloudflare security management
You already have a baseline and need continuing oversightManaged WordPress security

Common questions

Questions about this engagement

Is this an automated scan?

No. Tooling is used where it improves coverage, but every reported vulnerability is manually reviewed before it appears as a confirmed finding.

Will testing affect production availability?

Production constraints and testing windows are agreed before active testing. Destructive testing is not performed unless separately and explicitly authorized.

What access will you need?

It depends on the objective. Work may begin externally. Credentialed review uses a named, temporary, least-privilege account arranged after scoping.

Can you fix findings as well as report them?

Yes, where agreed. Remediation can also be delivered as guidance for your developers, host, or administrators.

How are credentials exchanged?

Never through this website or ordinary email. A secure exchange method is agreed after the scope and engagement terms are in place.

Do you guarantee that a site will never be hacked?

No responsible assessment can guarantee future security. The work documents observed risk, improves controls within scope, and identifies unresolved dependencies.

Can you work under an NDA?

Yes. An NDA can be completed before detailed scoping when required.

Do you test sites without authorization?

No. Active testing requires written authorization from the system owner or an authorized representative.

What does retesting cover?

Retesting verifies the specific agreed remediation. It is not a new full assessment unless that wider work is separately scoped.

What should the first inquiry include?

Provide the domain, service or concern, relevant deadlines, business impact, and a non-sensitive environment summary. Do not include passwords, keys, backups, or confidential source code.