Service
Web Assessment
Focused web application and website security assessment for UK SMEs — practical findings, clear fixes, authorised scope only.
A Web Assessment is a focused review of websites and web applications for common vulnerabilities, configuration issues, authentication weaknesses and avoidable exposure. It is for UK startups, SMEs, agencies and SaaS teams that want practical assurance without agency overhead — delivered by the specialist doing the work.
This is not a vague promise to cover everything under the sun. It is a scoped engagement against assets you authorise, with clear prerequisites, careful testing windows and a report your team can action. If you primarily need internet-wide asset discovery, public OSINT, or firewall rule analysis, we will steer you to External Infrastructure, OSINT or Firewall instead of stretching the Web label.
What it is
Web assessments concentrate on the applications your customers and staff actually use: marketing sites with forgotten admin paths, client portals, lightweight SaaS front ends, and the authentication flows that protect them. We look at OWASP-style issue classes in a pragmatic way — the problems that show up repeatedly in SME estates — rather than performing theatre for its own sake.
Typical themes include injection and input handling issues where relevant, authentication and session weaknesses, access control mistakes, misconfigurations, sensitive information exposure through the application layer, and security headers or TLS-related weaknesses that undermine trust. The emphasis is always on evidence, business impact and fix guidance.
Who it is for
You are a good fit if you run a website or portal that matters to revenue or reputation, you can authorise testing, and you want a clear first pass rather than an endless programme. Agencies looking after client sites should involve the client in authorisation. Product teams preparing for customer security questions often start here when the application is the main concern.
You are a weaker fit if you cannot identify an owner for the application, if you want unauthorised testing of someone else’s site, or if your real question is “what do we expose on the internet?” without a specific app in mind — that is often External Infrastructure first.
What we need
Authorisation from someone who can approve testing. A list of URLs and environments in scope. Clarity on production versus staging. Test accounts if authenticated areas matter. Contacts for emergency stop. Any fragile areas or rate limits we should respect. Notes on third-party components that are out of bounds.
We will not proceed on third-party targets without permission. We will not invent scope mid-engagement without agreement. The scope and prerequisites call exists to lock these details before work starts.
What you get
Prioritised findings with critical and high-risk issues first. Evidence such as screenshots or technical proof where appropriate. Plain-English risk context. Practical remediation steps. A debrief call to walk through the report. An optional retest after you have fixed what matters.
You also get founder-led continuity: the person who scoped and tested is the person explaining the results. No junior handoff. No inflated agency language.
What we will not do
We will not assess applications you cannot authorise. We will not claim a focused Web review is every possible security activity. We do not sell a CE+ product. We do not advertise that we look at any company. Destructive testing outside agreed rules, work on out-of-scope third parties, and surprise expansions are off the table.
If during the work we spot strong reasons to consider Infrastructure, OSINT or Firewall follow-up, we will say so as a recommendation — not as silent scope creep.
How it fits the 3-call process
Free intro call to confirm Web is the right starting point. Scope and prerequisites call to lock authorisation and assets. Assessment and report. Debrief call to turn findings into actions. That rhythm keeps SME engagements finishable.
Example starting scenarios
A client portal that grew authentication features quickly. A marketing site with an old CMS admin path. A SaaS trial environment that shares patterns with production. A customer asking for evidence you take application security seriously before signing. In each case, a focused Web Assessment gives you something concrete to fix and something concrete to show — without pretending one engagement solves every security problem in the business.
On the free intro call we will sanity-check whether Web is truly first, or whether External Infrastructure should map exposure before we spend time deep in one application. That sequencing advice is part of founder-led delivery.
Fit with the rest of the site
Web Assessment is one of four services. Many buyers arrive through the free intro call unsure whether their portal issue is really an application problem or an exposure problem. That is a normal starting point. We would rather redirect you to External Infrastructure or Firewall than force a Web engagement that answers the wrong question.
After delivery, optional retest helps confirm that authentication fixes, configuration changes and exposure removals actually landed. Pair that with the debrief so non-technical stakeholders understand what “done” means.
Authorised scope and inbound buying
We only assess applications you own or are authorised to commission. Inbound enquiries are welcome; we do not cold-spray prospects or invent CE+ certification products. Free intro is a fit conversation — written authorisation and a locked scope come before any testing.
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.