Free Exposure Brief

Submit your domain

We’ll reply with a short exposure memo. No obligation.

The main site or app to review.
Add more domains

Short business memo with clear next steps.See a sample memo

Request received.

We’ll reply within 2 business days from engagements@truehat.com.

  1. Contact
  2. Book
  3. Done

Request received.

We’ll reply within 2 business days from engagements@truehat.com.

Want us to reach you faster?

Optional — role and phone help us contact the right person.

Your role

Outsider view. Clear priorities.

See what outsiders can reach on your web apps.

Authorized review of your public surface. A short memo you can act on — with clear next steps.

  • Written authorization required
  • Privacy-first by design

How we assess

Start Outside-in. Go deeper only if you need to.

Most teams begin with a fixed Outside-in package for one production app. Accounts and internal access are scoped upgrades when you need them.

  • Outside-in

    Public surface only — no logins. Validated findings with evidence.

    • From you: authorization and domains
    • Answers: what can a stranger reach without login?
    • You get: validated findings, evidence, severity, and a fix path
    • Choose when: you need a paid assessment of public exposure

    Best for:A clear picture of what the public internet can already see

    External

    See Outside-in package
  • User-level

    Test accounts for the roles that matter after login.

    • From you: test logins for the roles that matter
    • Answers: what can a normal user abuse or overreach?
    • You get: prioritized findings and a remediation path
    • Choose when: portals, roles, or customer accounts are in play

    Best for:Apps where the real risk starts after login

    After login

    See upgrades
  • Inside-assisted

    Your docs and team help us go deeper on design and code.

    • From you: docs, code access, and technical leads
    • Answers: where are the deep design and code flaws?
    • You get: root-cause findings and a remediation roadmap
    • Choose when: stakes are high or a surface review raised harder questions

    Best for:Critical systems that need depth, not guesswork

    With your team

    See upgrades

Every paid engagement includes fix guidance and a retest after fixes land.

Free Brief vs Outside-in

The Brief orients. Outside-in validates.

Free Exposure Brief

  • A short orientation memo: what stands out, how sure we are, and what’s out of scope
  • Recommends the right assessment depth
  • Does not validate findings or replace a paid assessment

Usually 1–2 business days. Orientation only.

Request free brief

Outside-in assessment

  • Validated findings with evidence, severity, and remediation
  • Executive summary plus technical report
  • Remediation call and one bounded retest

After written authorization and engagement.

See Outside-in package

View a sample Exposure Brief

Common triggers

Teams usually come when something is about to change.

  • Launch
  • Enterprise customer
  • Security questionnaire
  • Diligence

FAQ

Do you scan without authorization?

No. Every review — including the Free Exposure Brief — requires written authorization from someone who can approve testing on the submitted domains. We do not run destructive tests.

How does Free Brief differ from paid Outside-in?

The Brief orients and recommends depth. Outside-in delivers validated findings, evidence, severity, remediation guidance, a remediation call, and one bounded retest under written rules of engagement.

How long does an assessment take?

The Free Exposure Brief usually returns in 1–2 business days. A paid Outside-in assessment is typically 3–5 working days of assessment work after scoping and written authorization — timing is confirmed on the scoping call.

What do you need from us?

For the Free Brief: primary domain, work email, and authorization to review the public surface. For paid Outside-in: written rules of engagement and agreed domains. Upgrades may add test accounts or internal access when scoped.

Is our data kept private?

Yes. Client data and evidence stay inside the engagement. We minimize what we collect, protect artifacts during the work, and tear down engagement environments when it ends. We do not publish client findings.

What happens after the Brief?

Act on the memo, book an Outside-in assessment (or an upgrade), or stop — no obligation to continue.

Ready to understand your exposure?

Start with a free brief. No obligation.