Services

One clear entry. Deeper when needed.

Start with an Outside-in Web Assessment for your production app. Use the Free Brief only to orient and choose depth. User-level and Inside-assisted are scoped upgrades.

Included

You receive

What happens

  1. Scoping call and written authorization (rules of engagement)
  2. Isolated assessment of the agreed public surface
  3. Evidence review and clear reporting
  4. Remediation call, then one bounded retest

Free Brief vs Outside-in

Free Exposure Brief

  • A short orientation memo: what stands out, how sure we are, and what’s out of scope
  • Recommends the right assessment depth
  • Does not validate findings or replace a paid assessment

Outside-in assessment

  • Validated findings with evidence, severity, and remediation
  • Executive summary plus technical report
  • Remediation call and one bounded retest

Scoped upgrades

Add accounts, roles, or internal knowledge when the application requires it.

  • User-level

    See what a normal user or role can overreach after login.

    • You provide: test logins for the roles that matter
    • We review: portals, privilege edges, and account abuse paths
    • You get: prioritized findings and practical remediation

    Not included: source walkthrough or design review with your leads (that’s Inside-assisted).

  • Inside-assisted

    Trace deep design and implementation flaws with your maps and leads in the room.

    • You provide: docs, code access, and technical leads
    • We review: root causes behind high-stakes surfaces
    • You get: root-cause findings and a remediation roadmap

    Not included: a free public-surface scan alone — this is a scoped, assisted engagement.

Every paid engagement includes fix guidance. Retest when fixes land — one bounded retest on Outside-in; more via ongoing coverage.

Common questions

FAQ

How is Truehat different from an automated scan?

Scans list findings. Truehat interprets what outsiders can actually reach and what matters to the business — short memos and reports with fix guidance, not raw tool output.

What is included in the Free Exposure Brief?

An authorized look at your public web surface and a short decision-maker memo (orientation only). Enough to choose depth before a paid assessment — not validated findings or a substitute for Outside-in.

How does Free Brief differ from paid Outside-in?

The Brief orients and recommends depth. Outside-in delivers validated findings, evidence, severity, remediation guidance, a remediation call, and one bounded retest under written rules of engagement.

Do you need written authorization before testing?

Yes. We confirm scope and authorization before any review. No destructive testing, and no work on domains you cannot authorize.

What happens after the brief?

Act on the memo, book an Outside-in assessment (or an upgrade), or stop — no obligation to continue.