Skip to main content
CloudKey

Fixed-scope security assessment

Security Snapshot: know your exposure in days, at a fixed price

A Security Snapshot is a one-time, fixed-price assessment of what an outsider can see and reach: your internet-facing systems, plus credentials and data already exposed on the dark web. Human-triaged, ranked by real risk, delivered as one report you can act on.

You are not signing up for a months-long engagement or an open-ended consulting bill. You authorize the scope in writing, we assess it, a human removes the noise, and you get a debrief call with a clear fix list. Most engagements land between $750 and $1,500, quoted before we start.

  • Fixed price, quoted upfront
  • Signed authorization first
  • Human-triaged findings
  • Report and debrief in days
12

Findings after triage

  • Staff credentials in a public breach dump 3 accounts
  • Exposed admin panel on a forgotten subdomain legacy-app
  • Edge service with a known exploited CVE vpn-gw
  • TLS certificate close to expiry www

Illustrative findings, not a real assessment. Your report shows your own exposure, triaged and ranked by a human.

Overview

The first honest look most teams never get

Most small and mid-sized organizations have never seen themselves the way an attacker does. Not because they do not care, but because the usual options are a raw scanner dump nobody can read or a full penetration test that costs five figures and takes weeks to schedule. So the question "how exposed are we, right now?" stays unanswered.

The Security Snapshot exists to answer exactly that question, quickly and at a price a small team can approve without a budget cycle. We map your internet-facing systems, check them for known weaknesses, and search dark web sources for credentials and data tied to your domains. Then a human goes through everything, removes the false positives, and ranks what is left by how exploitable it is and what it would cost you, prioritized by KEV listing and EPSS percentage, not just raw severity scores.

You end up with one report: what we found, why it matters, and what to fix first. If something needs deeper, hands-on validation, we say so plainly and scope it separately. If everything looks solid, the report says that too.

The shape of the engagement

Small scope, fast turnaround, one clear output

$750+
Fixed price, quoted after a 20-minute scoping call
5
Business days, typical time from authorization to report
1
Prioritized report with a debrief call included

These figures describe the scope and shape of a typical engagement, not performance metrics or guaranteed results. Complex estates are quoted individually.

What is included

What does a Security Snapshot cover?

Four pieces, combined into one picture of your exposure.

External exposure assessment

We map your internet-facing systems: domains, subdomains, exposed services and admin interfaces. Each one is checked for known vulnerabilities and risky configurations, with findings prioritized by KEV listing and EPSS percentage.

Dark web exposure check

We search breach dumps and dark web sources for leaked credentials, exposed employee accounts and mentions of your domains, so you know what attackers already hold before they use it.

Human triage

A security engineer reviews every finding, removes the false positives and duplicates, and ranks the rest by real exploitability and business impact. You read a short list, not a scanner export.

Report and debrief

One report with an executive summary your leadership can read and a technical fix list your team can execute, walked through together on a 30-minute debrief call.

Nothing runs before you sign

A Security Snapshot only assesses systems you own or are authorized to have assessed. Before anything runs, we agree the exact scope in writing and you sign an authorization covering it. That single page of paperwork is how professional security work is done, and it protects both of us. Findings that would need active exploitation to confirm are flagged for a separately scoped penetration test with its own signed Rules of Engagement.

How it works

From first call to fix list in about a week

Five steps, no surprises, fixed quote before anything starts.

  1. 01

    Scope

    A 20-minute call to list your domains and internet-facing systems. You get a fixed quote and a written scope, and you sign the authorization.

  2. 02

    Assess

    We map and assess the agreed scope: exposed services, known vulnerabilities, risky configurations and dark web exposure tied to your domains.

  3. 03

    Triage

    A security engineer removes false positives and ranks the real findings by exploitability and business impact.

  4. 04

    Report

    You receive one prioritized report: executive summary, findings with evidence, and a concrete fix list ordered by risk.

  5. 05

    Debrief and re-check

    We walk through the report together on a 30-minute call. Once you fix the critical findings, we re-check them within 30 days at no extra cost.

FAQ

Security Snapshot, answered

No. A Snapshot assesses and ranks your exposure; it does not attempt to exploit anything. When a finding genuinely needs hands-on validation, we flag it and scope a penetration test separately, with its own signed Rules of Engagement. That keeps the Snapshot fast and affordable, and keeps testing where it belongs: under explicit authorization.

From $750, fixed. The exact quote depends on the size of your external footprint and is confirmed after a 20-minute scoping call, before anything is signed. Most engagements land between $750 and $1,500. Larger or more complex estates are quoted individually.

Typically 5 business days from signed authorization to delivered report, with the debrief call scheduled the same week. Timelines are confirmed at scoping.

A list of your domains and any internet-facing systems you want covered, a signed authorization for that scope, and one contact for questions during the engagement. We do not install agents or change anything on your systems, and your team does not need to prepare anything.

You get a concrete fix list ordered by risk, and we re-check your fixed critical findings within 30 days at no extra cost. If you want the deeper follow-up, findings flow naturally into a penetration test, a security audit, or continuous monitoring with VulnMonitor.

That is what VulnMonitor is for: it reconciles new CVEs against your real asset inventory continuously and ranks them by KEV and EPSS percentage. A Snapshot is the natural starting point; VulnMonitor keeps the picture current afterwards.

Next step

See what an outsider sees

One scoping call, one fixed quote, one report you can act on. Signed authorization before anything runs.