What Can an Outsider Reach?
Review the agreed public-facing website and services to identify relevant exposure visible without signing in.
Authorized external or authenticated testing turns suspected exposure into validated findings, clear priorities, and a practical remediation plan—not just a scanner export.
Published Options From $150 Scope Confirmed Before Testing
Written authorization and defined targets are required before any testing begins.
Automated tools can surface candidates—and noise. MHCS checks relevant findings, documents supporting evidence, and explains the security impact in plain language.
That gives you a basis for choosing what to fix, what can wait, and what needs a different investigation.
The appropriate method depends on what is in scope and what access can be safely arranged.
Review the agreed public-facing website and services to identify relevant exposure visible without signing in.
With an approved test account, examine relevant functionality and access controls that a public-only review cannot see.
Recheck specified findings after remediation. A retest is narrower than a new full assessment.
Compare external testing, authenticated testing, and an option that includes a follow-up retest. We confirm fit and written authorization before committing to a package.
$150 Fixed Price
Best for: You need a clear view of externally visible exposure before deciding what to fix.
Authorized external assessment · Manual validation of relevant findings
Typical Delivery: 2 days
$300 Fixed Price
Best for: You need insight into risks behind an approved user login.
External and authenticated testing · Manual validation of relevant findings
Typical Delivery: 3 days
$450 Fixed Price
Best for: You want a remediation roadmap and one retest after fixes are made.
Full external and authenticated assessment · Technical and executive reporting
Typical Delivery: 5 days
About the published prices: The fixed price applies to the agreed package scope. Final fit depends on the application, permitted targets, authentication needs, and testing constraints. Additional systems or work are quoted separately. Typical delivery is an estimate after scope and access are ready.
Assessments are planned with the site owner so the targets, methods, and business constraints are explicit.
Tell us the domain, concern, and important customer functions—without sending credentials or sensitive records.
Agree on targets, authorization, testing constraints, timing, and any account access needed.
Run the permitted checks and manually review relevant findings before reporting them.
Use the evidence, priorities, and recommendations to plan remediation or a scoped follow-up.
The deliverable is a clear picture of agreed website risk. It is not a promise that every vulnerability will be found or that issues will be fixed during testing.
Remediation, malware cleanup, application-code changes, and continuous monitoring require separate scope unless specifically agreed.
If the site is unavailable, exposing data, or under active attack, describe the business impact before choosing a planned assessment. MHCS offers triage during U.S. business hours, not 24/7 response.
Request Business-Hours TriageNo. Findings are reviewed, validated, prioritized, and translated into practical remediation recommendations.
No. Testing begins only after written authorization and confirmation of the permitted targets and methods.
The assessment provides evidence and recommendations. Remediation or configuration changes can be scoped separately.
With an approved test account, authenticated testing can examine behavior available after login, including relevant user roles and workflows. Access is arranged separately using a least-privilege method; never send credentials through the contact form or email.
The retest checks agreed findings after you have made fixes; it is not a new full assessment or a guarantee that every issue has been removed. The published Complete Assessment option includes one retest within 60 days, subject to the agreed scope.
The displayed options are fixed-price starting scopes. We confirm the application, targets, authentication needs, and testing constraints before committing to a package. Work outside the agreed scope is quoted separately.
Tell us what you want to learn, which website is in scope, and whether authenticated testing may be useful. We’ll confirm the appropriate option before testing begins.