ZZ CYBER · UPDATED 8 SEPTEMBER 2026
External Exposure Snapshot
A limited review with clear boundaries.
The no-cost External Exposure Snapshot is an introductory security-hygiene review, subject to availability and written scope acceptance. It is not a penetration test, comprehensive vulnerability assessment, audit, certification or guarantee of security.
What is included
The proposed scope is one agreed business domain. The review may cover public DNS and email-security records, certificate information and visible website security headers. The output is a short observations summary with suggested next steps, not proof that every vulnerability has been identified. Findings reflect the agreed scope and time of review.
Authorisation comes first
No assessment begins merely because a domain is submitted. An authorised asset owner must approve the exact assets, methods, timing, exclusions and point of contact in writing. Authority over a domain does not automatically grant permission to test its hosting provider, payment provider, SaaS platform or other third-party infrastructure.
Activities outside this offer
- Exploitation or attempts to bypass authentication.
- Password attacks, credential testing, phishing or social engineering.
- Denial-of-service, stress testing or disruptive scans.
- Intrusive vulnerability scanning, access to private systems or collection of private data.
- Testing third-party assets without separate permission.
- Remediation implementation, continuous monitoring or incident response.
Information and findings
Only the minimum information needed for the agreed review should be shared. Findings are provided privately to the agreed contact. If unexpected sensitive information or a potential service issue is encountered, the review should stop and the owner should be contacted. Secure exchange and retention arrangements must be agreed before any confidential evidence is transferred.
Next steps
The review carries no obligation to purchase further work. Any follow-up assessment or remediation support is separately scoped and agreed. Further testing is never implied by receipt of the snapshot. Before proceeding, both parties must confirm the engagement conditions, handling arrangements and any necessary third-party permissions.