Services
Security Audit
| Tier | Scope | Turnaround |
|---|---|---|
| Surface | External, unauthenticated, ~15 pages | 3-5 days |
| Standard | Surface + one authenticated role, dependency/CMS review, DNS/email, deep TLS | 5-7 days |
| Deep | Standard + manual verification of all highs, hosting/VPS config review, one free retest | ~2 weeks |
Every audit delivers a readable PDF: exec summary, risk-ranked findings with evidence and plain-language fixes, and a one-page “fix first” list.
Remediation
We fix what the audit found — per-finding bundles or hourly. Audit fee credited toward remediation if booked within 30 days.
Secure Build / Rebuild
Mobile-first, SEO-first, fast static sites wherever possible. Ships hardened: security headers, HSTS, pinned dependencies, backups, and a baseline audit included.
Care Plans
| Tier | Includes |
|---|---|
| Watch | Monthly re-scan, CVE/dependency alerts, uptime + SSL monitoring, offsite backups, patching |
| Guard | Watch + quarterly authenticated scan, WAF management, monthly hardening review, staging site |
| Fortress | Guard + monthly manual review, VPS management, log review, incident-response hours |
VPS Setup & Hardening
Move off shared hosting onto an isolated VPS, hardened and managed by Escudiva — better security (no noisy neighbors) and better speed (dedicated resources, which also helps SEO).
Code Review Check
Static analysis (Semgrep/CodeQL + gitleaks) plus a manual review of authentication and input handling — not a full secure-code audit, a focused check.