Website audit
Website Security Audit for Businesses
We examine your website the way an attacker would: looking for a way in, not just running a scanner. Every finding comes with evidence and a fix.
Introductory program
Free security audit
One full engagement at no fee, delivered to the same standard and depth as a paid one. In return we ask for one thing: recognition — permission to reference this engagement in the cyberagent.id portfolio. You may remain anonymous.
When an audit pays for itself
- Before launching a new site, or a feature that touches customer data.
- When you start storing personal data, documents or payments.
- After changing vendors, adding a payment integration, or moving servers.
- As part of procurement, partner due diligence, or internal audit preparation.
- Periodically — code and configuration change with every release.
What we test
- Access control: whether another user's data can be read by changing an ID in a URL or parameter.
- Login and sessions: token lifetime, logout that actually ends the session, login throttling, password reset flows.
- Input handling: SQL injection, XSS, SSRF and related entry points.
- Business logic: coupons, pricing, balances and flows that can be bent without a technical flaw.
- Sensitive data: API keys, credentials and internal files left exposed.
- Server configuration: security headers, TLS, backups and admin panels.
What you receive
| Deliverable | Contents |
|---|---|
| Executive summary | Main risks in language management can act on, plus a fix order. |
| Technical findings | Reproduction steps, evidence, CVSS 3.1 score, business impact and remediation for each issue. |
| Debrief | A walkthrough with your engineers so the fixes are clear to the people implementing them. |
| Re-test | Verification once you have closed the findings. |
No inflated promises. We will not tell you the site is "100% secure" — nobody can. What we commit to: findings that can be reproduced again, explicit testing limits, and honesty about what was not tested.
Frequently asked questions
How long does an audit take?
For a mid-sized application, two to seven working days depending on features and user roles. The report is handed over after a debrief.
Do you need production access?
Not necessarily. If staging exists, we test there. If production is the only option, we restrict ourselves to non-destructive checks and never exfiltrate real customer data.
Audit or penetration test — which do we need?
An audit is broader (configuration, code, process). A penetration test focuses on exploitation. Engagements usually combine both.
Can you work with a limited budget?
Yes, with a narrower scope: one application, no source review, focused on the highest-risk paths such as login, payments and customer data.
Related services
Start with one email to founder@cyberagent.id listing the assets you want tested. You get scoping questions and a written quote back.