What kinds of exposure do you look for?
Common examples are forgotten logs and import files, backup or configuration copies, dependency manifests, source maps, test and installer scripts, publicly listed documents, REST endpoints returning data without authentication, exposed admin or service subdomains, incorrect HTTPS redirects and overly broad session cookies.
Is this a penetration test?
No. This is a non-intrusive review of the public web surface. We identify and verify externally observable exposure, but do not log in, submit attack payloads or exploit vulnerabilities. It is not a substitute for an authenticated pentest.
Can this review damage my website?
The review uses low-rate DNS, TLS, HTTP HEAD/GET/OPTIONS requests and passive inspection. It excludes brute force, load testing, form submissions, file uploads and exploitation, and starts after payment.
What happens if you find something serious?
We document the evidence, explain the likely impact and give you a prioritized remediation path. We do not publish findings or contact third parties without your permission.
Does the report prove my website is secure?
No. The report describes the reviewed public surface, confirmed findings, important checks that returned no result and the limitations of an external review at a specific time. It cannot inspect your database, server filesystem or private systems.
How does the money-back guarantee work?
If you are not satisfied with the completed review, request a refund within 7 days of delivery and we will return the full $99 payment.
Can TUNDRÄ fix the findings?
Yes. Your report can be turned into a ready-to-start TUNDRÄ development backlog. Remediation is quoted separately and never required to receive the report.