GO DIGITAL
The Shield // Website security

Your website, defended.

See your site the way a hacker does — every open door found and closed, then watched every month so it never reopens.

Chapter 1 / 5

Most sites are open right now

Before the pitch, the uncomfortable part: almost every break-in we see used a door that had been standing open for months. Not a clever attack - a known hole nobody closed.

The whole picture

One site. Five shields.

Every defence converging on the one thing that matters — your website — while threats break against the ring.

Chapter 2 / 5

The five ways in

Each one is a real route attackers use, and each is visible from outside without touching your site. Here is what we check, and what it costs you when it is left open.

What we read

Five ways in. Five walls up.

90% of real-world break-ins start with something visible from the outside. The Shield watches every one of them — passively, legally — and hands you the fixes.

01 // Nothing travels in the clear

Encryption

Every login, form and page should be sealed end-to-end. We verify your certificate is valid and modern, HTTPS is enforced everywhere, and HSTS blocks silent downgrades.

  • Valid, current SSL certificate
  • HTTPS enforced sitewide + HSTS
  • Weak / outdated TLS flagged
If ignoredWithout it, anyone on the same wifi can read your visitors' data — passwords included.
02 // The walls that stop injected scripts

Security headers

A handful of HTTP headers decide whether your site shrugs off an attack or hands it the keys. We check every wall is standing.

  • Content-Security-Policy (anti-XSS)
  • Clickjacking + MIME-sniffing blocked
  • Referrer & permissions locked down
If ignoredMiss the CSP and one injected script can hijack sessions, steal logins, deface your pages.
03 // The doors you didn't know were open

Exposure & leaks

We look for the files and version numbers that should never be public — the exact things attackers scan for first.

  • Exposed .env, .git, backup files
  • Leaked versions → known vulnerabilities
  • Debug output & directory listings
If ignoredA single exposed .env can hand over your database password — in plain text, to the world.
04 // Anyone can be you

Email spoofing

Your domain's DNS decides whether a scammer can send email as your brand. We check the records that shut that down.

  • SPF — who's allowed to send
  • DMARC — what happens to fakes
  • DKIM signing present
If ignoredNo DMARC, and criminals email your clients “from you” — phishing them with your name on it.
05 // Hard to win, easy to lose

Reputation & trust

The quiet signals that decide whether browsers, inboxes and customers trust you — watched continuously.

  • Blocklist & malware signals
  • Mixed content on secure pages
  • Cookie safety flags
If ignoredOne blocklist hit and your emails hit spam and your site throws warnings — everywhere at once.
Chapter 3 / 5

Don’t take our word for it

Security is the one thing you should never buy on a promise. So here is the proof: run our scanner on your own site, right now, free - and see your own exposure before you pay us anything.

Free · about 60 seconds · no access needed

Scan your own site before you trust us.

The free Growth Scan includes a live security check — the same passive signals the paid Audit reads. If it comes back clean, we’ll tell you so and you don’t need us. That’s a strange thing for a security company to build, which is rather the point.

  • It runs on your real site, not a demo — your domain, your headers, your exposure.
  • It shows the findings, graded by severity, before any money changes hands.
  • Nothing is touched. Passive signals only — no access, no login, no risk to your site.
Why we give this away

Because the hardest part of selling security is convincing someone there is a problem at all. Showing you your own open doors is more persuasive than any claim we could make — and if there aren’t any, we’d rather you knew.

Chapter 4 / 5

Scan. Close. Watch.

Four steps, in this order, every time - so you always know which stage you are at and what you have actually paid for.

How it works

Scan. Close. Watch.

01ScanWe read your site the way an attacker would — passive, public signals only. No break-ins, ever.
02ReportA clear grade, every open door ranked by risk, and exactly how to close each one.
03FixWant it handled? We close every open door and re-scan to prove it's shut — you touch nothing.
04WatchMonthly monitoring, patching and response — so it never quietly reopens.
Chapter 5 / 5

What it costs, and where to start

Three one-off jobs for three different situations, then three monthly plans if you would rather it never reopened. Every exclusion written down.

Packages

Find it. Fix it. Keep it shut.

Tell us where you are and we'll point at the right one — or browse all six yourself. Every exclusion is written down on each.

Where are you right now?
Start here
“Am I exposed?”

Shield Audit

Find every open door — and exactly how to close it

$250one-time
What you get
  • Full security scan across all five areas
  • Every open door ranked by real risk
  • A step-by-step fix for each one
  • Email spoofing (SPF/DMARC) checked
  • Branded PDF report you keep
What you supply
  • Just your website address — nothing else
Not included
  • Fixing what we find (that's Shield Fix)
  • Any access to your site — the scan is passive by design
  • Penetration testing or exploitation attempts
  • Code review of custom applications
  • Ongoing monitoring after the report (that's the plans)
delivered in 24–48 hours

Something bigger? Several sites, servers or internal systemstalk to us and we'll scope it on a call, then give you a fixed price.

Questions

Asked before every engagement.

28 answers

Including the ones that matter most in security - whether we hack your site to test it (we don't), what happens if you are breached while on a plan, and why we will never guarantee immunity.

Which one do I need

Not sure where you stand?

Run the free Growth Scan — it includes a security snapshot. If a door's open, you'll see it.