Outside-in security for small teams

Can someone send email pretending to be your company? Probably.

One missed sender in SPF. DMARC parked at p=none. A TLS setting that a buyer's security review catches before you do. OrangeStealth checks the public edge, writes up what matters, and walks you through it on a call.

$1,499Three business days. No access to your systems.

Replies come from a person doing the work, usually the same day.

Conceptual signal mapNo credentials required

Public data onlyNo credentials or agents

3 business daysFixed delivery window

Ranked findingsSpecific fixes, in order

20-minute walkthroughAsk the person who checked it

The approach

Small and well-run beats big and unwatched.

The companies in breach coverage had budget. Many were running the best-reviewed products on the market. The usual answer is another platform, another license, and another dashboard nobody has time to tune.

A smaller environment you understand, with detections written for the way your systems are exposed, is often the better build for a team without a security hire.

OrangeStealth uses AI tooling for the grunt work: parsing scan output, cross-referencing CVEs against exposed software, and organizing evidence. Security judgment stays human. That is how a one-week engagement produces something your engineers can open again in month three.

Free outside check

See what your domain says before a buyer does.

This quick pass checks public DNS and the headers returned by your homepage. It does not scan ports, test credentials, or touch anything behind the public edge.

Use the root domain only. Results stay in this browser response and are not added to a mailing list.

What the work looks like

Evidence first. Interpretation beside it.

Each finding shows what answered from the outside, why it matters, and the next action. The sample uses a reserved domain. Your report uses your real records and ranks them by what an attacker reaches first.

See the full assessment scope
Illustrative findingEMAIL / DMARC

dig +short TXT _dmarc.acme.example

"v=DMARC1; p=none"

Review before a sender is spoofed

The policy watches. It does not enforce.

Receiving mail systems are not being asked to quarantine or reject messages that fail authentication. First map every legitimate sender. Then move the policy in measured steps and watch the reports.

Sample format only. No customer information is shown.

Track record

Backed by over a decade of experience.

Behind the work is over a decade keeping production systems up — web applications, a global colocation footprint built for failover and replication, hosted banking and HIPAA-governed healthcare networks, and the Windows and Linux administration underneath. Including the unglamorous parts: continuity plans that had to hold when something actually broke.

It has meant working both sides of the line — securing networks and endpoints, assessing risk, managing vulnerabilities, reviewing code and the dependencies it pulls in, and meeting compliance across multiple regimes: PCI DSS, GDPR, and HIPAA. That range is the point: risk doesn't stop at the border between what a company builds and what it runs.

Services

Fixed price, and you get something you can run.

Every engagement ends in an artifact: queries that run in your tooling, a runbook, or a prioritized list your engineers can work down. Start with an external assessment — both are bookable now, no meeting first, nothing to install. Work that needs inside access is scoped on a call.

Start here · Nothing to authorize

External Exposure Report

$499three business days

The fastest way to find out where you stand. Everything in this report is drawn from what your company already shows the internet, so there is nothing to approve and nothing to install.

No system access. No meeting required before you buy.

What you get

  • SPF, DKIM, DMARC, and the services sending on your behalf
  • Web security headers and TLS, with the specific fix for each finding
  • Your public attack surface and outside-visible vendor exposure
  • A written report ranked by what an attacker can reach first
  • Every finding benchmarked against 705 comparable companies
  • A call to walk through the findings and answer questions
Secure checkout is hosted by Stripe.

Most complete · External only

External Security Posture Assessment

$1,499three business days

You handle customer data or payments. You do not have a clear picture of what an attacker, or an enterprise buyer's reviewer, can already see.

Sites built fast leak credentials. API keys, database tokens and payment secrets get compiled into the JavaScript every visitor downloads, and configuration files get deployed where anyone can fetch them. This tier looks for both.

No system access. No meeting required before you buy.

Everything in the External Exposure Report, plus

  • Credentials hard-coded into your public JavaScript, identified by type and location
  • Configuration and backup files reachable without a password (.env, .git, database dumps)

In the report either way

  • SPF, DKIM, DMARC, and the services sending on your behalf
  • Web security headers and TLS, with the specific fix for each finding
  • Your public attack surface and outside-visible vendor exposure
  • Findings ranked by what an attacker can reach first
  • Benchmarking against 705 comparable companies, and the walkthrough call
Secure checkout is hosted by Stripe.

With your authorization

Work that needs inside access.

The two assessments above need nothing from you but a domain name. These go further — your logs, your repository, your environment — so each one starts with a scoping call and written authorization before anything runs.

Inside access · Scoped first

Detection & Incident-Readiness Audit

No SOC, no full-time analyst, and no honest answer to “would we catch someone inside?” Answering that takes your logs and written authorization.

  • Review of email, endpoint, and cloud telemetry
  • Five to ten detections written for your environment
  • Findings report plus an incident-response runbook

Quoted per scope · one to two weeks

Scope it on a call

Code and API review

AI Security Risk Review

For teams shipping AI features or building quickly with AI coding tools. The external assessment finds credentials your site already publishes; this one reads the repository itself — every secret, route and permission an outside scan cannot see.

Ranked findings on secrets in source and history, auth and API gaps, and prompt-injection surface.

Quoted per scope · about one week

Ask about the review

Also available: vulnerability management, SOC 2 groundwork, scaling audits, and secure data pipelines for AI. Ask.

No pitch deck required

Twenty minutes.

Tell us what you are running and what would worry you most if it broke. If there is nothing here worth paying for, we will say so. You will have spent twenty minutes.

Book a 20-minute call