Free Exposure Brief

Request a Free Exposure Brief

Non-invasive public-surface orientation. Short memo. No obligation.

The Free Exposure Brief uses non-invasive public information and observation. Submitting this form does not authorize active security testing. Active assessments require separate written authorization and agreed Rules of Engagement.

View a sample Exposure Brief (illustrative and sanitized)

The main site or app for a passive public-surface Brief.
Add more domains

The Free Exposure Brief uses passive, non-invasive public information. Submitting this form does not authorize active security testing. Active assessments require a separate agreed scope, Rules of Engagement, and written authorization.

We’ll verify the request, then prepare a short orientation memo if accepted. Privacy Policy

Request received.

We will verify the request before preparing the Brief. Accepted requests usually receive the memo within 1–2 business days from engagements@truehat.net. No active security testing is authorized by this submission.

  1. Context
  2. Discuss
  3. Done

Request received.

We will verify the request before preparing the Brief. Accepted requests usually receive the memo within 1–2 business days from engagements@truehat.net. No active security testing is authorized by this submission.

Add context — optional

Optional — role, why you’re reviewing security, and phone help us reach the right person. Skipping does not cancel your request.

Your role

Authorized web application security assessments

See what outsiders can reach on your web apps.

Start with a free non-invasive Exposure Brief — then a paid assessment under written authorization when you need validated findings.

  • Passive Brief · paid work needs written ROE
  • Privacy-first by design

Book Scope Call

Paid assessment depths

Outside-in is the primary package. User-level and Inside-assisted are scoped upgrades.

Free Brief vs Outside-in

The Brief orients. Outside-in validates.

Free Exposure Brief

  • A short orientation memo: what stands out, how sure we are, and what’s out of scope
  • Recommends the right assessment depth
  • Does not find or confirm vulnerabilities — and does not replace a paid assessment

Accepted Brief requests are normally delivered within 1–2 business days after verification. Non-invasive orientation only.

Request Free Brief

Outside-in assessment

  • Validated findings with evidence, severity, and remediation guidance
  • Executive summary, technical report, and remediation discussion
  • One bounded retest when agreed fixes land

Only after qualification and written authorization (ROE).

See Outside-in package

View a sample Exposure Brief (illustrative and sanitized)

How it works

A Brief request starts verification — not testing. Active assessment starts only after scope and written authorization.

  1. Request a Free Exposure Brief
  2. We verify the request
  3. Accepted requests receive a non-invasive Brief
  4. Scope call, proposal, and written authorization
  5. Paid assessment, report, and bounded retest

Read the full process

FAQ

Does the Free Brief authorize active testing?

No. The Free Exposure Brief uses non-invasive public observation only. Submitting the form confirms you own, operate, or are authorized to represent the submitted domains for that Brief — it does not authorize active security testing. Active assessment starts only after qualification and separate written authorization with Rules of Engagement. We do not run destructive tests.

How does Free Brief differ from paid Outside-in?

The Brief orients and recommends depth — it does not validate findings. Outside-in delivers validated findings, evidence, severity, remediation guidance, a remediation discussion, and one bounded retest under written rules of engagement.

How long does an assessment take?

Accepted Free Exposure Brief requests are normally delivered within 1–2 business days after verification. A paid Outside-in assessment is typically 3–5 working days of assessment work after scoping, readiness, and written authorization — timing is confirmed on the scoping call.

What do you need from us?

For the Free Brief: primary domain, work email, and confirmation that you own, operate, or are authorized to represent the submitted domains. For paid Outside-in: written rules of engagement and agreed domains. Upgrades may add test accounts or internal collaboration when scoped.

Is our data kept private?

Yes. Client data and evidence stay inside the engagement. We minimize what we collect, protect artifacts during the work, and tear down engagement environments when it ends. We do not publish client findings.

What happens after the Brief?

Act on the memo, book a scope call to discuss Outside-in (or an upgrade), or stop — no obligation to continue.

Ready to understand public exposure?

Start with a free non-invasive Brief — or book a scope call about paid assessment.