Services

One clear entry. Deeper when needed.

Start with an Outside-in Web Assessment for your production app. Use the Free Brief only to orient and choose depth. User-level and Inside-assisted are scoped upgrades.

Recommended baseline scope

You receive

Not included (upgrade or out of scope)

What happens

  1. Scoping call and written authorization (rules of engagement)
  2. Isolated assessment of the agreed public surface
  3. Evidence review and clear reporting
  4. Remediation discussion, then one bounded retest

Free Brief vs Outside-in

Free Exposure Brief

  • A short orientation memo: what stands out, how sure we are, and what’s out of scope
  • Recommends the right assessment depth
  • Does not find or confirm vulnerabilities — and does not replace a paid assessment

Outside-in assessment

  • Validated findings with evidence, severity, and remediation
  • Executive summary plus technical report
  • Remediation discussion and one bounded retest

Scoped upgrades

Add accounts, roles, or internal collaboration when the application requires it.

  • User-level

    See what a normal user or role can overreach after login.

    • You provide: test accounts for the roles that matter
    • We assess: portals, privilege edges, and account abuse paths
    • You get: prioritized findings and practical remediation

    Requires client-provided accounts and clear role coverage. Not included: source walkthrough or design review with your leads (that’s Inside-assisted).

  • Inside-assisted

    Trace deep design and implementation flaws with your maps and leads in the room.

    • You provide: docs, code access, and technical leads
    • We assess: root causes behind high-stakes surfaces
    • You get: root-cause findings and a remediation roadmap

    Requires collaboration access and scheduled technical time. Not a free public-surface Brief — this is a scoped, assisted assessment.

Every paid engagement includes fix guidance. Retest when fixes land — one bounded retest on Outside-in; more via ongoing coverage.

Common questions

FAQ

How is Truehat different from an automated scan?

Scans list findings. Truehat interprets what outsiders can actually reach and what matters to the business — short memos and reports with fix guidance, not raw tool output.

What is included in the Free Exposure Brief?

A non-invasive public-surface orientation and a short decision-maker memo after we verify the request. Enough to choose depth before a paid assessment — not validated findings, and not a substitute for Outside-in. Submitting the form does not authorize active testing.

How does Free Brief differ from paid Outside-in?

The Brief orients and recommends depth. Outside-in delivers validated findings, evidence, severity, remediation guidance, a remediation discussion, and one bounded retest under written rules of engagement.

Do you need written authorization before testing?

Yes for active assessment. The Free Brief is non-invasive orientation only — form submit starts verification, not testing. Paid work starts after qualification and separate written authorization with Rules of Engagement. No destructive testing, and no work on domains you cannot authorize.

What happens after the brief?

Act on the memo, book a scope call to discuss Outside-in (or an upgrade), or stop — no obligation to continue.