Services

One clear entry. Deeper when needed.

Start with an Outside-in Web Assessment for your production app. Use the Free Brief only to orient and choose depth. User-level and Inside-assisted are scoped upgrades.

Recommended baseline scope

You receive

Not included (upgrade or out of scope)

What happens

  1. Scoping call and written authorization (rules of engagement)
  2. Isolated assessment of the agreed public surface
  3. Evidence review and clear reporting
  4. Remediation discussion, then one bounded retest

Coverage

What we actually test

Every paid assessment runs through the same disciplined coverage — not a generic scanner checklist. The categories below apply to Outside-in and scoped upgrades; the Free Brief does not test.

  • Login & accounts

    Authentication bypass, account takeover, session and token weaknesses, MFA gaps.

  • Access control

    Whether one user or role can reach another user's data, actions, or admin functions.

  • Data handling & injection

    SQL/NoSQL injection, unsafe input handling, and sensitive data exposure.

  • Client-side & APIs

    Cross-site scripting, CSRF, and authorization gaps across REST/GraphQL APIs.

  • Business logic

    Pricing, checkout, and workflow abuse that only shows up with real product context.

  • Infrastructure & configuration

    Exposed panels, outdated components, and misconfigurations attackers scan for first.

Full methodology and phase-by-phase process: See our methodology

Free Brief vs Outside-in

Free Exposure Brief

  • A short orientation memo: what stands out, how sure we are, and what’s out of scope
  • Recommends the right assessment depth
  • Does not find or confirm vulnerabilities — and does not replace a paid assessment

Outside-in assessment

  • Validated findings with evidence, severity, and remediation
  • Executive summary plus technical report
  • Remediation discussion and one bounded retest

Scoped upgrades

Add accounts, roles, or internal collaboration when the application requires it.

  • User-level

    See what a normal user or role can overreach after login.

    • You provide: test accounts for the roles that matter
    • We assess: portals, privilege edges, and account abuse paths
    • You get: prioritized findings and practical remediation

    Requires client-provided accounts and clear role coverage. Not included: source walkthrough or design review with your leads (that’s Inside-assisted).

  • Inside-assisted

    Trace deep design and implementation flaws with your maps and leads in the room.

    • You provide: docs, code access, and technical leads
    • We assess: root causes behind high-stakes surfaces
    • You get: root-cause findings and a remediation roadmap

    Requires collaboration access and scheduled technical time. Not a free public-surface Brief — this is a scoped, assisted assessment.

Every paid engagement includes fix guidance. Retest when fixes land — one bounded retest on Outside-in; more via ongoing coverage.

Common questions

FAQ

How is Truehat different from an automated scan?

Scans list findings. Truehat interprets what outsiders can actually reach and what matters to the business — short memos and reports with fix guidance, not raw tool output.

What is included in the Free Exposure Brief?

A non-invasive public-surface orientation and a short decision-maker memo after we verify the request. Enough to choose depth before a paid assessment — not validated findings, and not a substitute for Outside-in. Submitting the form does not authorize active testing.

How does Free Brief differ from paid Outside-in?

The Brief orients and recommends depth. Outside-in delivers validated findings, evidence, severity, remediation guidance, a remediation discussion, and one bounded retest under written rules of engagement.

Do you need written authorization before testing?

Yes for active assessment. The Free Brief is non-invasive orientation only — form submit starts verification, not testing. Paid work starts after qualification and separate written authorization with Rules of Engagement. No destructive testing, and no work on domains you cannot authorize.

What happens after the brief?

Act on the memo, book a scope call to discuss Outside-in (or an upgrade), or stop — no obligation to continue.