Affordable penetration testing and security checks built for small and home offices, startups, and growing SMBs. We find the holes attackers would use — and explain exactly how to fix them, in plain English. No jargon, no enterprise price tag.
You don't need an in-house security department — you need someone to check your defences like a real attacker would. Every test is done by hand, and every finding comes with a clear, prioritised fix you (or your IT person) can act on.
We test your website, online store, or customer portal the way a real attacker would — looking for login flaws, ways into customer data, and weak spots that scanners miss.
Wi-Fi, firewalls, servers, and shared drives. We find the misconfigurations and exposed services that let an intruder move around once they're in.
The tools your business runs on every day. We review your email, file sharing, and account settings for the misconfigurations behind most small-business breaches.
Most attacks start with one email. We run a safe, simulated phishing campaign to see who clicks — then give your team simple, practical training.
New to all this? Start here. A quick, affordable review of your whole setup with a plain-English report on your biggest risks and what to fix first.
Need to show you take data protection seriously? We test against POPIA, ISO 27001, and PCI DSS controls and give you clear evidence — plus a free retest.
We follow recognised industry standards (PTES and NIST 800-115) so every job is safe, predictable, and won't disrupt your business — while still catching the clever attacks that automated tools always miss.
We confirm exactly what's being tested and when, with your written go-ahead. Clear boundaries, no surprises.
We map out what an attacker would see first — your website, network, and anything exposed to the internet.
We try to break in by hand, the way a real attacker would, without ever putting your live systems or data at risk.
You get a clear report ranked by risk, with step-by-step fixes — plus a free retest once you've sorted them.
Know the cost before we start. Every package is a fixed price with a plain-English report, a debrief call to walk you through it, and a free retest after you've fixed things.
Perfect for SOHO and first-timers. A fast review of your website, email, and network with your top risks ranked.
For established small businesses. Hands-on testing of your main website or app plus your office network.
For SMBs with customer data or compliance needs. Fuller coverage with POPIA-ready evidence.
It's the opposite. Attackers favour small businesses precisely because they assume no one's watching. Most attacks aren't personal — they're automated, scanning the whole internet for easy ways in. A small shop with a weak password or an unpatched website is a far easier payday than a bank. Being small makes you a target, not a non-target.
A scan is an automated tool that lists possible problems — useful, but it produces a lot of noise and misses anything clever. A penetration test is a person actually trying to break in, by hand, to prove what a real attacker could do. We use scanners as a starting point, then do the manual testing that finds the issues that actually matter.
No. We test carefully and agree the rules with you upfront, including timing if you'd prefer we work after hours. We never put your live data or customers at risk. In hundreds of hours of testing we treat "do no harm" as the first rule — keeping your business running normally is part of the job.
None at all. You get a plain-English report that explains each risk, why it matters to your business, and what to do about it — ranked so you know what to fix first. There's a more technical section for your IT person or web developer too, but the main report is written for the business owner.
It helps with POPIA, but it's not box-ticking. POPIA expects you to take "reasonable" steps to protect personal information, and a test gives you real evidence you've done that. More importantly, it actually reduces your risk of a breach — which is the thing POPIA, and your customers, really care about.
You get your report and a call to walk through it together. Once you've fixed the issues — yourself, with your IT provider, or we can point you to help — we come back and retest the important findings for free, so you can be sure they're genuinely closed.
Fill in a few details and we'll reply within one business day with a fixed quote — no obligation, everything kept confidential.
You're not buying a scary audit. You're getting a clear picture of your real risks and a simple plan to fix them — at a price built for a small business.