A client asks, and you do not know what to answer.
A large company wants to work with you and sends over a security questionnaire. The questions read like a foreign language, and the contract depends on your answers.
For companies without an IT department
You have a system, a shop or an application that somebody built for you. We check whether it can be attacked, show you the result in plain language and tell you exactly what to fix. At the end you get a certificate you can show your clients.
A large company wants to work with you and sends over a security questionnaire. The questions read like a foreign language, and the contract depends on your answers.
Somebody wrote an application for you. It works. But nobody has ever checked whether your clients' data can be stolen from it.
Names, addresses, identity numbers, documents. If they leak, you are the one who answers for it. You simply do not know whether there is anything to worry about.
We do not click around on the surface. We look inside: at the code and at the running application. We look for the places where somebody could get in where they should not.
You get a report and a live meeting where we go through the result together. No jargon you have never heard. You leave knowing what matters and what can wait.
Once the important things are in order, we issue a certificate and a seal you can show to clients and partners. Anyone can check that it is genuine on our website.
We checked 7 areas. Most are in order. Three things need fixing, one of them first.
After an audit - core or full - you get an Anat Secure certificate and a seal for your website. This is not a sticker bought for pocket change. Behind every seal there is a real audit, and anyone can visit our site to check whether it is current and exactly which part of the system it covers.
Your clients see that somebody checked. You get peace of mind.
See a sample certificatePrices exclude VAT. You always start with the free check.
€1,900one-off
Scope: authentication, roles and personal data
The same method as the full audit, applied to a narrower slice of the system.
full coverage
from €3,900one-off
Scope: the whole application
Everything in the core audit, across the whole system, plus:
Both variants are run by a person and both end with a certificate - what differs is how much of the system we cover, not how carefully we work. The scope goes on the certificate, so anyone can see what the seal actually covers. We give you the price of a full audit after a short conversation, before we start anything. We can also fix what we find, or make sure the company that built your system does it.
Two things we are still building. We are not selling them until they are ready. We would rather say so plainly than take orders for something we cannot deliver.
A scan without a person involved: cheap and fast, as a first step before an audit. For now the free check fills that role, and we run it by hand.
Regular re-checks and a certificate that always stays current, because your system keeps changing. For now we arrange re-checks one at a time.
We work with companies that have no security department of their own, but do have software and other people's data:
If somebody built a system for you, or you bought one off the shelf and keep people's data in it, you are in the right place.
| Criterion | Scanning tool | Typical testing firm | Anat Secure |
|---|---|---|---|
| Finds problems | Only surface ones | Yes, in depth | Yes, in depth |
| Language of the report | Technical | Technical | Plain, for the business owner |
| Conversation with a person | No | Rarely | Always, live |
| Tells you what to do first | No | Sometimes | Yes, in priority order |
| Can fix it or oversee the fix | No | Usually not | Yes |
| Certificate for your clients | No | No | Yes, with verification |
| You need expertise to use it | Yes | Yes | No |
We have been building software for over twenty years. We know where the mistakes get made, because we spent years running the teams that made them. And we know how to explain it to somebody who is not a developer.
No. We work in a way that does not disturb your day-to-day operations. Heavier tests are run on a copy or at a time we agree with you.
Yes. We write the report for the business owner, not for a developer. And at the meeting we go through it together and answer every question.
We tell you straight away, before the work is even finished. Then we agree together what to do first. We can fix it ourselves or make sure the company that built your system does it.
We work on a test environment and do not need your clients' real data. Everything is covered by a confidentiality agreement.
The free check - one working day, because a person does it. A core audit - usually a few days. A full audit - one to three weeks, depending on the size of the application. We confirm the timing before we start.
We issue the certificate once the important things are fixed. If we find serious problems, we first help remove them and then check again.
No. That is exactly why we start with a free check and then suggest a core audit - narrower scope, lower price, the same thoroughness. A full audit only makes sense on a larger system, and we will tell you plainly when that is the case.
In our experience they do not - a good supplier is usually glad to get a concrete list instead of vague complaints. We write about faults, not about people, and if you prefer, we take the whole technical conversation off your hands.
The GDPR does not mandate an audit as such, but it does require you to test and evaluate the effectiveness of your security measures regularly if you process personal data (Article 32). In practice an audit is the simplest way to document that - including when a client or an insurer asks.
Enter your website address and we will show you what is visible from the outside. If everything is in order, we will tell you so plainly.
Prefer to talk? Write to verify@anatsecure.com.