Language: PL EN

Free check

For companies without an IT department

Is your software secure? We will check it and explain it in plain language.

You have a system, a shop or an application that somebody built for you. We check whether it can be attacked, show you the result in plain language and tell you exactly what to fix. At the end you get a certificate you can show your clients.

Free website check

See your first result before you talk to anyone.

We run it by hand and send the result back within one working day. No commitment, no sales call.

Prefer to talk to a person?

  • Part of the Anat Systems family
  • We test against OWASP and recognised industry standards
  • Over 20 years of building and protecting systems

Sound familiar?

A client asks, and you do not know what to answer.

A large company wants to work with you and sends over a security questionnaire. The questions read like a foreign language, and the contract depends on your answers.

You paid for a system and have to take its word for it.

Somebody wrote an application for you. It works. But nobody has ever checked whether your clients' data can be stolen from it.

You know you are holding other people's data.

Names, addresses, identity numbers, documents. If they leak, you are the one who answers for it. You simply do not know whether there is anything to worry about.

Three steps. We take care of the rest.

  1. Step 1. We check properly

    We do not click around on the surface. We look inside: at the code and at the running application. We look for the places where somebody could get in where they should not.

  2. Step 2. We sit down and explain

    You get a report and a live meeting where we go through the result together. No jargon you have never heard. You leave knowing what matters and what can wait.

  3. Step 3. You get the proof

    Once the important things are in order, we issue a certificate and a seal you can show to clients and partners. Anyone can check that it is genuine on our website.

What you get

  • A report you will understand. Every problem described in plain language: what it is, what it means for your business and what to do about it.
  • A conversation with a real person. An hour in which we answer every question, including the ones you think are silly. There are no silly questions.
  • A fix plan in priority order. You know what to do first and what can safely wait. No panic and no list of a hundred items.
  • A certificate and a seal. Proof for your clients that you take their data seriously.
  • A conversation with your own developer. If you want, we explain everything directly to whoever built your system, in their language.

Start with the free check

Audit report · summarypage 1 of 24

We checked 7 areas. Most are in order. Three things need fixing, one of them first.

  • Critical · 0
  • High · 1 fix first
  • Medium · 2
  • Low · 4
sample extract from a report

Security people can see

After an audit - core or full - you get an Anat Secure certificate and a seal for your website. This is not a sticker bought for pocket change. Behind every seal there is a real audit, and anyone can visit our site to check whether it is current and exactly which part of the system it covers.

Your clients see that somebody checked. You get peace of mind.

See a sample certificate
Anat Secure seal - security certificate Horizontal Anat Secure seal for a client website
the seal in its website version

Simple prices. No hidden costs.

Prices exclude VAT. You always start with the free check.

Core audit

€1,900one-off

Scope: authentication, roles and personal data

The same method as the full audit, applied to a narrower slice of the system.

  • A person reads the code and tests the running application
  • Report in plain language, no jargon you have never heard
  • A live meeting walking through the result
  • A fix plan in priority order
  • Certificate and seal with the scope recorded on them
Let's talk

full coverage

Full audit

from €3,900one-off

Scope: the whole application

Everything in the core audit, across the whole system, plus:

  • Every user path, integrations and the server
  • A re-check once the fixes are done
  • Certificate and seal covering the full scope
  • A conversation with your own developer, if you want one
  • Priority when something happens
Let's talk

Both variants are run by a person and both end with a certificate - what differs is how much of the system we cover, not how carefully we work. The scope goes on the certificate, so anyone can see what the seal actually covers. We give you the price of a full audit after a short conversation, before we start anything. We can also fix what we find, or make sure the company that built your system does it.

Coming soon

Two things we are still building. We are not selling them until they are ready. We would rather say so plainly than take orders for something we cannot deliver.

  • Automated scan soon

    A scan without a person involved: cheap and fast, as a first step before an audit. For now the free check fills that role, and we run it by hand.

  • Ongoing care soon

    Regular re-checks and a certificate that always stays current, because your system keeps changing. For now we arrange re-checks one at a time.

Who it is for

We work with companies that have no security department of their own, but do have software and other people's data:

  • clinics and medical practices
  • law firms
  • accounting offices
  • manufacturing and trading companies
  • schools and training providers
  • online shops
  • service companies with their own system

If somebody built a system for you, or you bought one off the shelf and keep people's data in it, you are in the right place.

Three ways to have software checked

Comparison: a scanning tool, a typical testing firm and Anat Secure.
Criterion Scanning tool Typical testing firm Anat Secure
Finds problemsOnly surface onesYes, in depthYes, in depth
Language of the reportTechnicalTechnicalPlain, for the business owner
Conversation with a personNoRarelyAlways, live
Tells you what to do firstNoSometimesYes, in priority order
Can fix it or oversee the fixNoUsually notYes
Certificate for your clientsNoNoYes, with verification
You need expertise to use itYesYesNo

We have been building software for over twenty years. We know where the mistakes get made, because we spent years running the teams that made them. And we know how to explain it to somebody who is not a developer.

Questions

  • Will the checking take my website or system down?

    No. We work in a way that does not disturb your day-to-day operations. Heavier tests are run on a copy or at a time we agree with you.

  • I am not technical. Will I understand any of the report?

    Yes. We write the report for the business owner, not for a developer. And at the meeting we go through it together and answer every question.

  • What if you find something dangerous?

    We tell you straight away, before the work is even finished. Then we agree together what to do first. We can fix it ourselves or make sure the company that built your system does it.

  • Is my data safe with you?

    We work on a test environment and do not need your clients' real data. Everything is covered by a confidentiality agreement.

  • How long does it take?

    The free check - one working day, because a person does it. A core audit - usually a few days. A full audit - one to three weeks, depending on the size of the application. We confirm the timing before we start.

  • Will I get a certificate even if you find something?

    We issue the certificate once the important things are fixed. If we find serious problems, we first help remove them and then check again.

  • I run a small company. Is this too big for me?

    No. That is exactly why we start with a free check and then suggest a core audit - narrower scope, lower price, the same thoroughness. A full audit only makes sense on a larger system, and we will tell you plainly when that is the case.

  • I already have a company that built my system. Will they take offence?

    In our experience they do not - a good supplier is usually glad to get a concrete list instead of vague complaints. We write about faults, not about people, and if you prefer, we take the whole technical conversation off your hands.

  • Is a security audit required by law?

    The GDPR does not mandate an audit as such, but it does require you to test and evaluate the effectiveness of your security measures regularly if you process personal data (Article 32). In practice an audit is the simplest way to document that - including when a client or an insurer asks.

Start with a check. It costs nothing.

Enter your website address and we will show you what is visible from the outside. If everything is in order, we will tell you so plainly.

Prefer to talk? Write to verify@anatsecure.com.