Production Server Audit
You find out what is actually running on your production server, what of it is exposed, and what breaks first. Read-only, no changes, delivered as a document you can hand to anyone.
The problem
Nobody fully knows a server that grew over years. Services were added, ports opened, certificates set up — and the person who built it has left, or never gets round to looking. None of that shows while nothing goes wrong. It shows on a bad day: a customer's security questionnaire, a handover to a new contractor, an outage that almost went badly, or a hosting bill nobody can explain.
A service can return HTTP 401 and be completely dead. A machine can run quietly for months with no swap left. From the outside, both look like business as usual.
What you get
One written report on one server. Findings ranked by severity, each with a concrete recommendation. We review:
- operating system and package currency
- running services, and which of them are reachable from outside
- TLS configuration
- authentication and privilege setup
- whether backups exist
- log retention
Two of those we state more precisely, so you know what is in the report and what is not:
- TLS means the certificate being served on the public port and its expiry. We check that from outside, without touching your files. No claim about your renewal configuration, and none about certificates on internally-bound ports.
- What is reachable from outside means which ports on your public IP actually answer, and whether the connection is encrypted. We do not read the firewall rules themselves — they are not readable without root, and we do not ask for root. What actually answers matters more than what the rule set claims anyway.
Delivery: three working days from access being confirmed. For two servers we confirm the window with the engagement. Day one is confirming access and taking stock. The anchor is confirmed access, not the order date — the access round-trip is the part we do not control on our own.
You get a document, not a slide deck. It is written so you can pass it to a managing director, a contractor or an auditor without translating it first.
What we do not do
- We change nothing. No configuration edits, no installs, no service restarts, no writes of any kind.
- No penetration test. We do not exploit anything we find, and we do not test credentials.
- We copy nothing off your server. We read logs and configuration where they sit. What leaves your system is our findings — counts, versions, settings, recommendations. No log files, no database contents, no personal data.
- No remediation. The report says what to do. If you want us to do it, you get a separate quote.
- No assurance that your system is secure. The audit is a point-in-time review of the items above, within the agreed access window. It is not a certification and not a warranty.
If one of those boundaries does not fit your request, that is a no rather than an exception.
What it costs
€750 net for one server. €1,200 net for two.
Fixed price, fixed deliverable, no hourly billing.
This offer is for businesses. All prices are net, plus VAT where it applies. Payment schedule, terms and cancellation are in the engagement terms you get together with the offer.
What we need from you
Three things, and the first matters most.
- Confirmation that you may authorise this server for inspection — that you own it or are otherwise entitled to permit the review, that no third party's consent is outstanding, and that your hosting agreement allows it. That includes the check from outside: the order names our source host, your target IP or hostname, and the list of ports. Without your written confirmation, not a single packet goes to your server.
- A read-only account that you create yourself and delete yourself. A dedicated, named account with read rights — not an existing admin login somebody else already uses. If a database is in scope, add a read-only database role (
pg_monitoris enough). So that log retention can be in the report, also add the account to theadmgroup — read access to log files, nothing more. No sudo, no root, no exceptions. The access stays in your hands: you create it, you can see what it is allowed to do, you delete it at the end of the window. We keep no copy, and we tell you when we are finished. - A time window. Start and end are in the order. After that the access is gone.
Next step
Write to us through the contact form: one server or two, what you need the report for, and by when. You get the engagement terms and the deposit invoice back. Acceptance is in writing — a reply by email and the paid deposit, that is the whole process.
Want to look for yourself first? The free server report runs on your own machine in under a minute, uploads nothing, and costs nothing. It tells you what is going on on the machine. The audit tells you which of it becomes a problem first, why, and in what order to deal with it.