Find what the internet can see
Included unit: up to 10 declared domains or public IPs.
You receive an approved asset view, exposed-service findings, priority risks, corrective actions, and one technical readout.
Security assessments
We assess the systems and data your business depends on, explain the highest-priority gaps, and give your team a practical improvement plan. Add cloud, application, device, or recurring review when it changes the outcome.
Small-practice entry options
A dentist, clinic, professional office, or other small business can begin with one domain without an enterprise access project. Agent-assisted checks and professional verification keep the boundary defined. Domain Monitor and FastTrack are separate products.
The free preview shows three observations from public DNS records and never starts billing. Domain Monitor adds one agent-scheduled public-record review each month for $149. FastTrack Domain adds interpretation, independent validation, prioritized fixes, a report, and one 30-day recheck for $750 once.
The flagship assessment
Choose this when leadership needs a defensible answer to where the organization stands and the technical team needs an ordered plan. A defined environment of up to 25 declared systems or assets starts at $12,500.
We review external exposure, identity and access, data protection, patch and configuration health, and detection and response readiness. The minimum includes the five-area score, leadership and technical reports, one readout, 90-day portal access, and verification of up to five agreed fixes.
Focused assessments
Buy a focused review when you already know which system, release, account, or suspected weakness needs attention.
Included unit: up to 10 declared domains or public IPs.
You receive an approved asset view, exposed-service findings, priority risks, corrective actions, and one technical readout.
Included unit: one repository up to 100,000 non-generated lines or one deployed application/API.
Runtime and authenticated depth are stated in the permitted methods before work begins.
Included unit: one Android or iOS release on one platform.
Runtime, backend, and second-platform work require separate scope.
Included unit: one account or tenant and up to 250 declared resources.
Review uses collector-supported or supplied evidence and makes no configuration changes.
Included unit: one artifact up to 500 MiB.
Static analysis, evidence register, and readout are included. Dynamic execution is separate.
Included unit: one device model and one firmware version.
Hardware, destructive, radio, protocol, and additional-release work is quoted separately.
Included unit: up to five previously reported findings in the unchanged target and method.
Additional findings are $350 each. New discovery requires new scope.
Choose the engagement
Each proposal states what is included, who needs to participate, what you will receive, the schedule, and the fixed fee before work begins.
Best when the organization has never had an independent assessment, the environment has changed, or leadership needs priorities for planning, insurance, or customer conversations.
Five-area score + action planBest when a specific application, cloud account, device, public surface, reported issue, or completed fix needs specialist review.
Defined target + technical answerBest when systems change regularly and leadership wants scheduled exposure review, remediation tracking, retesting, and trend reporting.
Monthly or quarterly reviewThe number and type of systems, assessment depth, access required, operating constraints, reporting needs, and whether retesting is included.
The included systems, permitted methods, customer responsibilities, schedule, deliverables, exclusions, retest terms, and total fixed fee.
Additional testing, systems, or charges are not added without a written scope change agreed by both sides.
The pricing page publishes a unit and commercial floor. The proposal fixes the actual fee, included usage, retention, overage, and support before work begins.
Common questions
Authorized customers receive leadership and technical reports plus a secure AlomSec workspace for the evidence-bound score, coverage, findings, remediation status, and current publication. Customer sign-in.
No. The first step is a conversation. Any security testing requires a separate written scope and authorization from the organization that owns or controls the systems.
Yes. Baseline work includes a concise leadership view and a technical findings register. Focused reviews state their exact deliverables in the proposal.
Yes. Remediation planning, implementation support where appropriate, and post-fix verification can be included or added as a separate engagement.
No. It is a dated summary of the agreed scope across five security areas. It supports decisions but does not replace a required legal, regulatory, or framework-specific audit.
Yes. Argus Ready is the recommended baseline, but a known application, cloud, device, exposure, validation, or retest need can be scoped directly.
Domain Monitor is a $149 monthly comparison of public DNS and configuration records for one domain. The review makes no customer-origin request and uses no credentials. Argus Watch starts at $4,500 per quarter for broader scheduled exposure, remediation, and verification work. Neither is a 24/7 SOC or emergency incident-response service.
Talk through your priorities
Tell us what the business depends on, what changed, and what outcome you need. We will recommend a practical scope.
Request a security assessment