Family Sentinel
White-glove penetration testing & hardening · for organizations

A report nobody acts on
is not security. We stay for the fix.

Most tests end with a PDF and an invoice. Ours ends when the findings are closed. We test your website, your web application and your external surface with your written authorisation, demonstrate every real finding, then sit with you — or your developer — and harden it. Then we test it again, free, to prove it is actually fixed.

Authorised testing only · Fixed scope, fixed price · Re-test included · Call or text (940) 281-6672

Hardening includedThe fix is the deliverable, not an upsell. We work through the findings with you until they are closed.
Free re-testAfter your fixes we test again at no charge and issue a closure letter you can show an insurer or a board.
Demonstrated, not listedEvery finding comes with proof it is real. A scanner's "possible" is not a finding.

How this is different from a scan

Anyone can run a scanner and hand you two hundred results. The work that matters is proving which ones a real attacker could actually use, ranking them by what they would cost you, and then closing them. A finding we cannot demonstrate does not go in the report as a finding — it goes in as an observation, clearly marked.

And a control nobody has tested is not a control. We check whether the thing works, not whether it is documented — the backup that has never been restored, the alert channel nobody has ever received a message on, the login page that rate-limits in theory.

Engagements

Website Security Test
from $3,500
  • Your public site and its forms, logins and integrations
  • Injection, unescaped output, broken access control
  • Exposed admin panels, backups, .env and .git directories
  • TLS, security headers, cookie flags, CORS
  • Every finding demonstrated — with the fix
  • Hardening session + free re-test included
Request a scope
Web Application Test
from $6,500
  • For applications with accounts, roles, payments or member data
  • Authenticated testing across every role you have
  • Access control: can one user reach another's records?
  • Business-logic abuse — the class scanners never find
  • Session handling, password reset, MFA bypass
  • API and mobile endpoints behind the app
  • Hardening sessions + free re-test included
Request a scope & quote
External Surface Test
from $3,500
  • Everything of yours the internet can already reach
  • Forgotten subdomains, staging sites, old VPN and RDP endpoints
  • Subdomain takeover, exposed services, default credentials
  • Email spoofing: SPF, DKIM, DMARC to enforcement
  • Staff credentials already in breach dumps
  • Hardening + free re-test included
Request a scope

Not sure which fits? That is what the scoping call is for. Prices are starting points — the scope drives the number, and you get it in writing before anything begins.

Rules of engagement

We test only with your written authorisation, only the assets you name, and only in the window you agree. If your site is hosted by a third party we get their sign-off too, because testing someone else's infrastructure without it is a crime rather than a service.

We do not test destructively. No denial-of-service, no data destruction, no social engineering of your staff unless you specifically ask for it and scope it separately. If we find something critical mid-test we stop and phone you the same hour rather than saving it for the report.

Findings are yours. We hold no copy beyond the engagement plus the re-test window, and we certify deletion in writing when it closes.

Request a scope and a quote.

A short call to understand what you have and what you are worried about. You get a written scope and a fixed price before anything is touched — and an honest answer if a test is not what you need yet.

Request a scope & quote

Or call the Security Architect directly — (940) 281-6672

security@familysentinel.org