External Vulnerability Review
Know what your public systems need first.
Start with a bounded review of the internet-facing assets your organization is authorized to test. Praeven scans the agreed public scope, reviews the meaningful results, and gives your team a concise plan for what to address.
Two practical ways to start
Establish a baseline, then keep the list current.
Both options cover up to five approved internet-facing assets. An internet-facing asset is a public IP address, fully qualified domain name, gateway, application, email service, or cloud system specifically listed in the approved scope.
External Vulnerability Baseline
$750one-time review
- Up to five approved internet-facing assets
- Defined external scanning and human triage of material findings
- Concise findings report with practical remediation priorities
- Results walkthrough with the designated client contact
Use the baseline when you need a current public-asset review, a practical starting point, or a defined result before deciding on recurring coverage.
Request the baseline
External Vulnerability Review
$395per month after the baseline
- Monthly review of the confirmed public-asset list
- Delta-focused findings and human triage
- Short monthly report with status and next actions
- Scope and ownership reconfirmed as the environment changes
Add up to five more approved assets for $200 per month. More than 25 approved assets receives a custom scope.
Discuss recurring review
A measured technical service
Useful scanning without pretending it is a pentest.
The service is designed for public exposure that can be reviewed safely within an agreed scope. Results are interpreted by Praeven before they reach your team.
You receive a practical record of the material findings, affected approved assets, recommended next actions, ownership questions, and limits that affected the review.
Not included in this service
- Internal network or endpoint scanning
- Credential testing, authenticated assessment, or agent deployment
- Exploitation, persistence, denial-of-service testing, or data access
- 24/7 monitoring, containment, incident response, or remediation work
- Testing of an asset without written authority from its owner and any required provider
How the engagement works
Authority and operating limits come first.
Public does not mean unrestricted. Before live work begins, Praeven records the client entity, approved assets, ownership, provider requirements, scan window, source details, rate limits, exclusions, and emergency stop contacts.
Confirm scope
Complete the engagement paperwork and authorize the exact public assets. A payment, web form, or company email address does not by itself authorize testing.
Review and triage
Praeven performs only the approved external methods, keeps an evidence record, and separates material observations from output that needs further validation.
Decide and improve
Receive a concise report and walkthrough. Recurring clients receive a monthly change-focused review of the same confirmed scope.
Choose the right depth
Three different external views.
These services answer different questions. We will recommend the smallest service that fits the decision you need to make.
External security service comparison| Service | Best when you need | What it covers | Starting price |
| External Vulnerability Review | A bounded technical review of known public assets | Approved external assets, scanning, human triage, and a concise report | $750baseline ยท $395/month thereafter |
| External Exposure Review | Monthly context and a recurring results discussion | Up to five approved assets, reviewed public exposure, concise findings report, and monthly results call | $895per month |
| Public Exposure Assessment | Brand, impersonation, fraud, or public-information research | Source-linked OSINT on public domains, brands, visible information, and reconnaissance risk | From $2,000per assessment |
Start with the real scope
Tell us what is public and who operates it.
We will confirm whether a one-time baseline or recurring review is the right fit, then prepare the scope and authorization records before live work starts.
Do not send credentials, network diagrams, or sensitive technical detail through the contact form.
Before we schedule
- Named client sponsor and technical contact
- Approved public-asset list and ownership information
- Provider or MSP involvement where applicable
- Written authorization, operating window, and stop contact
Discuss your scope
Prepare. Anticipate. Protect.