External Vulnerability Review

Know what your public systems need first.

Start with a bounded review of the internet-facing assets your organization is authorized to test. Praeven scans the agreed public scope, reviews the meaningful results, and gives your team a concise plan for what to address.

Two practical ways to start

Establish a baseline, then keep the list current.

Both options cover up to five approved internet-facing assets. An internet-facing asset is a public IP address, fully qualified domain name, gateway, application, email service, or cloud system specifically listed in the approved scope.

External Vulnerability Baseline

$750one-time review

  • Up to five approved internet-facing assets
  • Defined external scanning and human triage of material findings
  • Concise findings report with practical remediation priorities
  • Results walkthrough with the designated client contact

Use the baseline when you need a current public-asset review, a practical starting point, or a defined result before deciding on recurring coverage.

Request the baseline

External Vulnerability Review

$395per month after the baseline

  • Monthly review of the confirmed public-asset list
  • Delta-focused findings and human triage
  • Short monthly report with status and next actions
  • Scope and ownership reconfirmed as the environment changes

Add up to five more approved assets for $200 per month. More than 25 approved assets receives a custom scope.

Discuss recurring review

A measured technical service

Useful scanning without pretending it is a pentest.

The service is designed for public exposure that can be reviewed safely within an agreed scope. Results are interpreted by Praeven before they reach your team.

You receive a practical record of the material findings, affected approved assets, recommended next actions, ownership questions, and limits that affected the review.

Not included in this service

  • Internal network or endpoint scanning
  • Credential testing, authenticated assessment, or agent deployment
  • Exploitation, persistence, denial-of-service testing, or data access
  • 24/7 monitoring, containment, incident response, or remediation work
  • Testing of an asset without written authority from its owner and any required provider

How the engagement works

Authority and operating limits come first.

Public does not mean unrestricted. Before live work begins, Praeven records the client entity, approved assets, ownership, provider requirements, scan window, source details, rate limits, exclusions, and emergency stop contacts.

Confirm scope

Complete the engagement paperwork and authorize the exact public assets. A payment, web form, or company email address does not by itself authorize testing.

Review and triage

Praeven performs only the approved external methods, keeps an evidence record, and separates material observations from output that needs further validation.

Decide and improve

Receive a concise report and walkthrough. Recurring clients receive a monthly change-focused review of the same confirmed scope.

Choose the right depth

Three different external views.

These services answer different questions. We will recommend the smallest service that fits the decision you need to make.

External security service comparison
ServiceBest when you needWhat it coversStarting price
External Vulnerability ReviewA bounded technical review of known public assetsApproved external assets, scanning, human triage, and a concise report$750baseline ยท $395/month thereafter
External Exposure ReviewMonthly context and a recurring results discussionUp to five approved assets, reviewed public exposure, concise findings report, and monthly results call$895per month
Public Exposure AssessmentBrand, impersonation, fraud, or public-information researchSource-linked OSINT on public domains, brands, visible information, and reconnaissance riskFrom $2,000per assessment

Start with the real scope

Tell us what is public and who operates it.

We will confirm whether a one-time baseline or recurring review is the right fit, then prepare the scope and authorization records before live work starts.

Do not send credentials, network diagrams, or sensitive technical detail through the contact form.

Before we schedule

  • Named client sponsor and technical contact
  • Approved public-asset list and ownership information
  • Provider or MSP involvement where applicable
  • Written authorization, operating window, and stop contact
Discuss your scope

Prepare. Anticipate. Protect.