TaxPinTaxPin

EXTERNAL SECURITY AUDIT

Our external attack surface was audited by a third party

Internal review alone can leave blind spots, so we had WebEASM’s AEGISonar independently assess our externally exposed attack surface and web vulnerabilities.

5

Overall audit grade

Grade 5 · Safe

Top safety tier — 0 Critical, High, or Medium findings

AEGISonar Secure Mark

An application-layer External Attack Surface Management (EASM) solution. It discovers externally exposed web assets, assesses vulnerabilities, and connects remediation to reporting.

Web asset discoveryVulnerability assessmentShadow-IT detectionReporting & remediation
Learn about AEGISonar ↗

Results summary

Externally observable risks, tallied by severity.

0CriticalCritical
0HighHigh
0MediumMedium
2InfoInformational

The 2 items are informational (recommended-configuration) notes with no direct security impact — real vulnerabilities (Critical/High/Medium) total zero.

Detailed findings

🔐Secure · Trusted

SSL/TLS transport

The certificate is fully active and trusted. Issuer Let’s Encrypt, signature SHA-256 with RSA.

🔗0 threats

External links

No high- or medium-risk threats were found in outbound links. (SECURE)

🌐No exposure

Attack surface

No unintentionally open domains, endpoints, or exposed configuration were detected.

🧩Obfuscation grade B

Source-code protection

Client bundle protection rated “moderate.” Build obfuscation and secret hiding are being hardened.

Assessment scope

What AEGISonar examined from the outside.

External attack-surface discovery

Identifies exposed domains, subdomains, endpoints, and assets to ensure nothing is unintentionally open.

Web vulnerability assessment

OWASP-class web issues: injection, authentication & session management, access control, and misconfiguration.

Exposed config & sensitive data

Open ports, directories, keys, and configuration exposure observable from the outside.

Transport security

TLS/certificate configuration and security response headers (CSP, HSTS, etc.).

External threat intelligence

Leaked credentials, brand impersonation, and other externally-originating threat signals.

An honest boundary

Security is a continuous process with no “done,” so we re-run external audits as the service evolves.

We also run an internal adversarial review →