EXTERNAL SECURITY AUDIT
Our external attack surface was audited by a third party
Internal review alone can leave blind spots, so we had WebEASM’s AEGISonar independently assess our externally exposed attack surface and web vulnerabilities.
Overall audit grade
Grade 5 · Safe
Top safety tier — 0 Critical, High, or Medium findings
An application-layer External Attack Surface Management (EASM) solution. It discovers externally exposed web assets, assesses vulnerabilities, and connects remediation to reporting.
Results summary
Externally observable risks, tallied by severity.
The 2 items are informational (recommended-configuration) notes with no direct security impact — real vulnerabilities (Critical/High/Medium) total zero.
Detailed findings
SSL/TLS transport
The certificate is fully active and trusted. Issuer Let’s Encrypt, signature SHA-256 with RSA.
External links
No high- or medium-risk threats were found in outbound links. (SECURE)
Attack surface
No unintentionally open domains, endpoints, or exposed configuration were detected.
Source-code protection
Client bundle protection rated “moderate.” Build obfuscation and secret hiding are being hardened.
Assessment scope
What AEGISonar examined from the outside.
✓External attack-surface discovery
Identifies exposed domains, subdomains, endpoints, and assets to ensure nothing is unintentionally open.
✓Web vulnerability assessment
OWASP-class web issues: injection, authentication & session management, access control, and misconfiguration.
✓Exposed config & sensitive data
Open ports, directories, keys, and configuration exposure observable from the outside.
✓Transport security
TLS/certificate configuration and security response headers (CSP, HSTS, etc.).
✓External threat intelligence
Leaked credentials, brand impersonation, and other externally-originating threat signals.
An honest boundary
Security is a continuous process with no “done,” so we re-run external audits as the service evolves.