The places a security problem usually leaves a trace
AssayMark focuses on evidence smaller organisations often already have: sign-in and server records, public website exposure, and selected non-secret configuration settings.
See what’s happening
Supported logs can show repeated failed logins, access at unusual hours, unexpected changes and other events worth investigating. AssayMark turns those records into findings instead of asking you to read thousands of lines yourself.
Check what’s visible from the outside
AssayMark reviews selected website security controls and exposure indicators, with authorised deeper assessment where appropriate. The aim is to show what is visible that should be tightened, not to run destructive tests.
Check configuration without uploading the secrets inside it
For supported configuration files, your browser extracts an allow-list of non-secret settings. Passwords, database credentials, API keys, tokens and salts are never included and never leave your machine.
The non-secret settings received by AssayMark are independently re-validated on the server before a result is accepted.
Know what to fix first
Findings are presented with what the issue is, why it matters in your context and what to do next — prioritised by impact rather than listed alphabetically.