WHAT IT CHECKS

The places a security problem usually leaves a trace

AssayMark focuses on evidence smaller organisations often already have: sign-in and server records, public website exposure, and selected non-secret configuration settings.

SIGN-INS AND SERVER LOGS

See what’s happening

Supported logs can show repeated failed logins, access at unusual hours, unexpected changes and other events worth investigating. AssayMark turns those records into findings instead of asking you to read thousands of lines yourself.

Failed loginsUnusual accessUnexpected changesRecurring patterns
WEBSITE EXPOSURE

Check what’s visible from the outside

AssayMark reviews selected website security controls and exposure indicators, with authorised deeper assessment where appropriate. The aim is to show what is visible that should be tightened, not to run destructive tests.

Security headersExposure indicatorsAuthorised deeper checksPlain-English findings
SERVER AND APPLICATION SETTINGS

Check configuration without uploading the secrets inside it

For supported configuration files, your browser extracts an allow-list of non-secret settings. Passwords, database credentials, API keys, tokens and salts are never included and never leave your machine.

The non-secret settings received by AssayMark are independently re-validated on the server before a result is accepted.

THE OUTPUT

Know what to fix first

Findings are presented with what the issue is, why it matters in your context and what to do next — prioritised by impact rather than listed alphabetically.

Request a free security review