# Netsekurity.com — Full LLM content ## About Netsekurity (by **Dalang Pte Ltd**) is a **continuous external web security assessment** service. For one credit per domain, it runs an automated, read-only scan of your **public attack surface**, then a human security engineer reviews, validates, and curates the findings into a plain-language PDF report. **Positioning:** "You build fast with AI. We check your production attack surface — with human-reviewed findings." It is designed for vibe-coders and non-technical founders whose alternative is doing no security testing at all, and it integrates with CI/CD so the public surface is re-scanned on every deploy. **Important, stated plainly:** this is **not a full penetration test**. It is an automated external (blackbox, unauthenticated, read-only) assessment with human triage. It does not test authenticated application logic, authorization/IDOR, or business logic. Deeper assurance is available as a separate **whitebox** engagement. ## Pricing - **1 credit = 1 external assessment · 1 domain** - Starter: **$50** → 1 credit - Standard: **$100** → 3 credits - Professional: **$500** → 20 credits (most popular) - Enterprise: **$1000** → 50 credits - **Whitebox** (source code + credentials + authenticated manual testing by a human security engineer + agent): **$10,000 USD per app / per domain** ## Methodology (blackbox, external, unauthenticated) 1. **Recon & attack-surface mapping** — DNS resolution, passive subdomain enumeration, open-port discovery, technology & platform fingerprinting. 2. **Web fingerprint** — HTTP/S response analysis, server & WAF detection, CMS/stack identification. 3. **Security headers** — full OWASP set (HSTS, X-Content-Type-Options, X-Frame-Options, CSP, Referrer-Policy, Permissions-Policy), clickjacking check. 4. **TLS / PKI** — certificate validity, expiry, issuer, SAN coverage. 5. **Information disclosure** — exposed `.git`, `.env`, backups, `server-status`, `phpinfo`, `robots.txt`, SVN metadata, source maps, debug endpoints, secrets. 6. **Common web vulnerability probing** — SQL injection, LFI/RFI, XSS, open redirect, path traversal, server misconfiguration. 7. **Human validation & curation** — a security engineer reviews every finding: deduplicates, checks evidence, re-tests critical items where feasible, and curates the final report. Findings are **mapped to OWASP Top 10 categories** and scored with **CVSS v3.1**, each with reproduction steps and remediation guidance. ## Coverage & limitations (be precise) **Included (every scan):** - External recon & passive subdomain discovery - Technology / WAF / stack fingerprinting - Security headers, TLS/PKI validation - Exposed files & secrets (`.env`, `.git`, backups, config, debug endpoints, source maps) - SQLi, LFI/RFI, XSS, open redirect, path traversal, server misconfiguration - Human-reviewed, OWASP-mapped, CVSS-scored report with remediation roadmap **Not included in the standard product:** - Authenticated testing (anything behind a login/session) - Authorization / IDOR / privilege-escalation testing - Business-logic, workflow, payment, or race-condition testing - Deep multi-stage exploit chains - SSRF, GraphQL, WebSocket, request-smuggling, web-cache-poisoning (not claimed) - Source-code analysis (this is blackbox) **On "OWASP Top 10":** findings are *categorized* per OWASP. We do not claim to exhaustively test every OWASP category — some (e.g. broken access control) fundamentally require authentication and multiple identities, which an external unauthenticated scan cannot reach. **On "read-only":** all testing is non-destructive and safe for production systems. This means we can indicate that a parameter appears injectable but may not extract live database records as proof. ## Continuous security (CI/CD) — what it actually means Integrate with GitHub Actions, GitLab CI, Jenkins, or any CI tool via an **API token** (7/14/30/60/90-day expiry). Add a one-line step after deploy; Netsekurity **re-scans your public attack surface on every deploy**. This catches, on the day they ship: newly exposed endpoints/subdomains, changed headers, TLS mistakes, exposed files/secrets, and common injection regressions. It solves the "periodic assessment goes stale" problem **for the public surface**. **Caveat:** a fresh scan does not mean the authenticated application logic is re-tested. If your highest risk is in authenticated authorization/business logic, that coverage requires the whitebox tier or a manual pentest. Pairing the two is the recommended model for production transactional apps. ## Use cases ### 1. Vibe Coders / non-technical founders AI writes fast code but doesn't teach security. A production launch can leak API keys, have broken access control, or be vulnerable to SQL injection. Netsekurity finds common issues on the public surface before real users do, with a report in plain language. Against "doing nothing," this is a significant improvement. ### 2. CI/CD continuous coverage Instead of an annual report that goes stale, re-scan the public surface on every deploy for faster mitigation of external/common issues. ## Human review — what we mean Every automated finding is reviewed by a security engineer before delivery: false positives are removed, duplicates merged, evidence checked, severity adjusted, and (where feasible) critical findings re-tested. The report is then curated with remediation steps. For deeper manual validation, authenticated exploration, and exploit-path analysis, choose the **whitebox** tier. ## FAQ 1. **How does pricing work?** 1 credit = 1 external assessment on 1 domain. 2. **Is this a full penetration test?** No — it's an automated external web security assessment with human review. Authenticated/business-logic coverage is the separate whitebox tier. 3. **What is covered in one assessment?** See Coverage & limitations. Public, unauthenticated, read-only OWASP-mapped scanning with human-reviewed findings. 4. **How do I verify my domain?** We auto-generate a unique TXT record; add it in DNS and hit verify. 5. **Is it really automated?** The scan is automated end-to-end; a human security engineer reviews before the report is delivered. 6. **What if we have many subdomains?** Each domain costs 1 credit. Wildcard/API surfaces can be scoped — contact us. 7. **Blackbox vs Whitebox?** Standard is blackbox/external. Whitebox is $10,000 USD per app/domain. 8. **I'm not technical / built this with AI — is this for me?** Yes. Plain-language report, no security background required. ## Links - Home: https://netsekurity.com/ - Docs (CI/CD + API): https://netsekurity.com/docs - Product scope & methodology: https://netsekurity.com/PRODUCT_SCOPE.md ## Contact sales@dalang.io — replies within 1 business day.