Security audit

A security audit means examining your site the way a malicious person would, then handing you the list of what they could exploit. FastSolve looks for the weaknesses before an attacker finds them, and gives you what you need to close them.

This service requires written authorisation from you and proof that the site is yours. That is what separates a legitimate test from an intrusion, and what protects you if a dispute arises.

This service is billed on an accepted quote. An audit delivers findings, not a tool: the usual rule, test before paying, cannot apply here. The quote states in advance what it covers and how far the analysis goes.

What an attacker looks at first

An intrusion rarely starts with a dramatic move. It starts with the door someone forgot to close.

  • Files left accessible by accident: a backup, a configuration file, a technical folder that nothing protects.
  • Forms that trust whatever they are sent, and can be turned to read or write what they should not.
  • A protected area whose other users' content you reach simply by changing a number in the address.
  • A service that answers anyone without limit, and can be called in a loop to run up the bill or overload the site.

None of these doors are visible from the home page. They are found by searching, methodically, for what an ordinary visitor never looks at.

What the audit covers

The test follows the same path as a real attacker, but breaks nothing and never touches your data.

1. Reconnaissance

Security headers, encryption settings, exposed files, forgotten subdomains: the first pass maps everything visible from the outside.

Typical case. An ordinary-looking site left an old backup downloadable at a guessable address. It held the full database. The audit found it within minutes.

2. Injection and content flaws

We check whether a field, an address or a parameter lets someone inject code, hijack the display, or make the site do what it should not.

Typical case. A contact form echoed back exactly what was typed. One well-chosen line was enough to show a fake login prompt to the next visitors.

3. Access control and data

This is the most sensitive point as soon as there are accounts: making sure one user can never reach another's data, and that sessions cannot be stolen.

Typical case. In a client area, replacing a number in the address showed another client's invoice. No one had noticed, because nothing flagged it.

4. Abuse and cost

We measure what a stranger can trigger without limit: mass sending, repeated calls to a paid service, automatable actions that cost money or availability.

Typical case. An online assistant answered everyone with no limit at all. A simple loop would have been enough to run up a paid service's bill overnight.

What an audit does not do

It shows you where the open doors are. It does not claim to be more than that.

  • It does not replace an official certification. If your sector or your insurer requires one, you need an accredited provider carrying professional liability. The audit gives you a serious technical assessment, not a regulatory stamp.
  • It breaks nothing to prove a point. No destructive attack, no flooding: flaws are demonstrated harmlessly, without ever touching your real data.
  • It does not fix anything by itself. Closing the flaws found is a separate service, which FastSolve also provides.
  • It holds for a given moment. A site changes: an audit records the state of the day, it does not watch the future for you.

An honest audit is worth more than a reassuring one. We would rather flag one flaw too many than one too few.

Frequently asked questions

How much does a security audit cost?

The amount depends on the size of the site, the number of sensitive features (accounts, payments, private areas) and the depth you want. A brochure site and a platform with a client area do not have the same surface. The price is set after an initial scoping of the perimeter. As a guide, excluding VAT, most audits fall between 800 and 2,500 euros. A platform with accounts and payments can reach 3,000 euros.

Is it dangerous for my site?

No. The audit is carried out non-destructively: no data is changed or deleted, no flooding attack is launched. Flaws are proven through harmless, clearly identified actions.

Why is written authorisation mandatory?

Testing a site without a mandate, even with good intentions, is illegal. Written authorisation and proof of ownership make the test legitimate and protect you as much as us. It is a condition, not a formality.

How long does it take?

From a few days for a simple site to a little more for a platform with accounts and payments. The initial scoping gives a clear timeframe before starting.

What do I receive at the end?

A clear report, ranked by severity, describing each flaw, its real impact and how to fix it. It is readable without being an expert, and directly usable for securing the site. And if you wish, we carry out the fixes ourselves.