Request a free project consultation
AI-Assisted Security Review

Before a small issue grows,
we verifyyour server configuration and vulnerabilities.

Using a time-limited audit account, we review SSH, firewalls, permissions, CVEs, web servers, logs, and CMS configuration. AI helps organize what to inspect; final findings are reviewed against actual settings and public evidence. The diagnostic phase prioritizes read-only commands. We make changes only after approval.

30
Security checks
₩99K~
Starting price per server
PDF
Evidence, risk, and action order

* This console previews the actual report format · all diagnostic checks are read-only

Read-only diagnostics · no unapproved changes
Temporary account removed as soon as the audit ends
Schedule scope and delivery date agreed after intake
Configuration changes performed only after client approval
Why Audit

Unchecked settings
accumulate risk over time

Package versions, firewall rules, account privileges, and public ports keep changing during operation. The first step is to establish the current state with evidence.

No single tool can fully assess a security issue. Real priorities emerge only when server settings, public vulnerabilities, web applications, and logs are reviewed together. AI narrows the review quickly; the final report is built around evidence that can be independently verified.
Evidence-Based Review

We verify the evidence instead of trusting AI output alone

We separately inspect system configuration, code and secrets, and logs and exposures, then prioritize findings against actual files, versions, public CVEs, and logs.

System configuration review
SSH · permissions · firewall

We inspect sshd_config, sudoers, account and file permissions, firewall rules, and exposed services, recording evidence for risky settings.

SSH hardeningPrivilege analysisReporting
Code and secret review
Web app · environment variables · CMS

We inspect application source and configuration files for exposed secrets, unsafe permissions, outdated CMS components, plugins, and known vulnerability candidates.

Web app risks.env reviewCMS plugins
Log and exposure review
Auth logs · ports · packages

We review authentication logs, open ports, running services, and package versions to find repeated failures, unnecessary exposure, and pending updates.

Log analysisAnomaly detectionTimeline review

※ AI-flagged items are included in the report only after they are checked against actual server settings and public evidence.

Audit Scope

30 checks, with no blind spots

We break 12 security areas into 30 specific checks and clearly show what each plan covers. Diagnostics are performed safely over SSH with read-only commands.

LLite — 10 essentials SStandard — 10 more, 20 total PPro — all 30 checks

Showing all 30 checks. Select a plan to highlight what it includes.

SSH hardening

  • LRoot login · password authentication · default port exposure
  • SAllowUsers · PubkeyAuth · ClientAlive · 2FA settings
  • PDeep review of SSH key permissions and exposed authorized_keys files

Firewall / ports

  • LFirewall status (ufw · iptables · firewalld)
  • LExternally exposed TCP and UDP ports
  • S0.0.0.0 bindings · unnecessary services · rule consistency

Package & kernel CVEs

  • LKernel CVE matching and boot option review
  • SCVE matching for major installed packages and exposed versions
  • PFull CVE matching · public exploit availability · patch order

Accounts & privileges

  • LDuplicate UID 0 · empty passwords · login-capable accounts
  • SOverprivileged sudoers and wheel / admin groups
  • PUnused and service accounts · recent login history

File permissions

  • L/etc/shadow · /etc/passwd · web root · .env permissions
  • Psetuid · setgid · possible PATH hijacking binaries

Web server · PHP · DB

  • LServer version exposure · directory listing · expose_php
  • SMySQL bind-address · default accounts · remote access
  • SPHP security settings (disable_functions · open_basedir · sessions)

SSL / TLS

  • LCertificate expiry · chain validation · self-signed certificates
  • STLS 1.0 / 1.1 and weak protocol status
  • SWeak cipher suites · HSTS · OCSP stapling

Log analysis

  • SBrute force, dictionary attack, and scan traces in auth.log
  • PSuspicious IPs and attack patterns in web access logs

Defense controls

  • Lfail2ban and crowdsec installation status
  • SActive jails · ban history · custom filter review

Cron & suspicious jobs

  • PFull review of crontab · at · systemd timers
  • PRoot cron · @reboot · external script execution

CMS-specific checks (WordPress)

  • PCore · plugin · theme CVE matching
  • Pwp-config · admin accounts · REST API · file editor

Backups & exposed assets

  • LPublic exposure of /.git · /.env · phpinfo · phpMyAdmin
  • POff-site backups · restore testing · DR scenario review
Pricing

Practical security investment

From a focused diagnostic review to remediation, subscriptions, and incident response. Start with one server and pay only for what you need.

Lite

10 essentials — core exposure and configuration review

₩99,000 /server

VAT excluded · ₩60,000 per additional server

  • 10 essential checks covering SSH, firewalls, kernel CVEs, accounts, TLS, and exposed assets
  • Risk ratings: high / medium / low
  • PDF report · schedule confirmed after intake
  • Surface-level diagnostic scope
Apply

Pro

All 30 checks — penetration simulation and 6-month recheck

₩690,000 /server

VAT excluded · ₩420,000 per additional server

  • Standard 20 + 10 deep checks = all 30 items
  • Deep areas: cron · WordPress · backup/DR · public exploit availability
  • Read-only penetration simulation recreating realistic attack paths
  • One free recheck within 6 months, including post-remediation validation
Apply
Tier Example work Price per item
A · Small SSH hardening, fail2ban setup, simple firewall policy, single patch ₩90,000 /item
B · Medium TLS rebuild, WAF/Cloudflare integration, exposure blocking, permission redesign ₩250,000 /item
C · Large Automated backups, log pipeline, full CMS cleanup, incident remediation ₩690,000~ /item (estimate)
Hourly engagement (one-hour minimum) ₩250,000 /hour

Clients who purchase a diagnostic report receive 10% off per remediation item.

Basic

1 server · monthly review

₩129,000 /month

VAT excluded

  • Monthly review and report
  • Change alerts by Telegram or email
  • One urgent patch recommendation per month
Apply
Process

Four steps from intake to report

1

Intake / payment

Share your server details and plan through the form below. The estimate updates automatically.

2

Set up access

We provide a temporary audit-account guide. Access is removed immediately after the review.

3

Run the audit

We prioritize read-only commands and verify AI-assisted findings against actual settings and public evidence.

4

Report / remediation

We return a PDF risk matrix and recommended-action estimate. Remediation is optional.

Scope & Limits

What we can and cannot do

We are equally clear about what we cannot promise.

Supported

  • Linux/Unix — (Ubuntu, Debian, CentOS, RHEL, Amazon Linux, and more) — all 30 checks
  • macOS servers — supported when SSH access is available
  • Windows Server — partial PowerShell-based review when OpenSSH Server is enabled
  • WordPress / general PHP CMS — full core, plugin, and configuration review
  • Docker / container hosts — containers included when host access is available
  • AWS Lightsail / EC2 / GCP / Naver Cloud — broad IaaS support

Limited / excluded

  • Managed services — (RDS, Aurora, managed Redis, and similar) — no host access; IAM-based scope requires separate discussion
  • Network appliances — (firewalls, routers, switches) — quoted separately
  • Aggressive penetration testing — (brute force, exploit execution, DoS) — not performed due to cloud TOS risk
  • Systems you do not own or administer — requests are refused
  • Zero-downtime guarantee — diagnostics prioritize low-load queries; changes require user approval
  • Legal disputes or litigation support — outside the security-audit scope
FAQ

Frequently asked questions

The questions we hear most often from teams considering an AI-assisted server security audit.

How is an AI-assisted server audit different from a conventional audit?

We use AI as an assistant to quickly organize configuration and log items worth checking.

The final report records verifiable evidence such as actual settings, version information, public CVEs, and logs. A person reviews priorities and potential false positives.

Is it safe to provide SSH access?

We recommend adding our public key to a time-limited temporary audit account. Diagnostics prioritize read-only commands, and any configuration change requires separate approval.

After the review, we guide you through removing the temporary account and registered key.

Will the audit affect server operation?

We prioritize read-only commands and low-load checks. Work that could add load, such as large log analysis or external scans, is scheduled and scoped in advance.

Actual remediation, such as installing fail2ban or rebuilding TLS, proceeds only after client approval and is documented before and after.

When will I receive the report?

Timing depends on the number of servers, log scope, web services, and CMS configuration. We confirm the available audit window and report date after reviewing the intake.

Emergency response is scheduled separately after we confirm the current situation and access.

Can you audit WordPress sites?

Yes. Our WordPress-specific review covers core-version vulnerabilities, known plugin and theme CVEs, wp-config.php permissions, admin accounts, wp-admin protection, REST API exposure, and XML-RPC status.

We also match the vulnerability history of popular plugins such as Elementor, WooCommerce, and Contact Form 7 against CVE databases.

Can you remediate the vulnerabilities you find?

Yes. Remediation is optional. The report includes an estimate for each item: A small ₩90,000, B medium ₩250,000, or C large from ₩690,000. You can select only the items you need.

Clients who purchase a diagnostic report receive 10% off remediation rates. Urgent work can also be billed hourly at ₩250,000.

Do you support cloud servers such as AWS Lightsail, EC2, and Naver Cloud?

Yes. We support most IaaS environments with SSH access, including AWS EC2 and Lightsail, GCP Compute Engine, Azure VM, Naver Cloud, NHN Cloud, KT Cloud, and Oracle Cloud.

Docker and Kubernetes hosts can include container-level checks when access is available. Managed services without host access, such as RDS, Aurora, and managed Redis, require a separately agreed IAM-based scope.

Should I choose a one-time audit or monthly monitoring?

If you do not yet have a clear baseline, start with a one-time Lite ₩99,000 or Standard ₩249,000 audit.

For commerce, membership, payment, and other high-impact services, the strongest combination is an initial audit followed by monthly monitoring from ₩129,000 for new CVEs and configuration drift.

Apply

Request a server audit

Your estimate updates from the information entered. After reviewing the request, we confirm the available scope and schedule.

Security audit request

Only the required fields (*) are needed to submit. We can fill in details during consultation.
0 / 4 complete
1 Contact information
2 Server information
Never enter a password or private SSH key here. Access details are exchanged through a separate secure channel.
3 Access method
4 Choose a plan *
Estimated price VAT excluded · updates automatically
₩249,000

This site is protected by reCAPTCHA and the Google Privacy Policy & Terms of Service apply.

Estimated price
₩249,000
Apply →