Nyakinda

Security checks for small organisations

Find out what a stranger can see, before a stranger does.

Fixed-price external security checks for websites, web applications and cloud setups. We agree the scope with you in writing first, test only what you authorize, and send back a plain list of what to fix.

Ask for a checkSee the services

Three fixed services

Each has a fixed scope, a fixed price and a fixed delivery time, so you know what you get before you agree to anything.

External Exposure Snapshot

What a stranger on the internet can see of up to ten of your domains: names, certificates, TLS, e-mail authentication and exposed services, on one page.

  • One-page exposure map and a fix list
  • Delivered within 48 hours of authorization
  • One retest of the fixes included
€650fixed price

Web App Baseline Test

One web application looked at from outside, with safe, low-rate scanning. Every high-severity finding is checked by a person before it reaches you.

  • PDF report, executive summary and a prioritised fix list
  • Delivered within five business days of authorization
  • One retest of the fixes included
€2,400fixed price

Cloud and Repo Hygiene Review

A read-only look at your cloud configuration, plus code, dependency, container and secret checks on the repositories you hand us.

  • Prioritised fix list and a covering note
  • Delivered within five business days of authorization
  • One retest of the fixes included
€1,200fixed price

Prices are per package and exclude any applicable VAT. If you need something outside these three, ask: anything beyond the package is quoted and agreed in writing before work starts.

How it works

Nothing is tested until you have said, in writing, that we may.

  1. You tell us what to look atThe domains or application, who can authorize testing, and when it suits you.
  2. We confirm the scope in writingYou get a scope summary and a proposal with the price, the date and what is not included.
  3. You authorize itOwnership is proven with a DNS record or a signed letter. An email saying “go ahead” is not enough, by design.
  4. We run the checksInside the window you chose, at a low rate, on the hosts you listed and nothing else.
  5. A person reviews everythingFindings are verified and every word of the report is read before you see it.
  6. You get a fix list, then a retestPlain language, in order of importance. When you have fixed things, we check again.

The rules we work by

These are built into how we work, not just promises on a page.

  • Written authorization first. We send no test traffic to anything you have not authorized.
  • Only what is on the list. If we find a host you did not list, we tell you and leave it alone until you say so.
  • No disruption. No denial-of-service or load tests, no social engineering, and nothing that changes state on your systems.
  • Third parties stay out. We do not test your CDN, your host or a platform you use without that provider’s permission.
  • A person decides. We use software, including AI, to do the routine work. A person reviews every finding and every report before it is sent, and approves every delivery.
  • Secrets stay out of reports. If we come across a password or a key, we tell you it is exposed and never copy it into a report or a message.

We do not guarantee that a system is secure. A check shows what we could see on the day, inside the scope you authorized.

Ask for a check

Tell us what you would like looked at and by when. We reply with what we would need from you and a fixed price.

hello@nyakinda.com

Found a security problem on one of our own sites? Please write to the same address; see security.txt.