A website your customers genuinely trust.
The SAB Security Deep Review shows you in 48 hours whether your website convinces visitors or makes them leave. A non-destructive external review with a clear PDF report — written for business owners, not technicians.
Written permission required before every review. No destructive testing. No risky attacks. No hidden costs.
SAB Security Deep Review — 299 €
A professional external review of your website. One-time payment. No subscription. In 48 hours, you'll know where you stand.
For small businesses. External review with a clear PDF report and one retest included.
- 1 website review
- HTTPS, TLS & certificate check
- Security header audit (HSTS, CSP, X-Frame, etc.)
- Email security (SPF, DKIM, DMARC)
- Publicly exposed files & admin pages check
- Technology & CMS footprint review
- Sitemap / robots.txt / security.txt
- Google visibility & trust signals
- PDF report with executive summary
- One retest included
Small gaps — big impact on your customers
Most small business websites have preventable weaknesses. The owner usually only notices when something has already gone wrong. It doesn't have to be that way.
What the Deep Review checks
Every check is external, non-destructive, and safe. Your website keeps running normally throughout.
HTTPS & Redirects
Valid certificate, modern TLS protocols, correct HTTP→HTTPS redirect, no mixed content. The absolute baseline for any trustworthy website — and a Google ranking factor.
Security Headers
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy. Missing headers are among the most common and easiest-to-fix security gaps.
Email Security
SPF, DKIM, DMARC verification. Without these three DNS records, anyone can send emails pretending to be your domain. We check all three and provide exact configuration recommendations.
Publicly Exposed Files
Admin logins, phpMyAdmin, debug endpoints, directory listings, accessible backups — we document everything visible from outside with concrete remediation steps.
Technology Footprint
CMS detection, plugin versions, server headers, outdated JavaScript libraries — we show what your website reveals about its technology stack.
Google Visibility & Trust Signals
Sitemap, robots.txt, security.txt, canonical URLs, privacy policy and legal notice — everything your visitors and search engines can see.
Four steps from inquiry to result
No complicated processes, no endless meetings, no technical jargon.
You reach out
Send us a brief email with your website address. We'll get back to you within one business day.
We define scope
Together we agree in writing on exactly what will be checked. You'll know precisely what happens — and what doesn't.
You authorize
With your written authorization, we begin the review. Safe, controlled, and only within the agreed scope.
You receive your report
Within 48 hours, you get the PDF report with concrete recommendations. Includes one free retest after you apply the fixes.
A report you can actually read and use
No jargon. No fear tactics. Clear findings, prioritized by business risk — written for decision-makers, not engineers.
SAB Security Deep Review
Executive Summary — A concise overview of findings, risk levels, and recommended next steps.
Risk: Medium — users may connect over unencrypted HTTP
Recommendation: Enable HSTS with max-age=31536000 and include subdomains.
Risk: Low-Medium — publicly accessible admin interface
Recommendation: Restrict access by IP or add additional authentication layer.
Every report includes: Executive Summary, prioritized findings, practical remediation steps, and one retest.
Frequently Asked Questions
Who is the Deep Review for?
Small businesses: restaurants, tradespeople, transport companies, doctors, lawyers, real estate agents, local service businesses, freelancers, and agencies. If you have a website and want to know whether it builds customer trust, the Deep Review is for you.
What exactly do you check?
HTTPS and TLS encryption, security headers (HSTS, CSP, X-Frame-Options), email security (SPF, DKIM, DMARC), publicly exposed admin pages and files, technology footprint, sitemap and robots.txt, Google visibility and basic trust signals. All visible from the outside — non-destructive and safe.
Is this a penetration test or hacking?
No. The Deep Review is an external trust and security review. We only observe what is publicly visible from the outside. No active attacks, no denial-of-service tests, no social engineering.
What do I get after 48 hours?
A clear PDF report with an executive summary, prioritized findings, practical remediation steps, and one free retest. Written in plain language, no technical jargon, no fear tactics.
Do you need to break into my website?
No. We check from the outside only — via your web presence, DNS records, and public information. Every review requires your written authorization before any work begins.
How long does it take?
The Deep Review is delivered within 48 hours after written authorization. Urgent requests can often be processed faster — reach out and we'll let you know.
What does the Deep Review cost?
299 € including one retest. One-time payment, no subscription, no hidden costs. One price, one service, one clear report.
Do you only work with written permission?
Yes, without exception. This protects both sides and ensures you know exactly what will be checked. Before any activity begins, we define the scope together and you authorize it in writing.
What you receive
Your website is checked from the outside, just like a customer, search engine or attacker would see it.
- HTTPS and redirect problems
- Missing security headers
- Email fraud risk: SPF, DKIM and DMARC
- Publicly exposed files and folders
- Technology fingerprints that reveal too much
- Basic trust and reputation signals
- Website structure and visible security weaknesses
I do not only show the problems
A normal technical report often leaves you with one question: "Okay... but what should I do now?"
That is why every SAB Security Deep Review includes clear fix guidance.
What the issue means
Plain-language explanation, no technical jargon.
Why it matters for your business
The real-world impact on trust, revenue, and reputation.
How serious it is
Clear priority levels so you know what to fix first.
Who should fix it
Your web designer, hosting provider, or IT support.
What exactly should be changed
Specific, actionable steps — not vague suggestions.
A simple explanation you can forward
Ready-to-send wording for your technical contacts.
Finding: Your domain has no DMARC protection.
Business risk: Attackers may abuse your domain name for fake invoices or phishing emails.
Fix guidance: Add a DMARC DNS record. Start with monitoring mode, then move to stricter protection once legitimate email sources are confirmed.
You do not need to understand DNS yourself. You receive wording that you can send directly to your provider.
A hacked website is not just an IT problem
A hacked website can become a customer trust, legal and revenue problem.
If attackers gain access to your website or abuse your email setup, they may be able to:
- Redirect visitors to fake or harmful pages
- Send fake invoices using your business name
- Abuse your domain for phishing emails
- Expose customer contact details or form submissions
- Damage trust with existing and future customers
- Trigger legal, GDPR or insurance-related problems
- Cause your website to disappear from Google search results
- Make customers question whether your business is professional and trustworthy
Most small businesses only react after something has already happened. SAB Security helps you find visible risks earlier — before they become expensive problems.
299 € is not just a cost. It is risk prevention.
One security incident can cost far more than a website review.
A hacked website, fake invoice scam or exposed customer data can lead to:
- Emergency IT costs
- Lost customers
- Business interruption
- Reputation damage
- Legal stress
- GDPR-related consequences
- Expensive cleanup work
- Loss of trust in your business
The SAB Security Deep Review gives you a clear picture of your visible website and email security risks — for one fixed price.
You receive the findings, the business impact and practical fix guidance you can forward to your web designer, hosting provider or IT support.
Limited review capacity
SAB Security is a small, focused security service. Every Deep Review is manually checked, written and explained — not delivered as a generic automated scan.
To keep the quality high, only a limited number of reviews are accepted each month. After booking, your website is placed into the next available review slot.
Security is not a one-time document
Your website can be safe today and exposed tomorrow. Plugins change. Hosting settings change. DNS records break. New files appear. Old backups may become public. Email security settings can be modified or forgotten.
Your website and email security setup are checked regularly for common visible risks. If something important changes, you receive a clear warning and practical next steps.
- Regular external security checks
- Email security monitoring (SPF, DKIM, DMARC)
- Early warning when something changes
- Clear fix guidance for every finding
- Cancel anytime
Monthly care is optional and does not replace the initial Deep Review. The goal is simple: find problems early, understand the risk, fix them before they become expensive.
Ask About Monthly CareSee your website through your customers' eyes — before someone else does.
Based in Karlsruhe, Germany. Serving small businesses worldwide. Every review requires written authorization. Every report is written in plain language.
Request Deep Review — 299 €Questions? Email us at info@sab-security.net
Frequently Asked Questions
Who is the Deep Review for?
Small businesses: restaurants, tradespeople, transport companies, doctors, lawyers, real estate agents, local service businesses, freelancers, and agencies. If you have a website and want to know whether it builds customer trust, the Deep Review is for you.
What exactly do you check?
HTTPS and TLS encryption, security headers (HSTS, CSP, X-Frame-Options), email security (SPF, DKIM, DMARC), publicly exposed admin pages and files, technology footprint, sitemap and robots.txt, Google visibility and basic trust signals. All visible from the outside — non-destructive and safe.
Is this a penetration test or hacking?
No. The Deep Review is an external trust and security review. We only observe what is publicly visible from the outside. No active attacks, no denial-of-service tests, no social engineering. No hacking — just careful observation.
What do I get after 48 hours?
A clear PDF report with an executive summary, prioritized findings, practical remediation steps, and one free retest. Written in plain language, no technical jargon, no fear tactics.
Do you need to break into my website?
No. We check from the outside only — via your web presence, DNS records, and public information. Nothing invasive. That said, every review requires your written authorization before any work begins.
How long does it take?
The Deep Review is delivered within 48 hours after written authorization. Urgent requests can often be processed faster — reach out and we'll let you know.
What does the Deep Review cost?
299 € including one retest. One-time payment, no subscription, no hidden costs. One price, one service, one clear report.
Do you only work with written permission?
Yes, without exception. This protects both sides and ensures you know exactly what will be checked. Before any activity begins, we define the scope together and you authorize it in writing.