What you get

We find and close security gaps in the websites, servers and office IT of small and mid-sized businesses: a check, a report in plain language, the fix, and a second check to confirm it.

You pay for a result: closed vulnerabilities, a clean server, a report, documents ready for an auditor.

Five services and what you receive from each

1. Website and server security audit

We check the external perimeter, the CMS and its plugins, hosting control panels, TLS and security headers, DNS and mail (SPF, DKIM, DMARC), access rights and MFA, and backups.

You receive: a written report on what we found, how dangerous it is, and what to fix today, this month or later, plus a short plain-language version for the owner.

2. Penetration testing of web applications and the external perimeter

We test only with written permission from the owner of the system, against agreed targets and within an agreed time window.

You receive: a report with reproducible findings and evidence, a remediation plan, and a free re-test of the fixes within the same scope.

3. Incident response after a breach

We find malicious code and web shells, establish how the attacker got in and what leaked, close the entry point and restore the system.

You receive: a clean site or server, the entry point closed, passwords and keys changed, a backup verified by a test restore, and a report on how they got in, what was affected and what we did.

4. Hardening and remediation

We fix what the audit found: updates, server configuration, permissions, MFA, backups with a tested restore, and monitoring.

You receive: a completed checklist of measures with every item marked, a verified restore from backup, MFA switched on, and alerts configured.

5. Preparation for ISO/IEC 27001 and CyberSecure Canada

Policies, a risk register, the Statement of Applicability (SoA) and an internal audit. We work under our own information security management system based on ISO/IEC 27001:2022.

You receive: the document set (policies, risk register, SoA), a completed internal audit, and a list of what remains before the certification audit.

How we work

1. Agree the scope. A short call or the contact form: we decide together what gets checked.

2. Scope letter. Before any test, the owner of the system signs written permission with the targets, dates, contacts and the systems that must stay untouched. Work starts after the signature.

3. Check and report. A report in plain language, with the technical detail in an appendix.

4. Fix. We fix the findings ourselves or together with your contractor.

5. Re-test. We check again and confirm that each finding is closed.

We do the work and hand you the result. Our team uses its own experience and strong tooling, including Claude models, to find problems faster. Every finding is checked by a person before it reaches your report, and we fix what we find.

INNOVA CONSULT LTD has been approved for Anthropic's Cyber Verification Program (CVP), which lets verified organizations use Claude models for defensive cybersecurity work.

Who signs the contract

Security engagements are contracted with INNOVA CONSULT LTD., Ottawa, Ontario (Corporations Canada, Corporation Number 1522612). Tools and AI models are used within their providers' rules. Client data is covered by a confidentiality agreement.

Cost

Each engagement gets a fixed estimate once the scope is agreed.

Related

Setting up servers, mail and backups from scratch: turnkey IT infrastructure. Building the site itself: corporate websites. To agree what gets checked, write to us.


Maksym Stepanenko, founder of Marketing MIX. Last reviewed: 2026-09-25.