Know where you’re exposed, and what to fix first.
Penetration testing, security monitoring and compliance readiness for UAE companies, from the people who do the testing.
Check your domain
See how well your company’s email and DNS are protected against spoofing and tampering. It takes about 5 seconds.
Runs in your browser through Cloudflare’s public DNS resolver. We never receive the domain you type.
Results for
- Not run
Spoofing protection DMARC
Tells receiving mail servers what to do with email that fakes your domain.
Show record
- Not run
Approved senders SPF
Lists the servers allowed to send email for your domain.
Show record
- Not run
Mail servers MX
Shows who handles the email sent to your domain.
Show record
- Not run
Signed DNS DNSSEC
Protects the answers your DNS gives out from being forged.
Show record
- Not run
Certificate lock CAA
Limits which companies may issue HTTPS certificates for your domain.
Show record
- Not run
Encrypted mail delivery MTA-STS
Makes sending servers encrypt email on its way to you.
Show record
Spoofing protection:
We test our own site first
Independent scanners grade this website. We re-run the checks automatically and fix anything that slips.
Mozilla HTTP Observatory
A+
Security headers, including a strict Content Security Policy.
View the reportQualys SSL Labs
A+
TLS 1.2 and 1.3 only, with HSTS on every response.
View the reportEmail spoofing
Reject
DMARC tells receiving servers to refuse email that fakes our domain.
Run the check on us
What we do
Start with the service you need now, and let the report tell you what to look at next.
We test your web apps, APIs, networks and cloud the way a real attacker would, then show you how to close every gap we find.
- Web application testing
- API testing
- Mobile app testing
- External network testing
- Internal network testing
- Vulnerability assessment
We set up monitoring that spots attacks early, prepare your team for incidents, and harden the systems attackers try first.
- Security monitoring setup
- Incident response readiness
- Incident support
- Website and WordPress hardening
- Email security
We get you ready for the security standards your customers and regulators ask about, with policies and training your staff will follow.
- UAE Information Assurance Standard
- Dubai Information Security Regulation
- UAE Personal Data Protection Law
- ISO/IEC 27001
- Security policies
- Awareness training and phishing simulation
We test the AI features and cloud accounts your business now depends on, before someone else finds the weak point.
- LLM application testing
- AI integration review
- AWS and Azure configuration review
- Identity and access review
How an engagement works
The same 5 steps whether we are testing one web app or your whole network.
Scope
A 30-minute call to agree what we test, when, and what is off-limits. You get a written scope and a fixed quote.
Test
We work inside the agreed window and contact you straight away if we find something critical.
Report
Findings ranked by business risk, each with evidence, impact and step-by-step fixes.
Fix
Your team makes the changes. We answer questions along the way.
Retest
We verify every fix and update the report, so you can share it with customers and auditors.
Reports your team can act on
Every finding says what we found, why it matters to the business, and exactly how to fix it. This is what one looks like.
Anyone can send email that appears to come from your company
Evidence
_dmarc.example.com TXT "v=DMARC1; p=none"Business impact
Attackers can send invoices or payment requests that look like they come from your finance team. Because the policy is p=none, receiving mail servers are told to deliver them anyway.
How to fix
- Confirm SPF and DKIM pass for every service that sends your email.
- Change the policy to
p=quarantineand review the DMARC reports for two weeks. - Move to
p=rejectonce legitimate mail passes.
Retest
Fixed and verified. The policy is now p=reject.
Who you’ll work with
You deal directly with the founders, from the first call to the retest.
Mohammad Thabet Hassan
Co-founder
Holds a B.Sc. in Cyber Security from Canadian University Dubai and is first author of 3 IEEE-published papers, on SQL-injection detection, voice-deepfake detection and over-the-air update security. Reports vulnerabilities to open-source maintainers through coordinated disclosure.
Omar Alraas
Co-founder
Co-author of the IEEE paper on over-the-air update compromise risk in smart mobility, and builder of the testbed behind it.
Questions buyers ask first
Anything else, ask us directly. We answer in plain language.
How much does a penetration test cost?
It depends on the scope: how many applications, user roles, APIs and IP addresses are in play. After a 30-minute scoping call you get a written scope and a fixed quote, so the price does not change halfway through.
How long does an engagement take?
A single web application usually takes one to two weeks, including the report. Larger scopes take longer. We agree the testing window and the report date in the written scope.
Will testing disrupt our systems?
We test inside the agreed window, avoid destructive techniques unless you approve them in writing, and stop straight away if a system becomes unstable. If production is sensitive, we can test a staging copy instead.
Do you sign an NDA?
Yes. We sign your NDA, or provide ours, before you share any details about your systems.
What do we receive at the end?
A report with an executive summary for management and, for every finding, the evidence, the business impact and the steps to fix it. Once your team has made the fixes, we retest and update the report.
Book a scoping call
Email us your company name, what you would like tested or reviewed, and your timeline. We reply within one business day to set up a 30-minute call.
hello@securitysolution.techFound a security issue in one of our own systems? Please follow our disclosure policy.