St. Albert, Alberta · Serving clients across Canada

Security assessments for websites, servers, and applications

Forensic Five is a Canadian firm that reviews what you expose to the internet, explains the risk in plain language, and helps you decide what to fix. Work is scoped in writing, scheduled with your team, and delivered as a report you can share with counsel, insurers, or a board.

Websites

Public sites and portals reviewed from the outside in.

Servers

Host and configuration posture, not a checkbox export.

Applications

Login flows, sessions, and the paths that hold data.

Consulting

Remediation, incidents, and decisions after the report.

The public scan does not require an account. Paid work does not start until you approve a written scope and fee.

What we deliver

Core services

Three engagements we price and deliver as written work: a scoped assessment, a scan (public or in-depth), and consulting after you already have a problem or a deadline.

Assessments

Website, application, and server reviews scoped to how you actually operate. You receive a written report, a risk ranking, and a conversation about what to fix first.

  • Web and application security reviews
  • Server and infrastructure posture
  • Policy, process, and control walkthroughs
Assessment details

Scans

Start with a free public-site scan, or engage us for a deeper application and server scan. Surface findings first; analyst review when the score is not enough.

  • Free website security scan
  • Headers, TLS, ports, and exposure checks
  • Follow-on analyst review and retest
Run a free scan

Consulting

When you already know something is wrong — or need a plan before an audit, a launch, or a client review — we sit with your team and work the problem.

  • Remediation and hardening guidance
  • Incident and breach support
  • Policy, architecture, and vendor review
Consulting details

Penetration testing

Controlled attack simulation for networks, web apps, and exposed services — when you need evidence, not a dashboard.

Learn more

Security training

Practical sessions for staff, managers, and executives — built around how your people actually use email, apps, and accounts.

Learn more
How we work

A clear engagement, start to finish

You approve the scope, the window, and the fee before any testing begins. The report states what was covered and what was not.

1

Scope

We confirm targets, constraints, and what “done” looks like — a site, a server, an application, or a mix.

2

Assess & scan

Automated checks plus analyst review. We validate what matters and discard noise before it reaches your inbox.

3

Report

Prioritized findings, evidence, and recommended next steps — written for operators and for the people who approve the work.

4

Consult

We walk the report with you, help sequence remediation, and retest when you want confirmation the fix held.

Engagement terms

What we will and will not do

Most organizations hesitate for the same reasons. These are the terms we work under so a review does not become a risk of its own.

Written authorization only

We test only the hosts, applications, and accounts you authorize in writing. We do not scan neighbouring systems, staff personal devices, or third-party services you do not control.

Production stays available

Assessments and scans are scheduled with you. Destructive or high-impact tests are off by default. If a check could affect availability, we say so before it runs.

Findings stay with you

Reports are confidential to the named client. We do not publish client names, scores, or findings. We will sign an NDA when your counsel requires it.

A scan is not an assessment

The free website scan is a public-surface check. It is useful. It is not a substitute for a scoped assessment. Paid work includes analyst review and a written report you can stand behind.

Quoted after scope — not a retainer trap

You receive a written scope and fee before we start. There is no requirement to buy hosting, tools, or a monthly package to get the report. Follow-on work is optional.

We do not over-claim

If a finding is unconfirmed, we mark it that way. We do not promise that every vulnerability has been found. The report states method, coverage, and limits so you can brief a board or an insurer honestly.

The firm

Independent review. Canadian delivery.

We work with professional services firms, non-profits, and growing companies that need a defensible answer about their internet-facing systems — without staffing a security department.

Reports are written so a technical lead can act and a director can brief. The assessment is not contingent on buying hosting, software, or a retainer from us or from an affiliated company.

  • Based in St. Albert, Alberta — engagements delivered across Canada
  • Findings treated as confidential client material
  • Named analyst on every paid engagement
About the firm
1–4 weeks

Typical assessment window, including the written report

One day

Usual response to new inquiries during business hours

No account

Public website scan — no login and no mailing-list signup

NDA-ready

We will execute your confidentiality agreement before work begins

Request a written scope

Tell us the site, server, or application. We will reply with what we would review, how long it takes, and a fee — before any testing starts.