Forensic Five is a Canadian firm that reviews what you expose to the internet, explains the risk in plain language, and helps you decide what to fix. Work is scoped in writing, scheduled with your team, and delivered as a report you can share with counsel, insurers, or a board.
Public sites and portals reviewed from the outside in.
Host and configuration posture, not a checkbox export.
Login flows, sessions, and the paths that hold data.
Remediation, incidents, and decisions after the report.
The public scan does not require an account. Paid work does not start until you approve a written scope and fee.
Three engagements we price and deliver as written work: a scoped assessment, a scan (public or in-depth), and consulting after you already have a problem or a deadline.
Website, application, and server reviews scoped to how you actually operate. You receive a written report, a risk ranking, and a conversation about what to fix first.
Start with a free public-site scan, or engage us for a deeper application and server scan. Surface findings first; analyst review when the score is not enough.
When you already know something is wrong — or need a plan before an audit, a launch, or a client review — we sit with your team and work the problem.
Controlled attack simulation for networks, web apps, and exposed services — when you need evidence, not a dashboard.
Learn morePractical sessions for staff, managers, and executives — built around how your people actually use email, apps, and accounts.
Learn moreYou approve the scope, the window, and the fee before any testing begins. The report states what was covered and what was not.
We confirm targets, constraints, and what “done” looks like — a site, a server, an application, or a mix.
Automated checks plus analyst review. We validate what matters and discard noise before it reaches your inbox.
Prioritized findings, evidence, and recommended next steps — written for operators and for the people who approve the work.
We walk the report with you, help sequence remediation, and retest when you want confirmation the fix held.
Most organizations hesitate for the same reasons. These are the terms we work under so a review does not become a risk of its own.
We test only the hosts, applications, and accounts you authorize in writing. We do not scan neighbouring systems, staff personal devices, or third-party services you do not control.
Assessments and scans are scheduled with you. Destructive or high-impact tests are off by default. If a check could affect availability, we say so before it runs.
Reports are confidential to the named client. We do not publish client names, scores, or findings. We will sign an NDA when your counsel requires it.
The free website scan is a public-surface check. It is useful. It is not a substitute for a scoped assessment. Paid work includes analyst review and a written report you can stand behind.
You receive a written scope and fee before we start. There is no requirement to buy hosting, tools, or a monthly package to get the report. Follow-on work is optional.
If a finding is unconfirmed, we mark it that way. We do not promise that every vulnerability has been found. The report states method, coverage, and limits so you can brief a board or an insurer honestly.
We work with professional services firms, non-profits, and growing companies that need a defensible answer about their internet-facing systems — without staffing a security department.
Reports are written so a technical lead can act and a director can brief. The assessment is not contingent on buying hosting, software, or a retainer from us or from an affiliated company.
Typical assessment window, including the written report
Usual response to new inquiries during business hours
Public website scan — no login and no mailing-list signup
We will execute your confidentiality agreement before work begins
Tell us the site, server, or application. We will reply with what we would review, how long it takes, and a fee — before any testing starts.