Attack surface discovery
Identify reachable hosts, services and relevant subdomains within the explicitly authorised scope.
Penny by Point-IT
Penny maps your authorised external attack surface, tests relevant security controls and turns the evidence into a clear, prioritised report reviewed by Point-IT before delivery.
External security assessment
Penny combines discovery, established security tooling, deterministic scoring and structured analysis. Findings are normalised, duplicates reduced and the final PDF is reviewed by Point-IT before it is sent to you.
Identify reachable hosts, services and relevant subdomains within the explicitly authorised scope.
Review externally visible controls, certificates, protocols, DNS and mail-security configuration.
Test exposed services for relevant known weaknesses and configuration issues.
A reproducible score based on tested controls and evidence, not an AI-generated guess.
Findings are classified by severity and translated into practical remediation priorities.
Before delivery, Point-IT reviews the generated PDF for obvious false positives, inconsistencies and nonsensical output.
How it works
01
You define the domain and public IP addresses and confirm that you are authorised to have them assessed.
02
Point-IT contacts you within 3 business days to validate scope and arrange the assessment.
03
Penny runs the authorised checks. Point-IT reviews the generated results before release.
04
The reviewed report is sent manually as a PDF by email. A customer portal is not yet part of the service.
Transparent pricing
All prices shown are exclusive of VAT and other applicable taxes. The base assessment covers one organisation and one primary domain. One optional public IP address is included at no extra charge.
A fresh assessment outside the normal cycle, useful after remediation or configuration changes.
Remediation, configuration changes, engineering and security consultancy are not included in assessment prices.
The assessment is a point-in-time, best-effort evaluation of the agreed external scope. It is not a certification and does not guarantee that vulnerabilities, compromise or future attacks cannot occur.
European infrastructure
Point-IT's website and Penny assessment infrastructure are hosted on servers located in Germany. Assessment data is handled within European infrastructure, subject to the applicable privacy and service terms.
Responsible by design
Penny only assesses an approved scope. Ordering the service does not trigger an automatic scan: Point-IT validates the scope first and contacts the customer before execution.
Terms of ServiceOrder Penny
Choose a service and submit the authorised scope below. Point-IT will contact you within 3 business days to validate the scope and arrange execution. No scan starts automatically.
Contact
Use this form for product questions, partnerships, responsible disclosure or general enquiries.