Ongoing security

TrueShield Security Audit

We measure your site from the outside every month, explain what we find in plain language, and tell you what to do about it. No guarantee against intrusion β€” nobody can give you one. But you stop guessing.

0days

is the average time to find a breach

The lowest figure in nine years, and still eight months. The longer something runs unnoticed, the more it costs to sort out. A breach costs in the order of USD 4.44 million globally, a number that actually fell 9% last year.

IBM Cost of a Data Breach Report, 2025

0requests

were blocked against our own site in 20 days

Measured in our Cloudflare log in July and August 2026. This is not an attack on us in particular. It is the background noise every site on the internet stands in, around the clock.

Our own measurement, 2026-07-12 to 2026-08-08

You know where the site stands, every month

You get a grade, a list of what needs fixing, and the evidence behind each point. Not a technical report you have to interpret, but an answer you can act on. A check we could not complete is reported as unresolved, never as approved. And no report reaches you before a person has read it.

The 28 checks

Everything measured, every time. No selection, no surprises.

Domain and infrastructure
That the domain's basics are correct and cannot be forged
Open ports
That nothing unnecessary is open to the internet
HTTPS and redirects
That visitors always land on the encrypted version
SSL/TLS certificate
That the connection is encrypted and the certificate is valid
Certificate on your server
That the certificate behind the shield has not expired
Security headers
That the browser gets instructions blocking common attacks
Cross-site sharing
That other sites cannot read your data
Cookies and sessions
That logins cannot be stolen by a script
Technology and CMS
Which platform you run and its known weak points

The report is the product

Two layers in one document: one for the people deciding, one for the people fixing. Every finding has a line stating the evidence, so you can check us.

  • One layer for the people deciding
  • One for the people fixing
  • An evidence line under every finding
  • The same format every month
A page from a real TrueShield report

You get a grade, not a list

A to F on a scale where urgent findings weigh heaviest. The same scale every month, so a change means something.

The scale is the same every month and counted the same way every time, so a change between two reports means something real and not that we moved the yardstick.

A
90–100
B
80–89
C
70–79
D
60–69
E
50–59
F
0–49

In your report, your own grade is marked like this.

Choose how close we stand

Insyn sees from outside. Skydd stands in front. Vakt sees inside.

Insyn

We see the site from outside

€0/mo
  • Monthly scan of the site
  • Uptime with history
  • Automatic report, unread by a person
  • Free if we host you
Most chosen

Skydd

We stand in front of the site

€390/mo
  • Everything in Insyn
  • Cloudflare Pro, paid by us
  • Traffic monitoring at the wall
  • Report reviewed by a person
  • Alarm when a backup job goes quiet
  • 2 hours of remediation time per month

Vakt

We see inside the server

€690/mo
  • Everything in Skydd
  • Agent on the server
  • Code integrity watched
  • Alarms on the host condition
  • 4 hours of remediation time per month

The line between Insyn and Skydd is human judgement

Insyn tells you what was found. Skydd tells you what to do about it. That is the whole difference, and the only reason to upgrade.

More coverage, never a stronger guarantee. Each level sees more of the picture, but none is a guarantee against intrusion.

WordPress is a risk, and it is manageable

WordPress powers 41.2% of all websites (W3Techs, August 2026). That makes it the most attacked, not the worst. In 2025, 11,334 new vulnerabilities were found in the ecosystem, a 42% increase. 91% of them were in plugins. The core had a handful.

And 39.1% of the sites that were actually infected were running outdated software at the time. The risk sits in the plugins, and plugins are handled by someone keeping them updated. That is what the remediation time in Skydd and Vakt buys. We run five WordPress sites ourselves.

W3Techs (2026-08) Β· Patchstack, State of WordPress Security (2025) Β· Sucuri, Hacked Website Report (2023)

How to start

Insyn costs nothing if we host you. You get the first report in the next monthly run and can read it before deciding on anything more.