Architecte du Réel
Web security audit

Secure your web presence before the attack

Comprehensive remote audit. OWASP methodology, CVSS 3.1 scoring, GDPR compliance. Audit by a systems architect with 30 years of critical infrastructure experience. Passive and active testing. Report within 5 days. OWASP WSTG v4.2 (11 phases), CVSS 3.1, PTES. Tools: Burp Suite, Nmap, Nessus, custom scripts. Re-audit offered. From the Atlantic coast, satellite connection.

What the audit covers

  • OSINT reconnaissance and attack surface mapping
  • Passive intrusion tests (XSS, SQLi, NoSQLi)
  • Security headers, TLS, DNS, certificate analysis
  • GDPR compliance: trackers, cookies, consent
  • Deep audit of critical vulnerabilities (P0)
  • Scraping and quantification of exposed data
  • Active tests: known CVEs, social engineering, phishing
  • Overall score out of 100 with risk matrix
  • Prioritized remediation plan with timelines and effort
  • Executive summary for management (no jargon)

For whom?

B2C / B2B e-commerce

Sites with product catalog, cart, payment. Protection of customer data and inventory.

Extranets and portals

Distributor portals, client spaces, sensitive APIs. Risk of business data leakage.

Startups and SaaS

Modern stacks (Nuxt, Next, Vercel, AWS) often misconfigured in production.

Custom quote
Audit based on scope - Report within 5 days

First contact free. No commitment after the audit. Sample deliverable: 40+ page PDF report with archived material evidence.

Book a call

Sample deliverables

Reports written and published. Fully downloadable.

📄

Viasat KA-SAT Audit

Technical analysis of the February 24, 2022 cyberattack. AcidRain, GRU, wind farm impact. 26 pages.

Download →

📊

Cybersecurity budgets

International comparison France / Europe / USA. Incidents 2024-2026 and roadmap. 42 pages.

Download →

🔍

Meta investigation

Systemic flaws, Messenger phishing and platform liability. 10 pages.

Download →

Typical results

+24 pts
Average security score / 100
3 P0
Critical flaws discovered on average
200+ Mo
Sensitive exposed data identified
< 15 min
To scrape a full catalog

Need evidence before deciding?

I've conducted audits on institutional sites, e-commerce, SaaS, notary offices and local authorities. Scores, vulnerabilities, findings — all anonymized and factual.

See completed audits

The process

Step 1
Initial contact and scoping
30 minutes free. Definition of scope, exclusions and test credentials if applicable.
Step 2
Technical audit
From passive reconnaissance to active tests. 11 phases following OWASP WSTG v4.2. No data modified or destroyed.
Step 3
Report and remediation
Delivery of prioritized report (P0 to P3), management summary, correction plan with estimated effort. Re-audit available.