Prove the scope.
Ownership verification, staging boundaries, synthetic data, and explicit test rules come before deeper testing.
Founder-led · AI-assisted security lab
Probe5 combines purpose-built automation with human-directed security judgment. Start with one passive finding free, then choose a focused surface, authorization, or business-logic audit with evidence your developer can act on.
No login, no attack payloads, and no form submissions. Enter a homepage or public page you are authorized to review.
The Probe5 standard
Probe5 is a focused, founder-operated security lab with AI-assisted analysis. Automation handles repeatable coverage. Advanced engagements are scoped around your roles, workflows, and expected controls before authorized testing begins.
Ownership verification, staging boundaries, synthetic data, and explicit test rules come before deeper testing.
Coverage is organized around real security controls instead of a noisy list of generic scanner alerts.
Findings are separated from indicators, prioritized by impact, and bounded by what the evidence actually proves.
Customers receive the affected control, severity, impact, remediation, and retest criteria—not a reusable attack recipe.
Coverage
Probe5 separates confirmed configuration problems from potential application-layer risks. It never calls a suspicion a proven exploit.
Ownership-verified audits use inert canary markers to identify input that is returned without safe encoding.
Safe GET-only probes look for database error disclosures and abnormal server responses—never data extraction.
TLS use, HSTS, CSP, clickjacking protection, MIME sniffing, referrer policy, and permissions policy.
Secure, HttpOnly, SameSite, mixed-content, password transport, and cross-origin form-action checks.
Server banners, framework disclosures, generator tags, query surfaces, and missing browser defenses.
Every result includes evidence, severity, and a plain-language remediation step your developer can use.
The safe method
Buyers place a one-time verification token on the audited domain. Probe5 then limits tests to public, same-origin GET pages and a small number of query parameters. It does not submit forms, log in, brute-force, extract records, or alter data.
See the $5 reportStart with a passive, non-invasive check and see one verified issue free.
Add a text file or meta tag containing the unique token shown in the customer report.
Probe5 checks safe reflection and SQL-error signals, then produces prioritized remediation.
Authenticated applications
These controls cannot be judged from a public page. Probe5 scopes them separately after website ownership is verified, using a customer-controlled staging environment, synthetic identities, and purpose-built test accounts. Customers can upload OpenAPI, Swagger, or Postman definitions to generate a sanitized, risk-based application map before testing begins.
Server-side approval, verification-state integrity, provider-result trust, and synthetic identity safeguards.
Second-factor enforcement, secure lifecycle changes, recovery equivalence, retry controls, and session revocation.
Cross-role and cross-account access checks using customer-created test users and synthetic records.
State transitions, replay, duplicate actions, limits, and workflow invariants defined by the customer.
No real identity documents, biometric-bypass research, stolen credentials, OTP interception, uncontrolled brute force, or tests against a third-party KYC provider. After verification, synthetic staging test accounts can be placed in a 24-hour encrypted vault inside the customer report.
Checkout setup pendingReports identify the affected control, observed impact, severity, fix, and retest criteria. They do not publish bypass sequences, payloads, OTP or recovery details, provider secrets, or reusable exploitation steps.
Honest scope
The $5 audit covers the public surface. Authz and Logic require verified ownership, staging access, synthetic data, and a defined test plan. Probe5 does not sell a surface scan as a penetration test.
XSS/SQLi indicators, TLS, headers, cookies, CORS, forms, exposed software, and session-security signals.
Customer-supplied test accounts, role-boundary comparisons, unauthorized resource checks, and session enforcement.
Defined workflows, state-transition errors, price/quantity invariants, replay, and duplicate-action testing on staging.
MFA and session enforcement are assessed under Authz. KYC workflow enforcement failures are assessed under Logic. Findings are evidence-backed but are not a certification or guarantee of security.
Plain limits
Missing defenses, unsafe transport, cookie mistakes, risky form behavior, exposed versions, raw input reflection, and database error indicators on public GET surfaces.
Complete absence of vulnerabilities, authenticated-area safety, KYC or MFA enforcement weaknesses, authorization or business-logic flaws, or exploitability of every potential XSS or SQLi signal. Those require the separately scoped staging assessment above.
Use a qualified penetration tester for regulated data, payment flows, authenticated applications, compliance certification, or confirmation of a high-severity signal.