Founder-led · AI-assisted security lab

Find the leak.
Fix the risk.

Probe5 combines purpose-built automation with human-directed security judgment. Start with one passive finding free, then choose a focused surface, authorization, or business-logic audit with evidence your developer can act on.

Authorized scopeEvidence-ledSafe disclosure
PASSIVE PRE-SCANFREE

Check one public website.

No login, no attack payloads, and no form submissions. Enter a homepage or public page you are authorized to review.

01Layered security analysis02Verified authorization03Developer-ready fixes04Advanced scopes reviewed individually

The Probe5 standard

Purpose-built automation. Human-directed judgment.

Probe5 is a focused, founder-operated security lab with AI-assisted analysis. Automation handles repeatable coverage. Advanced engagements are scoped around your roles, workflows, and expected controls before authorized testing begins.

01 / AUTHORIZE

Prove the scope.

Ownership verification, staging boundaries, synthetic data, and explicit test rules come before deeper testing.

02 / ANALYZE

Test the control.

Coverage is organized around real security controls instead of a noisy list of generic scanner alerts.

03 / REVIEW

Challenge the evidence.

Findings are separated from indicators, prioritized by impact, and bounded by what the evidence actually proves.

04 / REMEDIATE

Make the fix useful.

Customers receive the affected control, severity, impact, remediation, and retest criteria—not a reusable attack recipe.

Coverage

Useful checks. Honest labels.

Probe5 separates confirmed configuration problems from potential application-layer risks. It never calls a suspicion a proven exploit.

01ACTIVE

XSS reflection

Ownership-verified audits use inert canary markers to identify input that is returned without safe encoding.

02ACTIVE

SQL error behavior

Safe GET-only probes look for database error disclosures and abnormal server responses—never data extraction.

03PASSIVE

HTTPS & headers

TLS use, HSTS, CSP, clickjacking protection, MIME sniffing, referrer policy, and permissions policy.

04PASSIVE

Cookies & forms

Secure, HttpOnly, SameSite, mixed-content, password transport, and cross-origin form-action checks.

05PASSIVE

Exposure clues

Server banners, framework disclosures, generator tags, query surfaces, and missing browser defenses.

06REPORT

Fix plan

Every result includes evidence, severity, and a plain-language remediation step your developer can use.

The safe method

Active testing starts only after you prove control.

Buyers place a one-time verification token on the audited domain. Probe5 then limits tests to public, same-origin GET pages and a small number of query parameters. It does not submit forms, log in, brute-force, extract records, or alter data.

See the $5 report
  1. 01

    Enter the website

    Start with a passive, non-invasive check and see one verified issue free.

  2. 02

    Verify ownership

    Add a text file or meta tag containing the unique token shown in the customer report.

  3. 03

    Run the protected probes

    Probe5 checks safe reflection and SQL-error signals, then produces prioritized remediation.

Authenticated applications

KYC, MFA, authz, and logic need a deeper test.

These controls cannot be judged from a public page. Probe5 scopes them separately after website ownership is verified, using a customer-controlled staging environment, synthetic identities, and purpose-built test accounts. Customers can upload OpenAPI, Swagger, or Postman definitions to generate a sanitized, risk-based application map before testing begins.

KYCSTAGING

KYC workflow enforcement

Server-side approval, verification-state integrity, provider-result trust, and synthetic identity safeguards.

  • Server-side KYC approval enforcement
  • Verification sequence integrity
  • Provider-result authenticity and freshness
MFASTAGING

MFA enforcement & recovery

Second-factor enforcement, secure lifecycle changes, recovery equivalence, retry controls, and session revocation.

  • Second-factor enforcement on protected actions
  • Enrollment, replacement, and removal protections
  • Recovery-path security equivalence
AUTHZSTAGING

Authorization boundaries

Cross-role and cross-account access checks using customer-created test users and synthetic records.

  • Object and tenant isolation
  • Role and privilege enforcement
  • Server-side authorization enforcement
LOGICSTAGING

Business-logic controls

State transitions, replay, duplicate actions, limits, and workflow invariants defined by the customer.

  • Workflow state integrity
  • Repeat-action and idempotency controls
  • Limit and prerequisite enforcement
RequiredVerified owner · staging/sandbox · synthetic data

No real identity documents, biometric-bypass research, stolen credentials, OTP interception, uncontrolled brute force, or tests against a third-party KYC provider. After verification, synthetic staging test accounts can be placed in a 24-hour encrypted vault inside the customer report.

Checkout setup pending
Safe disclosure

Reports identify the affected control, observed impact, severity, fix, and retest criteria. They do not publish bypass sequences, payloads, OTP or recovery details, provider secrets, or reusable exploitation steps.

Honest scope

Three audits. Three different promises.

The $5 audit covers the public surface. Authz and Logic require verified ownership, staging access, synthetic data, and a defined test plan. Probe5 does not sell a surface scan as a penetration test.

Surface AuditAUTOMATED
$5one time

XSS/SQLi indicators, TLS, headers, cookies, CORS, forms, exposed software, and session-security signals.

  • XSS and SQLi indicators
  • TLS, headers, cookies, and CORS
  • Forms and exposed-software signals
  • Session-security signals
Checkout setup pendingSecure checkout by Digistore24. Applicable tax may be added.
Authz AuditSTAGING
$49one time

Customer-supplied test accounts, role-boundary comparisons, unauthorized resource checks, and session enforcement.

  • OpenAPI, Swagger, or Postman application map
  • Customer-supplied test accounts
  • Role-boundary comparisons
  • Unauthorized resource checks
  • Session enforcement
Checkout setup pendingSecure checkout by Digistore24. Applicable tax may be added.
Logic AuditSTAGING
$99one time

Defined workflows, state-transition errors, price/quantity invariants, replay, and duplicate-action testing on staging.

  • Schema-driven endpoint and workflow map
  • Defined staging workflows
  • State-transition errors
  • Price and quantity invariants
  • Replay and duplicate-action testing
Checkout setup pendingSecure checkout by Digistore24. Applicable tax may be added.
Scope boundary

MFA and session enforcement are assessed under Authz. KYC workflow enforcement failures are assessed under Logic. Findings are evidence-backed but are not a certification or guarantee of security.

Plain limits

This is a focused surface audit—not a penetration test.

What it can find

Missing defenses, unsafe transport, cookie mistakes, risky form behavior, exposed versions, raw input reflection, and database error indicators on public GET surfaces.

What it cannot prove

Complete absence of vulnerabilities, authenticated-area safety, KYC or MFA enforcement weaknesses, authorization or business-logic flaws, or exploitability of every potential XSS or SQLi signal. Those require the separately scoped staging assessment above.

When to hire a professional

Use a qualified penetration tester for regulated data, payment flows, authenticated applications, compliance certification, or confirmation of a high-severity signal.