CLEAR SCOPESECURITY

EXTERNAL SECURITY ASSESSMENTS

Understand Your Exposure.
Know Your Next Move.

Clear answers about the security of your internet-facing systems. Evidence you can understand. Recommendations you can act on.

Discuss your security needs

Defined scope. Written permission. Human-reviewed findings.

Preparing for launch

We are completing our legal and technical readiness work. Client testing is not yet available. Initial inquiries are welcome; engagement dates will be confirmed once readiness checks are complete.

01 / SERVICES

Security Testing With
a Defined Purpose.

Start with the systems your business exposes to the internet. Agree on the boundaries, examine the evidence, and decide what needs attention.

INITIAL SERVICE

External security assessments

A scoped assessment examines the internet-facing systems you authorize us to test. Depending on the engagement, this may include exposed services, security configurations, web applications, APIs and approved validation of potential vulnerabilities.

Assessments can be conducted remotely or on-site, depending on your needs and the agreed scope. Location, travel, access requirements, methods, restrictions and the testing window are agreed in writing before work begins.

Explore our process

What you receive

  • An executive summary and reviewed technical findings
  • Supporting evidence and potential business impact
  • Prioritized remediation recommendations
  • A findings discussion with the owner
  • Retesting when included in your agreement

Remediation is separately scoped and authorized when offered. Assessments cover the agreed scope and testing period and cannot guarantee that every vulnerability will be found.

02 / OUR PROCESS

Clear Boundaries.
Accountable Decisions.

Every engagement begins with permission and ends with a conversation. Automation stays within the authority you grant.

01

Understand your needs

Discuss your concerns, systems, objectives and operational restrictions.

02

Define the scope

Document approved systems, activities, testing windows and emergency contacts. Confirm required third-party permissions.

03

Assess and review

Test within approved boundaries. Evaluate evidence and review findings before they reach your report.

04

Discuss next steps

Walk through the results, explain priorities, and discuss remediation and any agreed retesting.

Discovery does not expand permission.

A connected or newly discovered system remains outside the testing scope unless it is explicitly authorized.

03 / ABOUT CLEAR SCOPE

AI-First.
Human-Accountable.

Clear Scope Security LLC was founded by Peter Nulph to help businesses understand their external security exposure through remote and on-site assessments.

We are building an AI-first assessment workflow that combines security tools and AI agents for authorized testing, evidence collection, analysis and documentation.

Peter establishes authorization and scope, reviews and confirms findings and recommendations, approves the report, and personally discusses results with you.

AI does not create testing permission, expand scope or automatically remediate systems. External AI processing of client information will be governed by the engagement’s agreed data-handling terms.

Peter NulphFounder · Clear Scope Security LLC

04 / START A CONVERSATION

What Would You
Like to Understand?

Tell us what you want assessed and what prompted your inquiry. That is the starting point for defining a useful scope.

Email Clear Scope Security

contact@clearscopesec.com

Prefer to write directly? Email us with a brief description of your needs. Or use this form to prepare a message in your email app.

Do not include passwords, credentials, customer records or sensitive information. An inquiry does not authorize testing.

Your email app opens with a draft. Review it and press Send there. This website does not submit or store your inquiry.

A FEW COMMON QUESTIONS

Will testing change my systems?

Some testing techniques can affect system behavior or availability. We agree on permitted methods, operational restrictions and emergency stop contacts before testing. Assessments do not include automatic remediation; any remediation work requires separate scope and authorization.

Do I need to know exactly what to test?

An initial conversation helps identify objectives and candidate systems. Ownership, testing authority and any third-party permissions must be confirmed before an engagement can begin.

Who reviews the findings?

Peter reviews and confirms the findings and recommendations, approves the client report, and discusses the results with you.