If someone got into your store tonight, how long before you noticed? Most founders answer that and realise they have no idea.
Ten questions, two minutes, no signup. You get a risk score and the specific controls that scored worst — drawn from the same checklist we use in paid assessments.
What platform does your store run on? This changes the wording of the questions and the gaps we look for.
This is a self-assessment, not an audit. The full 48-hour assessment verifies every answer against your actual store, scores 22 controls instead of 10, and returns a written report with a prioritised 30-day fix plan.
Nothing you enter is sent anywhere. The score is calculated in your browser and discarded when you close the tab.
We walk through the checklist with you — 22 controls covering access, payments, apps, devices, backups and breach response. Nothing installed, no code access required.
Each control is verified against your live setup and scored: not in place, partially in place, or fully in place. Every gap gets a risk level and a real-world consequence.
Within 48 hours you get a written report with your score, the priority risks in order, and a 30-day plan setting out exactly what to fix first.
Written for the person who signs the cheque, not for an IT department. If a sentence needs you to know what NIST is, it didn't make the cut.
The Cybersecurity Framework is the standard large enterprises are measured against. We assess against the same six functions, then drop the vocabulary.
Whether anyone actually owns security, and whether your contractors are contractually obliged to hand access back.
Every app, integration, device and login that touches your store — including the ones nobody remembers approving.
The largest section: MFA, shared logins, offboarding, payout settings, API keys, app permissions, device encryption.
Whether anything alerts you when an admin does something unusual, or a customer list is exported at three in the morning.
Whether there's a written plan, who gets called, and in what order — decided before the day you need it.
Backups that exist, are isolated, and have actually been restored from — not just assumed to be working.
No. The assessment is evidence-based rather than intrusive — we ask you to confirm settings and show us specific screens. We never ask for your admin password, and we install nothing.
Shopify, WooCommerce and the rest secure their own infrastructure. They don't secure how you configure it: who holds admin, which agency still has access from a project two years ago, whether a payout account change requires re-authentication. That layer is yours, and it's where almost every gap we find lives.
Most attacks aren't targeted. They're automated sweeps for known-weak configurations, and a small store with an unused developer account open looks identical to a large one. Recovering from a breach typically runs into five figures in legal fees, lost customers and downtime.
That's the entire design goal. Plain-English finding, plain-English consequence, plain-English fix. The technical framework reference sits in small print at the end of each item, for the day an enterprise customer's procurement team asks.
You get a 30-day plan and can implement it yourself — most findings are configuration changes rather than purchases. If you'd rather be walked through it, that's a call.
Start with the free two-minute check. If it turns up anything worth discussing, we'll walk you through a 30-day fix plan on a short call.