Websites & Web Apps
Exposed data, weak authentication, injection, missing security headers, and misconfigurations.
Security Audits
A senior-led, non-destructive audit of your websites, servers, network, email, and accounts — with a clear, prioritized report and a plan to fix what matters. Start free.
Source: Verizon 2025 Data Breach Investigations Report (DBIR).
Sound familiar?
If you nodded at even one — start with a free Security Health Check.
What we check
Exposed data, weak authentication, injection, missing security headers, and misconfigurations.
Patch levels, hardening, exposed services, and configuration across on-prem and cloud servers.
Firewall rules, segmentation, VPN, and Wi-Fi — reviewed for gaps attackers look for.
M365 / Workspace security posture, permissions, sharing, and admin configuration.
SPF, DKIM, DMARC, MFA coverage, credential hygiene, and account access.
Whether backups exist, are secured, and can actually be restored when it matters.
How it works
A no-cost health check first — then only go as far as your risk requires.
Free
Same week
A senior engineer reviews your setup and runs automated checks, then gives you a red / yellow / green snapshot of where you stand — no commitment.
from $1,500 CAD
3–5 days
A thorough, non-destructive audit of your websites, servers, network, email, and accounts — with a clear, prioritized report. Credited toward remediation.
from $6,000 CAD
1–3 weeks
We don’t just find the holes — we close them: patching, security headers, MFA, backups, monitoring, and access clean-up.
from $2,500 CAD / mo
Monthly
Security isn’t a one-time project. Continuous review, patching, and fractional security support so you stay protected as you grow.
Prices in CAD. The audit is credited toward remediation — the health check and audit pay for themselves.
Why IT-TECH
This is our craft, not a checkbox. Our own systems ship locked down (HSTS, CSP, MFA) — we hold yours to the same standard.
Authorized, read-first testing that won’t disrupt your business — no reckless “break it to prove it”.
Not a 90-page scanner dump. A clear, prioritized report a human can read — and a fixed-scope plan to fix it.
NDA-backed, least-privilege access, run by senior engineers with 15+ years — your data and findings stay yours.
Vibe-coded apps have their own security pitfalls — see our dedicated Rescue Engineering service.
FAQ
No. Our audits are authorized and non-destructive: we review configuration, access, and exposure without disruptive or damaging testing. We don’t take systems down to prove a point.
A clear, prioritized findings report (by severity) with plain-language explanations and a fixed-scope remediation plan — the same format behind our own hardened stack. Not a raw scanner dump.
The Security Health Check is free. A full Security Audit starts at $1,500 CAD and is credited toward any remediation. Fixes are quoted as fixed scope after the audit.
The Health Check happens the same week. A full audit typically takes 3–5 business days; remediation runs 1–3 weeks depending on findings.
Yes — we work under NDA on request, use least-privilege access, and your systems, data, and findings remain entirely yours.
Both options. We can remediate and harden directly, or hand your team a clear plan to do it — your call.
Free Security Health Check
Tell us what you run — website, servers, email, cloud. A senior engineer reviews it and sends back a clear risk snapshot. No cost, no obligation.
Tip: tell us your website, what servers/cloud you use (e.g. Microsoft 365, Google Workspace, AWS), and anything you’re worried about.
🔒 NDA on request · non-destructive · reply within 1 business day
We value our partnerships and showcase the success we played a role in:

IT-TECH successfully launched our new website, incorporating all our requested features and quickly responding to feedback.

IT-TECH has been instrumental in launching and supporting our websites, including cadrail.ca, cadrailfleetservices.ca, and the redesign of primerailway.com.

IT-TECH has been invaluable in launching the AppliedLMS MVP. Their ongoing support and responsiveness, has been crucial to the project’s continued progress.