AuditaSample report
Get yours
Sample report — This is a redacted example for a fictional company. Your report will be specific to your domain and infrastructure.

Security Snapshot Report

Acme Digital Agency

acmedigital.io

Report date

March 28, 2026

Scope

External exposure review

Prepared by

Audita

Overall risk grade

C+

Medium-High Risk

Executive Summary

Acme Digital Agency has a moderate-to-high external risk exposure. Email authentication is partially configured, TLS is active but uses outdated protocols on some subdomains, and several services are unnecessarily exposed. These gaps could undermine client trust and create compliance friction.

3

Critical findings

4

Warnings

3

Passing checks

Domain & DNS Findings

Email authentication & DNS hygiene

SPF Record

Warning

Configured but overly permissive (~all instead of -all)

DKIM

Fail

Not configured for primary domain acmedigital.io

DMARC

Warning

Policy set to p=none — monitoring only, no enforcement

MX Records

Pass

Standard Google Workspace configuration

Dangling DNS

Fail

staging.acmedigital.io CNAME points to deprovisioned Heroku app

TLS / SSL Posture

Certificate & protocol review

acmedigital.ioPass

TLS 1.3, valid certificate, HSTS enabled

portal.acmedigital.ioWarning

TLS 1.2 only — certificate expires in 12 days

staging.acmedigital.ioFail

TLS 1.0 / 1.1 still accepted — vulnerable to downgrade attacks

Wildcard certificateWarning

*.acmedigital.io in use — increases blast radius if private key is compromised

Exposed Services & Misconfigurations

Publicly reachable services that should not be

SSH (port 22)

Critical

203.0.113.42

Password authentication enabled on production IP

Node.js dev server (port 3000)

High

staging.acmedigital.io

Development server publicly accessible

Elasticsearch (port 9200)

Critical

staging IP

Responding without authentication — data exfiltration risk

Environment file

Critical

staging.acmedigital.io/.env

Secrets, API keys, and database credentials exposed

Apache server-status

Medium

203.0.113.42/server-status

Internal server metrics publicly accessible

Prioritised Remediation Plan

Top 5 recommendations

Ordered by combined severity and ease of fix. Difficulty is rated from 1 (easy) to 3 (hard).

1

Rotate all secrets and remove exposed .env file

Credentials are publicly accessible — assume compromise. Rotate every secret referenced in the file, revoke API keys, and block direct file access.

Difficulty
Impactcritical
2

Close Elasticsearch port and disable SSH password auth

Unauthenticated Elasticsearch access allows data exfiltration. SSH password auth on a production IP invites brute-force attacks.

Difficulty
Impactcritical
3

Deploy DKIM and enforce DMARC to p=reject

Without DKIM and an enforced DMARC policy, attackers can spoof emails from your domain — damaging client trust and enabling phishing.

Difficulty
Impacthigh
4

Renew portal TLS certificate and disable TLS 1.0/1.1

An expired certificate will break the client portal. Legacy TLS versions are vulnerable to POODLE and BEAST attacks.

Difficulty
Impacthigh
5

Remove dangling staging DNS and decommission unused subdomains

A dangling CNAME is a subdomain takeover risk — an attacker could claim the Heroku endpoint and serve content on your domain.

Difficulty
Impactmedium
What to do next

Turn findings into fixes

This snapshot surfaces your most visible external risks. The next step is to address critical findings immediately, then work through the remediation plan. If you want a deeper review that includes internal controls, identity, access, and operational readiness — Audita’s full audit covers it all.

Step 1

Remediate critical items today — rotate secrets, close exposed ports, and block the .env file.

Step 2

Work through warnings over the next 30 days — deploy DKIM, enforce DMARC, and renew expiring certificates.

Step 3

Upgrade to the full Automated Security Audit for internal controls, identity review, and a 30/60/90 remediation roadmap.

This is a sample report for demonstration purposes. “Acme Digital Agency” is a fictional company. Actual reports are generated from live external checks against your real domain and infrastructure.
© 2026 Audita. All rights reserved.

Get your Security Snapshot — $299