I bought a security audit

For customers who bought LeakTrace Scope (security audit). Covers the full path from audit delivery through every finding closed, with the Continuous Monitoring decision inline at the point it comes up.

Last updated 2026-05-11 Journeys
SECURITY · LEAKTRACE SCOPE AUDIT · OPTIONAL UPSELLS: MONITORING, IMPLEMENTATION

The Security customer journey end-to-end, from LeakTrace Scope purchase through every finding closed, with the Continuous Monitoring decision inline where it comes up.

1 · Purchase 2 · Setup 3 · Action 4 · Resolution
1
Now · ~60 seconds

Scope purchase

Stripe Checkout completes the order. North American billing supported, with CAD or USD pricing depending on the card issued. Payment confirmation arrives within a minute.

What's included in Scope →
2
Same day, usually within hours

Confirmation and audit scan

You receive an intake email within a minute confirming payment. Our scan runs in the background — checking roughly 10 sources for credential exposure, breach databases, paste sites, domain impersonation, and infrastructure tied to your company. No action required on your side.

3
When scan finishes

Audit Ready notification

Subject: "Your forensic audit for [your company] is complete." The email contains a permanent link to your audit dashboard — bookmark it. No password required.

Find your audit report →
4
Whenever you're ready

Findings review

Findings are grouped by severity (Critical, High, Medium, Low). Each finding has a plain-English description and concrete remediation steps embedded inline. This is where you assess which items you can handle internally and which require specialist support.

Read findings and action items →
5
Decision point

Remediation path selection (DIY or Implementation)

Two paths and you can mix them per-finding:

  • DIY — follow the remediation steps inside each finding yourself (or hand them to your IT person). Best for simple things: rotating a password, enabling MFA, updating a DNS record.
  • Work them yourself. Every finding in your dashboard carries the exact change that closes it, with the command to verify it afterwards. Mark it fixed and we re-check it for you. If you have an IT provider, use Forward to IT to send them the finding, the fix and the reproduction step in one email.
6
However long the fix takes

Remediation is performed

Whichever path you chose, the actual remediation happens here — you, your IT, or our contractor implements each change. No need to declare in advance which findings you will handle yourself versus which you will outsource. You can decide per-finding as you go.

7
As each fix is made

Mark fixed and reverification

Click "I've done this" on a finding once it's fixed, then click Reverify. We re-check the same source the finding came from. Status flips to Resolved (gone), Mitigated (historical record, credential rotated), or Still present with a note on what remains. Repeat per finding.

Reverify a finding after you fix it →
8
When findings are closed

Next steps

From here most customers do two things: work through the findings in the dashboard, each of which carries the change that closes it, and activate Continuous Monitoring so new exposures are caught as they appear rather than at the next audit.

Activate Monitoring →  

Other things you can do anytime

Features available throughout the audit lifecycle. Not steps you have to take in order — use them whenever you need to.

Download PDF reports

Three formats: Executive summary (leadership), Technical report (IT / your auditor), Compliance evidence package (PIPEDA / HIPAA / PCI / insurance questionnaires). Available from the moment the audit is delivered.

Download PDF reports →

Share evidence with an outside reviewer

Time-limited read-only link for your insurance broker, CPA, SOC 2 / ISO auditor, or enterprise client's vendor-security team. Most useful when an outside party asks for proof of your security review (insurance renewals, compliance audits, vendor questionnaires). Different from Implementation — this is for external parties, not our contractor.

Share evidence with a reviewer →

Export the compliance evidence package

One bundled archive containing the technical report, severity breakdown, evidence per finding, and an attestation cover sheet — formatted for regulators and insurance underwriters.

Export the evidence package →
Did this answer your question? If not, the AI assistant in the bottom-right can help, or email [email protected].