Free, no obligation

See what the internet already knows about your business

A free attack-surface scan of your domain. Passive, no disruption, report emailed to you.

We scan the domain in your email address, that's how we know it's yours. Your report usually arrives within a day.

Ransomware in South Africa

R18 million
median ransomware demand in South Africa
Sophos, State of Ransomware 2025

R24 million
average cost to recover from an attack
Sophos, State of Ransomware 2025

71%
of South African ransomware victims paid the demand
Sophos, State of Ransomware 2025

A free security scan shows what the internet exposes about your company before attackers use it. We scan your internet-facing systems from the outside, the same way an attacker sees them, and email you a plain-language report. It costs nothing to request and nothing touches your systems.

Looking for a free security scan in South Africa? This one covers any company domain, local or international, as long as the request comes from an email address at that domain.

What does the free security scan cover?

The scan looks at your public, external presence only, from the outside. That is deliberate: it is the exact view an attacker starts with, and it needs no access to your network, no software installed, and no disruption to your business.

  • Your website’s security configuration and software versions
  • Email security setup: SPF, DKIM, DMARC, the settings that stop email spoofing
  • SSL/TLS certificate quality
  • Open ports and exposed services on your public addresses
  • Subdomains, including forgotten test and old systems
  • Known vulnerabilities in anything public-facing
  • Whether your domain shows up in leaked credentials and public code repositories
  • Your domain’s reputation on threat-intelligence feeds

What are the limits of a free security scan?

A free scan is external and passive. It reads what is publicly visible and touches nothing. It cannot see inside your network, cannot tell you whether any of the exposure has ever been used, and is not a penetration test. It answers the outside-in question: what can an attacker see and reach today. The inside-out question is a different job, and if your report points that way, we will say so.

No scan findings are shown on this website. Your report goes to your email, to you.

What do you get in the report?

A written report, emailed to you, yours to keep.

  • Three scores: Severity, Attack Surface, Operational Risk. Plain language, what it means for your business, not just your IT team.
  • A benchmark against the SA Top 50, so the numbers mean something.
  • Every finding explained: what it is, why it matters, and what to do about it, ranked by priority.
  • A business-impact section: risk translated into money terms, anchored to your turnover.

Who is Hayshack?

Hayshack is a cybersecurity company. We do security work for businesses from assessments to ongoing managed security, and we build security into the systems we run. The free scan is how most of our customers meet us. If your report shows something you want help with, that conversation starts on your terms.

Frequently asked questions

Is the security scan really free?

Yes. There is no charge and no card details. You get the report whether or not you ever speak to us again. We offer it because most companies have never seen their external exposure, and the ones who need help usually start here. We may call to walk you through your report.

Will the scan affect my website or systems?

No. The scan is passive: it reads publicly available information from the outside. Nothing is sent to your systems, nothing is installed, nothing changes. Your website, email, and network carry on as normal while it runs.

What do you need from me to run the scan?

Your name, your mobile number, and a work email address. We scan the domain in your email address, which confirms the request is authorised and the domain belongs to your company. No server access, no logins, no software to install.

How long does the free scan take?

The request takes about a minute to submit. Your report usually arrives within a day, emailed back to you. If anything in your report is urgent, we say so at the top of it, not buried in the detail.

What happens after I get the report?

The report is yours to keep and act on, including handing it to your own IT team. We may call to walk you through it. If you want help fixing what it shows, that is a separate conversation, on your terms.

Can you scan any company domain?

Any South African or international company domain, provided the request comes from an email address at that domain. We cannot scan government or military systems, and we will say so if a domain falls outside what we can responsibly scan.

Ready when you are: Request your free scan