We find and close security holes in websites, servers and office IT for small and medium businesses: audit, plain-language report, remediation, re-test.
We do the work and hand you the result: closed security holes, a clean server, a report, ready-to-use documents. Our team uses its own experience and strong tooling, including Claude models, to find problems faster. Every finding is checked by a person before it reaches your report, and we fix what we find.
Cybersecurity services and what you get
1. Website and server security audit
We check the external perimeter, CMS and plugins, hosting panels, TLS and headers, DNS and email (SPF, DKIM, DMARC), access controls and MFA, backups.
You get: a written report: what we found, how dangerous it is, what to fix today, this month and later. It comes with a short plain-language version for the owner.
2. Web application and external perimeter pentest
We run it only with the written permission of the system owner, with agreed targets and a time window.
You get: a report with reproducible findings and evidence, a remediation plan and a free re-test of the fixes within the same agreed scope.
3. Post-breach analysis and cleanup (incident response)
We look for malicious code and webshells, find out how the attackers got in and what leaked, close the entry point, restore operations and prepare a report.
You get: a clean website or server, the entry point closed, passwords and keys changed, a backup verified by a test restore, and a report: how they got in, what was affected, what was done.
4. Hardening and remediation
We fix what we find ourselves: updates, server configuration, permissions, MFA, backups with a verified restore, monitoring.
You get: a completed checklist of measures, a verified restore from backup, MFA enabled and alerts configured.
5. Preparation for ISO/IEC 27001 and CyberSecure Canada
Policies, risk register, SoA, internal audit. We work according to our own ISMS based on ISO/IEC 27001:2022.
You get: a document package (policies, risk register, SoA), a completed internal audit and a list of what is left before the certification audit.
Describe what needs to be checked or fixed. We will agree on the scope and send a fixed quote.
How we work
- A short call or a request through the form: we agree on what to check.
- Written permission and a scope letter before any test: goals, dates, contacts, what is off-limits. Work starts after the letter is signed.
- Audit, then a plain-language report with a technical report as an appendix.
- We fix the issues ourselves or together with your contractor.
- Re-test: we confirm that the findings are closed.
Cost
Fixed quote once the scope is agreed.
Who performs the work
Cybersecurity work is performed by INNOVA CONSULT LTD., Corporation Number 1522612, Ottawa, Ontario (Corporations Canada). We use tools and AI models within their rules, and we work with client data under a non-disclosure agreement.
INNOVA CONSULT LTD has been approved for Anthropic's Cyber Verification Program (CVP), which lets verified organizations use Claude models for defensive cybersecurity work.

DUNS Number: 68-606-2061
NCAGE Number: A3G3J