What is included in a cybersecurity audit?
The agreed criteria, control areas, platform boundaries, evidence period, procedures and deliverables define the work. Typical areas include governance, identity, cloud, change, recovery and suppliers.
Does an audit include exploitation?
Active scanning and exploitation are not assumed. They need a separate authorised testing scope and safeguards. Read-only evidence review can identify control gaps without proving an exploit path.
Will you certify us?
This site offers control assessment and readiness work. Certification, statutory assurance and formal attestations have separate requirements and are not promised by this service.
Can you sign our NDA first?
Send your NDA for human review through the contact form or email sales@cybersecurityaudit.services. Uploading a document does not accept its terms or automatically sign it.
Can we attach an RFP?
Yes. The contact form and final brief step accept a PDF or DOCX up to 2 MiB. Documents go to the team, not the AI. Use a separate agreed channel for confidential audit evidence.
Can we review the brief before it is sent?
Yes. Review the draft, answer optional clarification questions and edit it. It is sent to Atlant Security only when you submit the contact step. There is no brief download or export control.
What does missing evidence mean?
It limits the conclusion. An assessor should distinguish an unavailable record from a confirmed control failure and explain the impact on the assessment.

