Find out who actually controls your website.
Five working days. A written map of all eight control points — domain, DNS, hosting, repository, database, deploy pipeline, API keys, admin accounts — plus what is at risk and what to reclaim first.
RM5,000 fixed, excl. SST · credited in full against an eligible fixed-scope or monthly improvement engagement · no sales call unless you ask
Illustrative. Amber marks a control point held by someone else — the one we would tell you to reclaim first.
8
control points traced to a named account holder
5 days
from access granted to PDF delivered
RM5,000
fixed — credited in full against what comes next
Why this exists
Most owners cannot answer three of the eight questions.
Not through carelessness. The answers live in accounts nobody has opened since launch, often under an email belonging to someone who has moved on.
Risk 01
The domain is in their name
The most common trap in this market. Agencies register the client's domain under their own account, then refuse to transfer it. You lose your address and your email, not just the site.
Risk 02
Nobody can export the database
Your customer records, orders and form submissions live there. If you cannot get a copy today, you are the data controller for data you do not hold — a PDPA problem as much as a technical one.
Risk 03
Licences on someone else's account
Plugin and theme licences bought on a vendor's account stop receiving security updates the day you part ways. Unlicensed ones never received them at all.
What you actually get
A PDF you could hand to a different vendor.
It is not a sales document. Everything in it is useful whether or not you ever work with us — which is precisely why it is paid work.
The ownership map
All eight control points, who holds each, under which account and email, at which provider. Green where it is yours, amber where it is not. This is the page people photograph and send to their business partner.
Risk ranking, in order
What breaks if each amber item stays where it is, ordered by how much damage it does and how fast. Not a severity score out of ten — a sentence you can act on.
Recovery steps and real cost
For each item you do not control: what has to happen to reclaim it, whether it needs the current vendor's cooperation, and what it costs in time and money. Including the ones you can do yourself in twenty minutes.
Technical condition
CMS and dependency versions against known vulnerabilities, SSL expiry, whether a backup exists and whether a restore has ever been tested, licence status of every paid component.
What it would cost to look after
A written quote for care or a build, if either makes sense. If neither does, we say so — that has happened, and we would rather say it than sell you something.
How it runs
Five days, and you barely appear in them.
No workshops, no discovery call, no questionnaire. Read-only access on day one, a PDF on day five.
Day 1
Read-only access
You grant what you can. Where you cannot, that is itself a finding — someone else holds the key.
Day 2
Trace the eight
Registrar, DNS, hosting owner, repository, database, pipeline, keys, admin accounts. Who, under which email.
Day 3
Technical condition
Versions against known vulnerabilities, backups and whether a restore works, SSL, licences.
Day 4
Risk and recovery
What breaks, in what order, and what reclaiming each item actually takes.
Day 5
The PDF
By email and WhatsApp. Yours to keep, and to take elsewhere if you prefer.
The number
RM5,000
fixed, excluding SST · five working days
- ✓Credited in full against an eligible fixed-scope project or monthly improvement engagement
- ✓No sales call required at any point
- ✓You keep the map whether or not you continue
- ✓Paid up front by card or FPX — no invoicing terms to negotiate
Included
- ✓All eight control points traced and documented
- ✓Technical condition and vulnerability check
- ✓Risk ranking with recovery steps and costs
- ✓A written quote for care or a build, if either fits
- ✓One follow-up call to walk through it, if you want one
Not included
- —Any fixing — the review documents, it does not repair
- —Contacting your current vendor on your behalf
- —Legal action or formal dispute support
- —A design critique or SEO audit — different job, ask separately
Questions
Why charge when everyone else audits for free?
A free audit is a sales call with a document attached, written to make the problem look big. This is five days of real work that stands alone — you can hand it to a different vendor and it still does its job. Charging for it means we are not incentivised to inflate what we find.
What if you find nothing wrong?
Then you have written confirmation that you control your own website, which almost nobody can produce. It has happened. We say so plainly rather than manufacturing a problem to justify the fee.
Do you need my passwords?
No. Read-only access wherever possible, and secure credential sharing only if work is agreed afterwards. Never send passwords or API keys by email or WhatsApp — if you do, we delete the message and tell you.
Will my current vendor find out?
Nothing we do requires telling them, and nothing in the review is adversarial. It is a record of who holds what. Most vendors are not being malicious, just untidy.
Find out what you actually own.
RM5,000 fixed, excluding SST, with a decision-ready report and 30-day action plan.