Secuvexa for United States

Website security for US small businesses

A free outside-in scan of your website, then manual audits, fixes and monitoring priced in US dollars. Clear reports you can hand to your developer, your insurer or a client who sent you a security questionnaire.

Need a person to test it? Request a website security audit

Who we help in the US

Most US small businesses do not have a security team, but they are still expected to protect customer data. We work with:

E-commerce and DTC brands
Online stores taking card payments, where a skimmed checkout or an outdated plugin can lead to chargebacks and card-brand scrutiny.
Tax preparers, mortgage brokers and other non-bank financial businesses
Firms covered by the FTC Safeguards Rule that need regular vulnerability assessments and evidence of them.
Medical and dental practices
Practices with patient forms and booking systems on their websites. HIPAA has its own Security Rule; our audit covers the website side and does not certify HIPAA compliance.
SaaS startups
Young software companies answering security questionnaires from larger customers.
Real estate and property management
Brokerages and managers handling tenant applications and wire instructions by email.
Agencies and freelancers
Web studios that want an independent check before launch or a hand-over.

Prices in USD

Set for the US market, not converted at today's exchange rate. Start free and pay only for the help you need.

Premium Report

$29

Every finding with evidence, step-by-step fixes and a PDF to share.

Scan first

Professional Audit

from$1,299

Web application and API testing, including login, roles and business logic.

Request a quote

Annual Monitoring

$299 / year

Weekly scans of one website and an email alert when your score drops.

Start monitoring

The website scan itself is free. Larger applications, APIs and VAPT are quoted after a short scoping call. Secuvexa Mobile, our Android anti-scam app, is currently available in India only.

Rules worth knowing in the US

There is no single US website security law, but several rules ask businesses to protect customer information. A careful summary:

FTC Safeguards Rule

Applies to many non-bank financial businesses, such as mortgage lenders and brokers, tax preparers, debt collectors and some investment advisers. It requires a written information security programme and, unless you use continuous monitoring, annual penetration testing and vulnerability assessments every six months. Since May 13, 2024, certain breaches affecting 500 or more consumers must be reported to the FTC within 30 days.

Source: FTC: Safeguards Rule, what your business needs to know

PCI DSS for card payments

If you accept cards, the PCI Data Security Standard applies. It includes quarterly external vulnerability scans by a PCI SSC Approved Scanning Vendor (ASV). Secuvexa is not an ASV, so our scan does not replace that requirement, but it often finds the issues that make ASV scans fail.

Source: PCI Security Standards Council: document library

This is general information, checked in October 2026, not legal advice. Secuvexa is not a certification body. For a compliance decision, speak to a qualified adviser in your jurisdiction.

Working with a team in India

Our team works on India Standard Time (UTC+5:30), which is 9.5 to 10.5 hours ahead of US Eastern time and 12.5 to 13.5 hours ahead of Pacific time, depending on daylight saving. We schedule calls in your morning, which is our evening, and agree testing windows that suit your traffic.

  1. Tell us what you have

    Send your website and what worries you through the contact form. We reply within one working day with questions or a quote in USD.

  2. Agree scope in writing

    An authorisation letter lists exactly which systems we may test, when, and how. Nothing starts without it.

  3. Test, report, retest

    You get a plain-English report with business impact and fixes. Once your developer fixes the issues, we check again.

How we work

No inflated claims. Here is exactly what you can expect when you scan with us or hire us.

  • Non-destructive by design

    The free scan makes ordinary web requests, like a browser. No password guessing, no exploits, no form submissions, and nothing on your website is changed.

  • Permission first

    You confirm you are authorised before every scan. Manual testing starts only after the scope and testing window are agreed in writing.

  • Plain-English reports

    Every finding says what we saw, why it matters to your business and what to change, so your developer can act on it the same day.

  • Careful with your data

    Reports sit behind private links that search engines do not index. Contact details such as phone numbers are encrypted at rest, and every page is served over HTTPS. Privacy policy

  • Transparent pricing, secure payments

    Prices are published in your currency before you buy. Payments are processed by Razorpay, so we never see or store your card details.

  • Open to scrutiny

    Found a weakness in our own systems? We publish a responsible disclosure policy and a security.txt contact.

Questions from US businesses

Can your work help with the FTC Safeguards Rule?

Yes, for the testing part. Our scan and manual audit give you a dated vulnerability assessment with findings and fixes, which you can keep as evidence. The rule also requires other things, such as a qualified individual and a written security programme, which an audit alone does not cover.

Are you a PCI Approved Scanning Vendor?

No. If you need quarterly ASV scans for PCI DSS, use a listed ASV. We can test your website and help you fix problems before the ASV scan.

Are your prices in US dollars?

Yes. Prices on this page are in USD. Payments are processed by Razorpay. If online card payment in USD is not yet available for your order, we send you an invoice instead.

Is it a problem that your team is in India?

We work remotely and agree scope, testing windows and data handling in writing before any manual testing. If your contract requires testers to be in the US, tell us early and we will say honestly whether we can meet it.

Is the free scan safe to run on my live website?

Yes. It makes a small number of ordinary web requests and never tries to log in, submit forms or exploit anything.

Check your website now

Free, non-destructive and ready in about 30 seconds. Every finding comes with a plain-English fix.