Project audit: what it is and why it matters
Before we take your project on for support or start making changes, we run a technical audit. It is like a car inspection before a long trip: we need to know what is under the hood so we can make sure the machine will not break on the road.
What is an audit?
We access your servers and code in read-only mode. We do not change, break, or restart anything. We analyze the current state across 50+ parameters.
Why does this matter for you?
- Security: We find the "open doors" that could be used to attack your systems.
- Cost savings: We often find forgotten servers or inflated plans that you are still paying for.
- Speed: We identify why the site is slow and how to fix it.
- Clarity: You get a report in plain language: what is good, what is bad, and how much it costs to fix.
🔒 Security and NDA
We understand that access transfer requires trust.
- NDA (non-disclosure agreement): We sign an NDA before the work starts. Your data, code, and customer databases are legally protected.
- European law: We operate under EU jurisdiction (Poland) and strictly follow GDPR.
- Clean handover: After the audit (if we do not continue the work) we remove all access from our side.
📝 Checklist: what we need from you
For a proper audit we need the following access. If something is missing, that is fine — just let us know.
1. Server access (VPS / dedicated)
This is the most important one. We need administrator access to check the system settings.
- Server IP address: (for example,
123.45.67.89) - User: (usually
rootorubuntu) - SSH key or password:
- Port: (if it is not the default 22)
2. Code access (repository)
If you use Git, provide access to the repository.
- Platform: GitHub / GitLab / Bitbucket
- Invite account:
1it-audit(or your email) - If there is no Git: FTP/SFTP access (host, login, password)
3. Hosting provider and domain
We need this to check network, firewall, and DNS settings.
- Server control panel: (Hetzner Console, DigitalOcean, AWS)
- Domain / DNS management: (Cloudflare, GoDaddy, Namecheap)
4. Additional services (if any)
- Site admin panel (WordPress, admin panel)
- Database (if it is hosted separately)
🚀 How do I safely share passwords?
Never send passwords in plain text over Telegram, WhatsApp, or email. That is not safe.
Please use one of these methods:
Method 1. One-time note services (recommended)
This is the simplest and fastest way.
- Go to 1ty.me or Privnote.
- Paste all access details into the input field.
- Click "Create Link".
- Send us the link.
- How it works: As soon as we open the link, the note self-destructs. Nobody else can read it.
Method 2. Password managers
If you use 1Password, Bitwarden, or LastPass:
- Create a "Secure Note" or "Item".
- Use the "Share" feature.
- Send us the access link.
📊 What will you get in the end?
Within 1–3 business days we will give you a PDF report split into 3 zones:
- 🔴 Critical (Red): Problems that must be fixed immediately (risk of breach or data loss).
- 🟡 Important (Yellow): Recommendations to improve speed and stability.
- 🟢 Good (Green): Things that are already done well.
We will also prepare a roadmap with estimated time and cost for fixing the issues we find.