Is it really free?
Yes. Six months, the full package, with no card taken at any point. Because we never hold a card, there is no mechanism for us to charge you. At six months we'll ask whether you want to carry on at £149.95 a month. If you don't reply, it simply stops.
Do you need access to our systems or passwords?
No. Everything in the free package is done from the outside — the same view an attacker has of you. We never ask for admin access, and you should be suspicious of anyone who does over email.
We already have an IT provider. Does this step on their toes?
No, and we'd rather work with them. IT providers keep things running; we look for what's exposed. Most of our findings go straight to the provider to fix, and plenty of Jersey IT firms are happy to have a second pair of eyes on it. We're glad to copy them into everything.
What do you do with the information on this form?
We use it to configure your protection, to know who to contact, and to run the scan on the domain you've authorised. We don't sell it, we don't share it for marketing, and it's handled under the Data Protection (Jersey) Law 2018. Ask us to delete it and we will.
Does it have to be a .je domain?
No. Plenty of Jersey businesses run on .com, .co.uk or something else entirely, and we scan whatever you actually use. The condition is about the business, not the web address: you need to be registered in Jersey with the JFSC, or trading from a Jersey address. We check that by hand before switching anything on.
Are you actually in Jersey?
Yes. That's the whole reason this exists: the offer is funded to raise the security floor here, not to test a market from a distance.
How quickly do we hear anything?
Your first findings land within one working day of applying, written in plain English rather than a vulnerability dump. If you'd like them talked through we'll book twenty minutes; if not, we'll leave you to it and carry on in the background.
Will you want to use us in your marketing?
We might ask, if the six months go well. Only ever with your written agreement, and never with technical detail that would tell anyone how to get at you. Saying no changes nothing about the service.
What if you find something serious?
We tell you the same day, in plain English, with what to do about it and roughly how urgent it is. If fixing it is beyond your setup we'll say so and quote for the work — but you're free to hand our findings to anyone you like, and the report is yours either way.
Is this suitable if we're regulated by the JFSC?
It's a solid baseline and it gives you evidence you're monitoring your exposure. It is not a substitute for a full penetration test or your own regulatory obligations, and we won't pretend otherwise.