What this usually includes
- Review of public website, app, email and domain exposure.
- Security headers, DNS, mail authentication and obvious configuration checks.
- Scoped testing where there is written permission and clear boundaries.
- A report with evidence, priority and recommended fixes.