Professional cyber security, made accessible

Cyber security should not depend on how much you can afford.

Security Aid provides professional cyber security services to organisations that need them, including penetration testing, security assessments, incident support and practical advisory.

Free means free. Some of our work is provided completely free of charge.
  • No sales trap
  • No deliberately reduced assessment
  • No obligation to purchase afterwards
Written authorisation Professional testing Actionable reporting Confidential findings No forced upsell
A concrete commitment

What does a free penetration test actually mean?

Where Security Aid accepts an engagement, the limitation is capacity and eligibility, not deliberately reduced quality.

It can include

  • Scope definition and rules of engagement
  • Written authorisation before testing
  • Manual and authenticated testing where appropriate
  • Vulnerability validation and business logic testing
  • Responsible evidence collection and risk-rated findings
  • Remediation guidance and a findings walkthrough
  • Retesting where agreed

What it does not mean

  • An automated scanner passed off as a penetration test
  • Five minutes of superficial testing
  • Withholding findings unless the organisation pays
  • A deliberately incomplete assessment designed to sell consultancy
Free means free.
Professional services

What can Security Aid help with?

Real security work, practical advice and clear remediation priorities.

View all services
01

Web Application Penetration Testing

Manual web application testing designed to identify vulnerabilities that could realistically be exploited.

02

Vulnerability Assessments

Identify exposed systems, insecure services, configuration weaknesses and practical remediation priorities.

03

Security Advisory

Practical cyber security advice for leaders, IT teams, charities, non-profits and small organisations.

04

Incident Response Support

Help organisations understand and respond to cyber security incidents, subject to available capacity.

05

Security Architecture & Roadmaps

Review proposed or existing systems and identify security weaknesses before they become incidents.

06

Cyber Essentials Readiness

Guidance on understanding Cyber Essentials requirements, identifying gaps and preparing for certification.

What's the catch?

There isn't one.

If Security Aid accepts your organisation for a free engagement, you do not need to subscribe afterwards.

Request Free Support

We do not withhold the useful parts of reports. We do not deliberately limit testing so that we can sell the rest.

The limitation is simply Capacity.

Requests are reviewed against organisational need, security risk, available capacity, potential impact and urgency.

Paid members pay for guaranteed capacity and ongoing services, not access to findings that should have been included in free work.

Who we help

Who do we prioritise?

Applications are assessed individually so Security Aid can direct limited capacity where it can have meaningful impact.

Charities

Organisations delivering public and social benefit.

Non-profits

Mission-led organisations working with limited budgets.

Community organisations

Local groups supporting people and communities.

Small businesses

Businesses without enterprise security resources.

Significant cyber risk

Organisations facing an active or material concern.

Based in Northamptonshire. Supporting organisations across the UK.

How the model works

Protect. Sustain. Support.

Commercial activity exists to create dependable capacity and expand the free programme.

Protect

Free professional security services where capacity allows.

Request help
Sustain

Memberships fund guaranteed support and ongoing services.

View memberships
Support + memberships Fund capacity More free security work
What useful reporting looks like

Clear findings. Practical decisions.

Security work should leave an organisation understanding what happened, why it matters and what to do next.

  • Evidence-led findings
  • Clear business impact
  • Risk-based remediation priorities
  • Confidential handling throughout
Example finding High

Broken access control allows unauthorised access to customer records

Impact
An unauthenticated attacker could access sensitive records belonging to other users.
Recommendation
Implement server-side authorisation checks for every affected endpoint and validate access against the authenticated user.
Example only. This is not a finding from a real organisation.
Transparent by design

Our impact

Security Aid intends to publish transparent statistics as the programme grows. No invented numbers and no inflated claims.

View Impact
Organisations supportedReporting coming soon
Free penetration tests deliveredReporting coming soon
Security hours donatedReporting coming soon
High-risk vulnerabilities identifiedReporting coming soon
Need guaranteed support?

Memberships provide certainty and fund the free mission.

Free services depend on available capacity. Memberships are for organisations that need reserved security capacity, advisory hours, ongoing support or platform functionality.

Membership revenue helps Security Aid provide more free security work.

View Memberships
  • Reserved advisory capacity
  • Continuous monitoring
  • Vulnerability tracking
  • Incident response arrangements
  • Reserved penetration-testing capacity
  • Security reporting and platform functionality
Start here

Need security help?

Whether you need a penetration test, are worried about an incident or simply do not know where to begin, tell us what you need. If we can help through the free programme, we will tell you. If we do not have capacity, we will be transparent about that too.