Penetration testing · for small companies · Slovenian

A white hat for your company.

A small company has the same exposed surface as a big one — a website, a mail server, a handful of services — but rarely the budget for a yearly pentest. Beli Klobuk is a security agent that maps what is exposed, checks your domains and mail reputation, hunts typosquats, and hands you a report with the findings in the order to fix them.

Exposed surfaceDomainsMail reputationTyposquatsKnown issues

First Look entry package · early access · launching soon

How it works

A first look, then a deeper test only with your word

The entry package is passive — it looks at what is already visible. Anything intrusive happens only after you confirm written authorisation, and it runs in a sandbox.

First Look

A passive assessment of your exposed surface, domains, mail reputation and typosquats. No intrusive testing — only what is publicly visible.

Report

Findings in priority order, written for a person who has to decide what to fix first. In Slovenian.

Authorise

If you want a deeper, active test, you confirm written authorisation for the assets in scope. The agent will not test anything outside it.

Active test

A multi-agent security agent runs the authorised test in an isolated sandbox, step-limited and time-boxed, and extends the report.

What it checks

The things a small company is actually exposed on

Not a hundred-page report nobody reads. The handful of things that are both likely and worth fixing.

surfaceWhat of yours is reachable from the internet — sites, services, open ports.
mailSPF, DKIM and DMARC on your mail domain; whether someone can spoof you.
domainsTyposquats and look-alike domains registered to impersonate you.
reputationWhether your mail server or IP is on a blocklist that hurts deliverability.
TLSCertificates about to expire, weak configuration, mixed content.
known issuesPublic, known weaknesses on the versions you are visibly running.
Authorisation and ethics

Active testing is bound to your written word

This is the part a serious buyer asks about first, and the part that keeps everyone out of trouble.

Enforced in code, not a checkbox. The agent performs active security testing only against assets you own and only after confirmed written authorisation for exactly those targets. The check lives in the code path, so a scan outside the authorised scope does not run.

Sandboxed execution. Tools run in an isolated environment, step-limited and time-boxed, so a run cannot wander off your targets or loop. A tool that cannot reach the authorised target simply has no path.

Your report, your call. Findings stay with you, in priority order, with what to do about each. Beli Klobuk tells you where you are exposed; the fix is yours to schedule.

Who it is for

Companies that fall through the gap

A yearly penetration test from a consultancy starts in the thousands and takes weeks to schedule. Most small companies and startups simply skip it — and carry the same exposed surface unchecked. Beli Klobuk is the first look they can actually act on: a report they can read and a clear next step if they want to go deeper.

Small companies and startupsA website, a mail server, a few services, and nobody whose job is security.
Before an audit or a tenderSee where you stand before a customer, an insurer or a certification asks.
After a scareA spoofed e-mail, a look-alike domain, a near miss — find out what else is open.
In SlovenianInterface and report in Slovenian, findings written to be acted on, not only read by a specialist.
FAQ

Questions buyers ask

Is this legal? You are testing systems.

Active testing runs only against assets you own and only after you have confirmed written authorisation in the system. That check is enforced in code, not a checkbox on a form, and execution runs in an isolated sandbox. The passive first look needs only a domain you control.

What do I get for the entry package?

The First Look is a passive assessment: your exposed surface, domain and mail-reputation checks, typosquats and known issues on what is publicly visible — no intrusive testing. You get a readable report with findings in priority order. It is the lowest-commitment way to see whether a deeper, authorised test is worth it.

We are a small company, not a bank. Do we need this?

A small company has the same exposed surface as a large one — a website, a mail server, a few services — but rarely the budget for a yearly pentest. Beli Klobuk exists for exactly that gap: a first look small companies can actually act on, with a clear next step if they want to go deeper.

Does my data or my systems leave the building?

The agent reports to you. Findings and the report stay with you. Active testing is sandboxed and scoped to the targets in your authorisation; a tool that cannot reach the authorised target has no path out.

Is the report in Slovenian?

Yes. The interface and the reports are in Slovenian; the agent works internally in English and translates. The findings and the priority order are written for a person who has to decide what to fix first, not only for a security specialist.