Security reviews that end in a fix, not a PDF.

Viverna checks your website, email and servers the way an attacker would, explains what it found in plain English, and hands you the fix already in motion: a pull request, a DNS record ready to paste, or a takedown already filed.

For small businesses and early-stage SaaS teams across Canada. Based in Toronto, Ontario.

FindingHigh

No DMARC policy on yourfirm.ca

Anyone can send email that looks like it came from your domain, including invoices with their bank details on them.

Ready to paste into your DNSStarts in monitor-only mode
; add one TXT record to yourfirm.ca
+ _dmarc  TXT  "v=DMARC1; p=none;
+   rua=mailto:dmarc@yourfirm.ca"

Not sure you have a problem?Send your domain. You'll get one real finding from your own site by email, free, with no access needed and no obligation. Verify it yourself before deciding anything.

Request my free finding

Built for businesses without a security team

Different businesses get hit in different places. Here's where the gaps usually are, and the service that closes them first.

One-off services

Fixed scope, fixed price range, agreed before any work starts. Final price depends on the size of your setup. All prices in CAD.

Best place to start

Security Snapshot

$150–250

Turnaround: 48 hours

A quick outside look at what anyone on the internet can see about your site. The easiest way to find out whether you have a problem.

  • Automated scan of security headers, TLS, dependencies and exposed secrets
  • Short written report with 3–5 prioritized findings
  • 20-minute walkthrough call

Email Authentication Hardening

$150–300

Turnaround: Same day to 48 hours

Stops people from sending email that looks like it came from you. Most businesses have never set this up, and it's usually the fastest visible win.

Full scope (7 items)
  • Audit of your current SPF, DKIM and DMARC setup, or confirmation that none exists
  • Every legitimate sender mapped: your mail provider, invoicing, newsletters, booking tools
  • SPF record drafted to cover them all without breaking the 10-lookup limit
  • DKIM enabled through your email provider
  • DMARC set up in monitor-only mode (p=none) with a defined path to enforcement
  • Delivery test confirming your domain passes authentication
  • Plain-language report: what was wrong, what it exposed you to, what was fixed

Price depends on how many sending services need mapping. Included free on every Full Audit or Bundle.

Clone Site Detection & Takedown

$300–600

Turnaround: 3–7 business days per batch

Finds fake copies of your site set up to steal your customers' logins or payments, then files to get every one taken down.

Full scope (6 items)
  • Look-alike and typo domain scanning, certificate transparency log search, reverse image search on your brand assets and copied-content matching
  • Checks against PhishTank, OpenPhish and Google Safe Browsing
  • Evidence package for each confirmed clone: screenshots, hosting and registrar details, side-by-side comparison
  • Takedown reports filed in parallel with the host, registrar, Google Safe Browsing, CDN and threat-intel feeds
  • Active password-stealing clones filed first
  • Report with takedown status per site and realistic timelines

Scales with the number of confirmed clones. Formal domain disputes (UDRP) against repeat offenders need a lawyer; those are flagged for you, not filed.

Full Web App Audit

$900–1,800

Turnaround: 3–5 business days

A hands-on review of your web application, the way an attacker would approach it.

  • OWASP Top 10 review
  • Login, session and permission testing
  • API checks
  • Header and TLS review
  • Dependency audit
  • Prioritized report and walkthrough call
  • Email Authentication Hardening included as a same-day quick win

How an engagement works

  1. Start with what's public

    A free finding or a Security Snapshot. It only looks at what anyone on the internet can already see, so no access or passwords are needed.

  2. Talk it through

    A short call in plain English: what each finding means for your business, and which ones actually matter this month.

  3. Get the fix, not just the finding

    Deeper testing only happens under a written scope agreement. Fixes arrive as pull requests your developer can review, DNS records ready to paste, or takedown reports already filed.

  4. Keep watching

    Look-alike sites come back under new domains and new email senders appear. A retainer keeps someone watching after the report is done.

Monthly retainers

Available after your first audit, once there's a known baseline to watch. Prices per month, in CAD.

Monitor

$250–400/month

Someone keeping watch between audits.

  • Weekly automated scans: dependencies, headers, TLS, exposed secrets
  • DMARC report review with recommendations for tightening enforcement
  • Monthly summary report

Email support, 48-hour response

Managed

$700–1,200/month

Teams shipping new features every month.

Everything in Monitor, plus:

  • Monthly manual review of new features and deploys
  • Patch and log review
  • Quarterly mini penetration test
  • DMARC managed all the way to full enforcement (p=reject)
  • Monthly sweep for new clone and look-alike sites

Priority support, 24-hour response

Partner

$1,800–3,000/month

Companies selling to enterprise or raising money.

Everything in Managed, plus:

  • Security review before every major release
  • Same-day incident response
  • Help with security questionnaires and SOC 2 prep
  • BIMI logo setup and Verified Mark Certificate guidance
  • Weekly clone-site monitoring with same-day takedown filing
  • Quarterly report written for investors and enterprise buyers

Direct Slack channel

Neither email security nor clone sites stay fixed on their own. Someone who cloned your site once will often do it again under a new domain, and your DMARC policy needs updating every time you add a new tool that sends email. A retainer means someone is watching continuously, not just once.

Ask about a retainer

Coming next from Viverna

The scanner behind every Security Snapshot is built in-house. These two are next.

In development

TOLENV

Upload your codebase and get automated security testing back, with a proposed fix for each problem written as a diff against your original file. All that's left is reviewing and merging it.

Register interest

In development

Cross-border AI compliance

For Canadian businesses using or selling AI tools in Europe and the UK. Translates the EU AI Act, UK AI regulation and provincial privacy law into a list of what you actually need to do.

Register interest

Who you'll work with

Viverna is run by O.D.A Adetunji, a computer science and networking student at Ontario Tech University and a full-stack developer who builds and secures his own products. You deal with the person doing the work, from the first scan to the last fix.

The toolkit covers web application testing against the OWASP Top 10, vulnerability scanning with Nuclei and Nikto, secrets detection with Gitleaks and TruffleHog, TLS auditing, Linux hardening with Lynis, dependency and container scanning, and Burp Suite for manual testing.

Viverna is part of ADA Inventive.

CompTIA logo

CompTIA Security+

Products built and hardened in-house

  • Hestia

    Property management platform for Canadian landlords.

  • SOXO

    University-verified social platform with location anonymization and system-level encryption.

  • Aegis

    Tool for scanning domains and websites for publicly exposed credentials and issues

Each one ships with rate limiting, idle-session timeouts, lockout after repeated failed logins and CAPTCHA on sensitive pages.

Questions clients ask first

Do you need access to our systems?

Not for a free finding or a Security Snapshot. Both only look at what is already publicly visible. A Full Web App Audit or Server Hardening needs your written authorization and an agreed scope before any testing begins.

Could testing break our live site?

Scope and timing are agreed with you in writing first. Anything that could affect a live site is either scheduled with you or run against a staging copy.

We already have IT support or a developer.

This works alongside them, not instead of them. It's an outside view of what the public internet can see, which most IT providers only check when asked. Fixes are delivered as pull requests and records your team can review before anything changes.

How do I know a finding is real before I pay?

Ask for one free finding. You get a real issue from your own site by email, and you can verify it yourself or with your developer before deciding anything.

Can you help with security questionnaires or SOC 2?

Yes. That's part of the Partner retainer, along with a quarterly report written for investors and enterprise buyers.

Why is the retainer only available after an audit?

Monitoring only works once there's a known-good baseline to watch against. The first audit sets that baseline.

Start with one finding

Tell Viverna what you run. The free finding and the Security Snapshot only look at what's already public, so all that's needed is your domain.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.