Services

Website security & data protection check

A practical security and data protection check for your website — the five things behind most small business incidents, plus the Ley 172-13 obligations that actually apply in the Dominican Republic.

Most small business websites that get compromised weren't hacked by anyone in particular. They were running software with a known flaw, nobody was patching it, and an automated scan found it on a Tuesday. That is genuinely dull, and it is also almost entirely preventable. This check finds those gaps, tells you which ones matter for a business your size, and fixes the ones worth fixing. It is a check, not a certificate — we don't issue badges, because there's no scheme here that would mean anything.

Scope
Fixed, quoted up front
You get
A written report
Badge or certificate
None — and that's honest
Covers
Ley 172-13 + GDPR

Where AI fits in a security check — almost nowhere

Honestly, not here. Patching, access control and backups are deterministic engineering problems: there's a right answer and it's knowable. AI adds nothing to applying a known update or confirming a backup restores. The one place it earns a small place is triaging a wall of log lines to work out whether something actually happened — but that's a question for a human anyway, and a good log is a better use of your money.

The five things, and why they're the five things

Look at almost any small business website breach — anywhere in the world — and the cause is rarely a sophisticated attacker. It's an unpatched plugin, a reused admin password, a backup that never worked, or a form that let anyone post anything into a mailbox. Those four account for the overwhelming majority. So that's what we look at, in that order, because the order reflects how often each one is the actual answer.

Unpatched software is the single biggest one

Every plugin, theme and library on your site is code someone else wrote and someone else now maintains. When a flaw is published, the only thing standing between it and your business is whether you applied the update. Sites left alone for a year accumulate dozens of known holes, and most scanners will find them without trying particularly hard. This is unglamorous maintenance work, and it is the thing that prevents the overwhelming majority of incidents.

Access control is the second

It's remarkable how many sites still have a default admin path and an admin account whose password was set in 2019 by someone who has since left. Two accounts with weak credentials and a login form with no rate limiting is an invitation, not a defence. We look at who has access, whether it needs to be shared, and whether anything sensible stops repeated automated attempts.

Backups only count if you've restored one

Every host promises backups. Very few can produce a working restore when you need one, and the failure mode is always the same: something goes wrong, the host says 'we have backups', and then nobody can actually produce it. So we check where the backups live, whether they're kept away from the server itself, and — the part that matters — whether anyone has ever restored from one. An untested backup is a hope, not a safeguard.

Forms are where the internet reaches you

Contact forms, booking forms and quote requests are a direct line into your inbox from anyone on the internet, so they're the most abused part of most sites. That doesn't mean they have to be made unusable — you need them to work. It means the abuse should be filtered without an aggressive captcha in front of every genuine customer, and without leaving a route for someone to post arbitrary content through your form.

The part that actually applies here

The Dominican Republic's Ley 172-13 is the law that applies, and the GDPR also reaches the personal data of European visitors. In practice that means real consent before any non-essential cookie or analytics script loads, a privacy notice that actually describes what you collect, and a route for someone to exercise their rights. Almost every small site we look at fails some of that — usually the consent banner, which is either missing entirely or a fake one that accepts everything before doing anything else. It's unglamorous, it's legally required, and it's fixable in a day.

Where this stops and something bigger starts

If you're being asked for ISO 27001, NIS2 certification, or to sign a client's data processing agreement with a 200-page annex, this check is the wrong product and we'll tell you so. Those are management-system projects involving policy, training and audits over months — real work, but a different scale and a different budget, and not something a web studio should pretend to deliver. What we do is make sure you're not obviously exposed, and that you know exactly where you stand.

What’s included

  • Out-of-date software and known vulnerabilities, checked against what your platform actually exposes
  • Who can reach your admin area, and whether the default accounts are still open
  • Backup setup reviewed — including whether a restore has ever been tested
  • Forms checked for spam abuse and injection, without wrecking the ones your customers rely on
  • Ley 172-13 position: consent, privacy notice and what happens to enquiry data
  • A written report in plain English, ranked by what would actually hurt you

Why it matters

  • A known list of gaps rather than an unknown amount of worry
  • The handful of things worth fixing, in the order that matters
  • An honest answer on whether you need anything done at all
  • Evidence you can show an insurer, a client or a partner

Often useful alongside this

  • Website maintenance if you'd rather fix the gaps once and then have it handled properly.
  • Website hosting for the uptime, monitoring and off-server backups the check assumes exist.
  • Website design if a lot of what we find is a site built before any of this mattered.

Common questions

Do I get a certificate or badge to put on my website?
No. There's no recognised scheme for most of this, and any badge we invented would mean nothing to a client checking it — which is worse than having none. You get a written report listing what we found, what we fixed, and what's left, which is more useful than a logo and honest about what it is.
Is this required by law in the Dominican Republic?
Parts of it are. Ley 172-13 applies to any business handling personal data, and almost every website with a contact form does, so the data protection side isn't optional. The technical security side is common sense and insurance requirements rather than law. We'll tell you which parts are which, so you can prioritise properly.
What if my website is small and doesn't hold much data?
That genuinely lowers the stakes and we should say so rather than selling you a project you don't need. If your site is a brochure with a contact form and no customer records, the realistic risk is low. It's worth doing if you take bookings or payments, or if downtime would cost you money — and it's worth skipping if the worst case is an embarrassing email address in public for a week.
Will you break my website while fixing it?
Not if we do it in the right order. Changes that affect live behaviour — forms, admin access, anything customer-facing — get tested before and after, and there's a tested backup before we start. Most of the work is updates and configuration that should be invisible. If a fix carries real risk, we'll explain the tradeoff before making it rather than after.
Do you provide ongoing monitoring or managed security?
No, and deliberately. Continuous monitoring is what the hosting plan covers — uptime, backups, and applying security updates on a schedule. This check is a one-off assessment with a document at the end. If you need ongoing security operations, an MSP or a managed security provider is the right fit and we're happy to say so.
Can you help with the cookie banner specifically?
Yes, and it's usually the single most useful part of the whole check. Google Analytics and similar tools set cookies before anyone has agreed to them, which is the part that breaches Ley 172-13 and the GDPR. We implement proper prior consent with a genuine reject option, and make sure the analytics only start after someone accepts.

Free, no-obligation

Get a free website audit and quote

Tell us about your business and we’ll come back with honest, friendly advice — including a clear quote and what we’d improve first.

Trusted by businesses across the Dominican Republic