Straight answers about scope, pricing & readiness
What the free External Security Health Check actually covers, what remediation and Shield Care include, and how we talk about compliance readiness — without overnight “certified” promises.
Getting started
Who we help and how the first conversation works.
Who is Arcane Digital Shield for?
Arizona small and mid-size businesses — trades and home services, professional offices, medical and dental practices, hospitality, and owner-led firms that need clear cybersecurity without enterprise sales theater. We are Phoenix-based and serve the Valley (including Carefree, Fountain Hills, Scottsdale, Tempe, Chandler, Mesa, and Gilbert) plus remote clients who want the same fixed-price path.
What is the Free External Security Health Check?
A free look at what a stranger can already see of your website and email — no agent on your network, no passwords. You get a plain-English findings list. If a prime contractor sent you a security questionnaire, the Health Check is still the start; the $250 Questionnaire Gap Assessment on the Supply page is the next step for that packet.
Do I need to buy anything before we talk?
No. Start with a Free External Security Health Check. You only pay when you choose fixed-price remediation, Shield Care, a Questionnaire Gap Assessment, or a custom quote for advanced work.
How is this different from a big MSSP or “enterprise SOC”?
Large providers often sell per-seat tooling and long contracts. We lead with public-exposure visibility you can understand, one fixed remediation price when you want gaps closed, and optional monthly monitoring. Compliance and advanced programs are quoted separately — we do not pretend every SMB needs a six-figure SOC.
Health check & scoping
Exactly what the free check includes — and what it does not.
What is the Free External Security Health Check?
A no-obligation review of how your business looks from the outside — the same public surface attackers scan first. We use publicly available information only. You get a plain-English report of what is exposed and what it means. The report is yours to keep either way.
What is in scope for the free health check?
Typical coverage: email spoofing and authentication (SPF / DKIM / DMARC), website and CMS exposure (including common WordPress issues), HTTPS and security headers, and threat-reputation lookups on your public assets. Nothing to install. No agent on your network. We do not ask for passwords or admin access for the free check.
What is out of scope for the free check?
Internal network scanning, authenticated application testing, cloud tenant deep-dives that need admin consent, staff phishing simulations, full policy libraries, formal Security Risk Analyses for regulated programs, and anything that requires privileged access. Those belong in remediation, custom projects, or written compliance-readiness follow-up — not the free public check.
How long does the health check take?
Usually a few business days once we have your domain and website. Because it uses public data, there is nothing for you to install and no downtime.
What if the check comes back clean?
We tell you. You owe nothing. If useful, we may still suggest light hardening or monitoring so it stays that way — your call.
Pricing & engagement
Numbers match our public pricing page — no invented packages.
How much does remediation cost?
Professional Remediation is a fixed $1,199 (one-time) for findings from your health check: we close the gaps in scope, deliver a remediation report, and verify after 30 days. The Pricing page lists the full feature set.
What is Shield Care?
Ongoing protection at $149/month: continuous monitoring, monthly patch management, quarterly external re-scan, and priority support. It is designed to keep remediation from drifting. You can add it after remediation or discuss timing on the Health Check call.
When do you use custom / enterprise pricing?
Larger environments, unusual scope, penetration testing programs, formal compliance roadmaps (including SOC 2 readiness support), cloud posture programs, and vCISO-style advisory are custom quotes. You always see the number before work begins.
Will you surprise me with add-ons mid-project?
No. Free check → clear findings → fixed remediation quote (or custom quote when scope is bigger). If something is outside the agreed scope, we pause and get your approval in writing before expanding.
What we fix
What does Professional Remediation typically include?
Closing health-check findings such as email authentication (SPF / DKIM / DMARC), WordPress / CMS hardening, security headers (for example CSP and Referrer-Policy), a fuller external vulnerability pass as needed for the fix set, plus a remediation report and 30-day verification. Exact items track what we found on your assets.
Do you only hand me a list of problems?
No. Remediation is priced to fix what we found in scope — not to drop a PDF and walk away. If you prefer recommendations-only, say so; most owners want the gaps closed.
Do you offer penetration testing and incident response?
Yes, as scoped projects. Pen testing and emergency response are not the free health check. We define targets, rules of engagement, and price up front. For an active incident, call (480) 788-5419.
Can you help with day-to-day IT as well?
Yes — practical IT support (devices, malware cleanup, backups, network basics) is available alongside security work. Security packages above are separate from hourly IT unless we combine them in a written scope. See the Services page for categories.
Compliance readiness
Plain English for owners under HIPAA-ish, PCI-ish, or SOC 2 pressure. We talk readiness and documentation — not overnight “you are certified” promises.
What does “compliance readiness” mean here?
Readiness means helping you understand where you stand against a framework’s security expectations, closing technical and process gaps that are in our scope, and organizing evidence so you (or your auditor/assessor) can move forward. It is not the same as a government stamp, a SOC 2 report, a PCI Attestation of Compliance, or a claim that you are “fully compliant” forever.
Will you make my practice “HIPAA certified”?
No — and be wary of anyone who sells that badge. There is no official HHS “HIPAA certification.” HIPAA compliance is your ongoing legal obligation (policies, risk analysis, safeguards, training, BAAs, breach procedures). We can help with security posture, technical hardening, and readiness guidance. For HIPAA/legal obligations we use written follow-up — we do not give off-the-cuff legal advice in a sales call, and we never promise that one engagement makes you compliant overnight.
How do you handle HIPAA-sensitive topics?
Health-related and regulated questions get a careful, written follow-up after we understand your environment. The free External Security Health Check still only looks at public exposure (site, email auth, headers, reputation). Formal Security Risk Analysis work, policy packages, and workforce-program design are separate scoped engagements — not something we invent on a phone call.
What about PCI DSS if we take cards?
PCI obligations depend on how you accept payments (for example, who your processor is and whether card data ever touches your systems). We can help you understand technical exposure and reduce unnecessary card-data handling. We do not issue PCI Attestations of Compliance or replace your Qualified Security Assessor when one is required. Expect written scoping if you need PCI-oriented readiness help.
Can you help with SOC 2?
Yes as readiness support: roadmap, control mapping, policy development support, evidence hygiene, and technical hardening that auditors tend to ask about. A SOC 2 report is issued by an independent CPA firm after their examination — we prepare and guide; we do not “grant SOC 2.” Enterprise / SOC 2 work is custom-quoted on the Pricing page.
Security vs compliance — which do I need first?
Most SMBs need basic external hygiene first (email auth, site hardening, monitoring). Compliance frameworks build on that foundation. If a customer, insurer, or regulator already asked for a specific framework, we prioritize that path in writing after the Health Check — without skipping the public exposure problems attackers exploit today.
Ongoing monitoring
What does “continuous monitoring” mean on Shield Care?
We keep watching the external and agreed monitoring surface after remediation — so regressions, new exposures, and patch drift get attention instead of a one-time cleanup. Monthly patch management and a quarterly external re-scan are part of the $149/mo plan.
Is Shield Care a full enterprise SOC?
No. It is practical managed care sized for SMB budgets. If you need 24/7 enterprise SOC, MDR tooling across every endpoint, or heavy OT environments, we will say so and quote custom — we will not sell you a label that does not match the work.
What if something looks wrong after hours?
Shield Care includes priority support and rapid response. For suspected active compromise, call (480) 788-5419. Incident response beyond the monthly plan may be scoped at emergency rates — we tell you before expanding billable work whenever possible.
Logistics
Do you work on-site in the Phoenix metro?
Yes. Most health-check and remediation work can be remote. We come on-site across the Valley when it helps — Phoenix, Scottsdale, Tempe, Chandler, Mesa, Gilbert, Carefree, Fountain Hills, and nearby communities. Browse the Locations hub for city pages.
Do you work outside Arizona?
Remote engagements are welcome when the work fits (public exposure, email/web hardening, advisory). On-site outside the metro is discussed case by case.
How do I get started?
Book a Free External Security Health Check on the Book page, or call (480) 788-5419. Prefer email? a.caruso@arcanedigitalshield.com. Prime-contractor questionnaires start on the Supply page.
Where can I see prices and city pages?
Full pricing is on the Pricing page. Service categories are on Services. Local coverage is under Locations, including Phoenix, Carefree, and Fountain Hills pages.
Still unsure? Ask us on a free call
Book a Free External Security Health Check. We will tell you what is in scope — and what is not — before you spend a dollar.