PFProveFixed
Menu

Agency field guide

A public website security baseline agencies can act on

A useful baseline connects an authorized asset to an observation, a finding, a decision, a fix task, and a later verification event. It keeps technical evidence clear without overstating coverage.

ProveFixed is an external evidence and fix-verification layer. It complements maintenance platforms and professional security work; it does not replace them.

Baseline workflow

From authorized asset to verified change

Step 1

Confirm scope and authorization

Record who owns or manages each website, what public checks are permitted, and who can approve changes. Do not collect customer credentials for a public baseline.

Step 2

Capture an initial public observation

Record DNS email controls, TLS and HTTPS behavior, response headers, and the public homepage evidence that was actually read.

Step 3

Separate evidence from inference

Use confidence to describe evidence quality. A scanner status without auditable raw evidence should not be presented as a fully confirmed conclusion.

Step 4

Prioritize a short action list

Select the issues with the clearest business impact and evidence. Name the responsible owner and provide a precise, reviewable fix task.

Step 5

Apply changes through the normal workflow

The authorized developer, DNS administrator, email provider, or host reviews and applies the change. External monitoring should not modify production automatically.

Step 6

Re-scan and compare

Collect a later independent observation. Mark a fix verified only when comparable before-and-after evidence supports that conclusion.

Responsible boundary

Know what the baseline does not prove

Public observations are valuable when their scope stays explicit. Unread pages, authenticated systems, application code, and internal infrastructure remain outside this first-pass evidence.

  • It does not replace WordPress maintenance or update management.
  • It does not replace endpoint, firewall, or malware protection.
  • It does not inspect private administration areas or source code.
  • It is not a penetration test or complete vulnerability assessment.
  • It does not guarantee continuous detection or complete security.

Start with a reviewable example

The sample report shows how public evidence, confidence, business impact, responsible ownership, and before-and-after verification fit together. Sample findings remain clearly labeled as sample data.