Employee bios, client mentions, machinery photos, clearance-required job posts, technology stack details. Media Express audits everything publicly visible on your website to identify what hurts your compliance posture with government buyers — and helps competitors, attackers, or foreign intelligence.
Every audit maps against these eight categories. Most sites have issues in at least three of them. Nobody realizes it until we look.
Detailed bios, org charts, LinkedIn-linked staff pages. Reconnaissance-friendly — helps social engineering and spear-phishing.
Prime contractor logos, marquee client mentions, "As trusted by..." reveals your supply chain. Often violates prime-contractor flow-down clauses.
Specific machine models, tolerances, envelope sizes. Tells attackers — and competitors — exactly what you can and can't produce.
"Must hold Secret clearance" or "Active Top Secret required" in job posts reveals classified programs and staffing gaps.
Powered by / Built with badges, framework versions, plugin lists, CMS fingerprints. Reveals attack surface to threat actors.
Interior photos, entry/exit locations, security guard positions, badge readers visible in tour videos. Physical reconnaissance material.
Owner's personal cell, direct emails for high-value staff, home addresses on legal filings linked from site. Personal targeting vectors.
Old PDFs, brochures, presentations, quote docs left in /uploads folders. Metadata reveals authors, machines, software, edit history.
Every audit produces a structured PDF report you can hand to your web team, IT team, or Media Express for implementation. No 100-page consultant report — just clear findings, prioritized by risk, with the specific fix each one needs.
Crawl your site, catalog every page/image/PDF/script, extract metadata, fingerprint the tech stack. Result: full inventory of what's public.
Human eyes on every page. We map findings against the eight OPSEC categories, note context (what makes each item risky given your industry and clients), and gather concrete evidence with URLs and screenshots.
PDF audit report delivered. OPSEC readiness score, findings by category and severity, specific pages flagged, recommended fixes, effort estimates, 30/60/90 day action list.
If you order Audit + Fix package, we remove or replace the flagged items, redact metadata from files, adjust image publication, restructure pages, and set up canonicalization for legacy URLs.
Monthly re-scan for new exposures. Quarterly full re-audit. Alerts when your team publishes something risky. Keeps you clean over time as your site evolves.
From a self-service automated scan to a full audit + fix + ongoing monitor. Pick the level that matches your risk exposure.
Ongoing monitor + quarterly re-audit: $300-800/mo. Recommended for anyone with active gov contracts.
Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.
⚜ Free Consultation →No. Traditional security audit looks for vulnerabilities in your systems (SSL misconfiguration, injection risks, weak passwords). OPSEC audit looks at what's INTENTIONALLY public but shouldn't be — the marketing, employee info, client references, and technical details that expose your organization. Both matter; they're complementary.
Any business pursuing federal, state, or prime contractor work — especially defense, aerospace, utility supply chain, IT services for regulated clients. Also useful for law firms handling classified matters, healthcare providers with sensitive patient bases, and any business with valuable IP or sensitive customer lists.
Full audit: 5-7 business days for a small site (up to 50 pages), 10-15 business days for larger sites. Rush option available. Automated scan is instant.
Yes — via the Audit + Fix tier. The Full Audit tier delivers a PDF report your web team can act on. Audit + Fix includes implementation: we remove or replace flagged items, redact metadata, adjust image publication, restructure pages, and verify with a clean sweep scan.
Everything about the audit is confidential. Media Express signs an NDA at the start. The report is delivered encrypted. We don't share your findings, screenshots, or company details with anyone. Standard.
Yes. Most OPSEC audits are on sites Media Express did not build. We work with WordPress, static, custom stacks, subdomain sprawls, and legacy CMS. If your web team owns the site, we deliver the report and they implement. If you want us to implement, we work with your web team's access.
Full re-audit annually at minimum. Quarterly if you actively publish new content, hire employees regularly, or add new client references. Monthly automated re-scan is included in the retainer.
OPSEC audits pair with framework readiness and capability statements to build a complete compliance-visible posture.
Book an OPSEC audit and find out. Full manual review with prioritized PDF report in 5-7 business days. Optional fix implementation available.