Your website is open all night.

Most small practices have nobody looking at it.

SmallShield looks at it for you.

From the outside, the way an attacker does. Every month. One page back, in plain English.

Website security for small practices, run by a person you can call.

Monthly outside checks from $99 a month. Built and answered in Mount Pleasant, South Carolina.

Website security for small practices, run by a person you can call.

Your website is open all night. SmallShield looks at it from the outside every month and sends you one page in plain English.

Who this is for

Small practices that hold other people's private information.

If a patient or client can book, pay, or fill out a form on your website, your website is part of your practice. It deserves the same attention as the front door.

Dental offices

Patient forms and appointment booking run through your site. A hacked site can mean a breach you have to report.

Med spas

Before and after photos, intake forms, deposits. Your clients expect discretion.

Accountants

Tax documents move through your portal every spring. Attackers know the calendar too.

Law firms

Client trust is the whole business. A hijacked site costs more than the fix would have.

Every line above is a real risk. The fix is simple: a monthly outside check, in plain English, from someone you can call.

What we check

Ten things an attacker looks for. We look first.

Every scan looks at your website from the public internet, exactly the way an attacker does. Nothing is installed. Nothing is logged into.

Sample results for an example site. Your real first scan runs after you sign the authorization form.

  1. HTTPS certificate

    Expired or broken HTTPS is the first thing a browser warns your patients about.

    Valid. Renews in 61 days.
  2. Open ports

    Doors into your server that never needed to be open.

    Two unused ports open. Medium.
  3. Known vulnerabilities

    Published flaws attackers start scanning for the day they go public.

    None found.
  4. Security headers

    Browser protections your site should be sending and probably is not.

    Three missing. Low.
  5. Exposed admin login

    Login pages sitting in public view, waiting for password guessing.

    Publicly visible. High.
  6. Outdated software

    Old versions with known holes. Still the most common way in.

    One plugin two versions behind. Medium.
  7. DNS records

    The records that point your name to your website. Misconfigured, they make impersonation possible.

    Clean.
  8. Blacklist status

    Whether Google or spam filters have already flagged your domain.

    Not listed.
  9. Mixed content

    Insecure pieces quietly loading inside your secure pages.

    None.
  10. Email protection

    SPF and DMARC records, the settings that stop criminals from sending email as you.

    DMARC missing. Medium.
How it works

Three steps. No passwords, no software, no visit.

STEP 1

You sign one form.

It gives us written permission to scan your domain. Five minutes, by email. Nothing else is needed from you.

STEP 2

We look from the outside.

Every month, or every week on Pro and Compliance, we check your website the way an attacker would.

STEP 3

You get one page.

What we found, why it matters, and the one fix for each item. If something critical shows up between reports, you get an email the same day.

Your report

Written for the owner, not the IT department.

Every finding gets a plain name, one sentence on why it matters, a severity, and one fix. If a report ever confuses you, that is our bug and we rewrite it.

Sample report example-practice.com
LOW

Your HTTPS certificate is valid. It renews automatically in 61 days. Nothing to do.

HIGH

Your admin login page is publicly visible. Anyone who finds it can start guessing passwords. Fix: restrict it by IP address. Step by step instructions included.

MEDIUM

Two ports are open that nothing is using. Open doors get tested. Ask your host to close ports 21 and 8080. The exact wording for that email is included.

3 findings this month. 1 worth handling this week. Full detail in your inbox.
Plans

One flat monthly price. Cancel by email.

No contracts. No setup fee. Every plan bills monthly through Stripe and ends the month you say so.

Starter

For a practice that wants someone looking.

$99per month
  • Full outside scan every month
  • One page report in plain English
  • Same day email for critical findings
  • Email support answered by a person
Start Starter monitoring

Pro

For a practice that wants to know first.

$199per month
  • Everything in Starter
  • Scans every week instead of every month
  • Dark web watch for your business email, so you hear when a password leaks
  • Priority replies
Start Pro monitoring
Recommended for regulated practices

Compliance

For dental, medical, legal, and accounting practices that answer to auditors, insurers, or HIPAA.

$349per month
  • Everything in Pro
  • Reports formatted to support your HIPAA and PCI paperwork
  • A monthly review call, on the calendar
  • A folder you can hand an auditor or insurer
Start Compliance monitoring

Prices in USD, billed monthly through Stripe. Compliance reports support your own documentation. They are not a HIPAA certification and not a PCI ASV scan, the card industry's official scan.

What happens after checkout

  1. Checkout takes about a minute on Stripe.
  2. You get an email with the authorization form. Signing it takes about five minutes.
  3. The first scan runs as soon as the form is signed. Your first report follows.

No scan runs before the form is signed. That is the law, and it is how we work.

Mount Pleasant, South Carolina

One person. A real phone number.

SmallShield is one person: William Vincent, who built it at 18 in Charleston because small businesses were being ignored. The security companies chase hospitals and banks. The four chair dental office down the road gets nobody. Every scan, every report, and every reply comes from William. When you call, he picks up. When you email, he answers the same business day. No ticket queue, no call center, no salesperson who disappears after checkout.

William VincentFounder, SmallShield LLC
Questions

The questions people ask before they sign up.

Yes. We only scan domains we have written permission to scan, and you give that permission by signing a short authorization form before the first scan. Looking at your own website from the outside, with your consent, is standard security practice. We never scan anyone who has not signed.

No. We never log in to anything. We look at your website from the public internet, the same view anyone has, and we never ask for passwords, hosting logins, or files. Reports contain technical findings about your site, not your patients' or clients' records. We are not set up to receive protected health information, meaning patient medical records, and we do not act as a HIPAA business associate, a vendor that handles patient data on your behalf.

No. Scans are read only. They look, and they do not change anything. They are designed to be light, and in rare cases a firewall notices the scan and logs it. That is the whole effect. If your hosting company has a rule about outside scans, we check it with you before the first one.

We tell you exactly what to fix and how, in plain words, with the exact message to forward to your web person or hosting company. We do not log in and change your website ourselves, because we never have access to it. If you want hands on help, we can quote it separately, and you are never obligated to say yes.

Yes, by email, any time. There is no contract and no minimum term. Reply to any email from us and your plan ends at the close of the month you have already paid for. No partial refunds, no cancellation fee, no phone tree.

SmallShield LLC is a one person company in Mount Pleasant, South Carolina, founded by William Vincent at 18. William is not a large firm and does not pretend to be one. The scans run on established professional scanning tools. The reports, the phone calls, and the accountability are William's. If a one person company is not the right fit for your practice, that is a fair decision, and we would rather you know now.

Ready when you are

Start monthly monitoring.

Checkout takes about a minute. You sign the authorization form, the first scan runs, and your first report follows.