Security Check with a system:
Find vulnerabilities – fix them – prove it

CheckFix makes cybersecurity measurable – for SMEs, NIS-2, and the Cyber Resilience Act.
No pentester required. No technical jargon. With your technician. Before you get hacked.

Automatically finds vulnerabilities

Delivers actionable to-dos:
YOUR technician can handle it

Re-Check: Risk assessment for clients & audits

Technical reports: NIS-2 and CRA compliant

CheckFix product image: It shows an example of a security assessment and a to-do checklist that guides you step by step through fixing the identified security vulnerabilities.

Companies from all industries trust us

Security Check with a system:
find vulnerabilities, fix them, prove it

CheckFix makes cybersecurity measurable – for SMEs, NIS-2, and the Cyber Resilience Act.
No pentester required. No technical jargon. With your technician. Before you get hacked.

Automatically finds vulnerabilities

Risk assessment for clients & audits

Delivers actionable to-dos

NIS-2 and CRA compliant reports

https://checkfix.io/wp-content/uploads/2025/12/checkfix-header-EN-Mobile_1.png
https://checkfix.io/wp-content/uploads/2025/12/checkfix-header-final_mobile_2-EN.png

Companies from all industries trust us

Would you like to learn how CheckFix works?

In just 2 minutes, you’ll understand our simple yet effective approach.

CheckFix Risk Manager Demo starten

Start Interactive Demo

Cybersecurity with a System – Simple, Measurable, Effective

Find and fix security vulnerabilities – developed in Austria



✓ Automated · ✓ In 24 hours · ✓ No-nonsense · ✓ Made in Austria

What makes CheckFix different

For us, analyzing your cybersecurity is just the beginning – CheckFix guides you from vulnerability to solution: automatically, clearly, documented.
CheckFix Brand
Automated analysis from external (“hacker”) perspective – without penetrating your system
CheckFix Brand
Prioritized to-do list with concrete solution instructions (including technical details)
CheckFix Brand
Dashboard: Assign tasks, track status, check off to-dos
CheckFix Brand
Trained GPT assistant: supports your IT during implementation
CheckFix Brand
Re-Check: After implementation, CheckFix checks again and documents the progress
CheckFix Brand
Reports for NIS-2 and CRA: Usable for risk assessment and audits
Many tools only show problems. CheckFix delivers the solutions – clearly, actionably, provably.
CheckFix identifies the open doors for cybercriminals – with our to-dos, you close them before attackers enter.
You can run your next CheckFix analyses and re-checks anytime you’re ready.

CheckFix vs. Pentester (Penetration Test) – Which approach fits your company?

Does my company need a pentest or is an automated tool like CheckFix enough?
Both approaches have their value – what's crucial is where your company currently stands and what goal you're pursuing.
CheckFix Brand

CheckFix

  • Passive external analysis, no penetration
  • To-do list with solutions, prioritized
  • Regularly repeatable, re-check documents progress
  • Start with free check, affordable subscription
  • Continuous improvement & proof (NIS-2, CRA)
  • Trained GPT assistant: supports your IT during implementation
CheckFix Brand

Traditional Pentest

  • Active penetration into systems by security experts (invasive)
  • Report with findings; implementation is up to the company
  • One-time snapshot
  • Several thousand euros per test (depending on scope)
  • Proof of improvement only with new pentest (additional costs)
  • Deeper proof of vulnerability at a specific point in time

When is CheckFix the right approach?

CheckFix Brand

For beginners

CheckFix is the ideal entry into cybersecurity: regular, passive external analysis with immediately actionable solutions and documented re-checks for measuring success.

CheckFix Brand

For companies with pentests

Companies that already conduct pentests use CheckFix for preparation: critical vulnerabilities are identified early, saving time and costs during the penetration test.

CheckFix Brand

For experienced security teams

Companies already investing in cybersecurity use CheckFix to verify the effectiveness of existing measures and the competence of their experts.

Conclusion for security beginners: Start with CheckFix, close the most important gaps, and document progress. Then decide with confidence whether a pentest is still necessary.

Pricing & Packages – What does CheckFix cost?

You can get started with CheckFix at any time. Choose one of the offers below and within 24 hours you’ll receive the FREE Security Check or the comprehensive CheckFix with to-do checklist and technical details for independently fixing the security vulnerabilities.

CheckFix Brand

FREE
Security Check

Review of your security status & risk assessment
  • A = Your company is highly secure
  • C = Action is required
  • F = Serious security vulnerabilities
Upgrade to Security Fix possible anytime
No hidden costs!
FREE for all CheckFix new customers

CheckFix Brand

CheckFix Basic
€ 490,00 / year

Once annually:
Complete security check & fix
  • Ratings from A – F
  • Re-check after fixing
  • Trained GPT for detailed questions
  • All technical details
  • Check up to 3 domains
  • Cancel anytime
Use your CheckFix as security proof for clients and audits

CheckFix Brand

CheckFix Premium
€ 950,00 / year

Twice annually:
complete security check & fix
  • All features of the one-time CheckFix
  • You save €230 | Only €475 per CheckFix
  • 2 security checks per year (incl. re-check)
  • Ongoing progress documentation
  • Cancel anytime
Technical security audit for NIS-2 supply chain & CRA – with documented proof for clients and audits

Specialized Solutions for Your Organization

Beyond CheckFix Basic and Premium, we offer tailored
security solutions for larger organizations and partners.

CheckFix Brand

CheckFix Risk Management

For CISOs and Compliance Teams: Supply Chain Security & NIS2/DORA Management
  • Technically assess supply chain, subsidiaries,
    and subcontractors
  • Standardized questionnaires
    for compliance management
  • NIS2, ISO 27001, DIN SPEC 27068
  • Rating A – F & Report = Audit-ready
Use CheckFix Risk Management for comprehensive supply chain risk management

CheckFix Brand

CheckFix for MSPs

For IT Service Providers and Consultants: Security-as-a-Service for Your Clients
  • Multi-Client Dashboard
  • Automated Client Onboarding
  • Attractive Partner Commissions
  • Branded Reports for Your Clients
  • Dedicated Partner Support
Offer CheckFix to your clients as an additional service

All enterprise solutions include personalized onboarding, priority support,
and flexible payment models. Contact us
for a customized quote.

How good is CheckFix really?

This is what our customers say.

800+

Domains geprüft

24/7

24/7 Technical support

100%

Verified reviews

5
★★★★★
Based on 5 reviews
5 stars
100%
4 stars
0%
3 stars
0%
2 stars
0%
1 star
0%

Customer experiences

FS

Franz Steinbauer

★★★★★
STEINBAUER IT GmbH, Wies

I especially like the easy-to-use interface, the appealing analysis, and the customer-focused structure. The price-performance ratio is also excellent. Thank you!

Security assessment
December 2, 2025
Verified review
AO

Alexander Oberegger

★★★★★
CTO, smaXtec

CheckFix provides an excellent overview of the security posture of our IT landscape. We rely heavily on CheckFix to support changes in our IT and product areas from a security perspective, continuously monitor our security status, and detect vulnerab…

Continuous monitoring change management security
November 17, 2025
Verified review
SI

Sharif Ibrahim

★★★★★
eitk Elektro IT Kommunikations Gmbh, Premstätten

We used CheckFix to analyze our own domains and received a wealth of valuable insights on how to further improve our security. The report is clearly structured and highlights details you wouldn’t normally think of. We highly recommend CheckFix to any…

Security assessment actionable recommendations
November 12, 2025
Verified review
SS

Simon Schmelzer-Ziringer

★★★★★
EDV & IT Schmelzer-Ziringer, Trahütten

The software detects even the smallest security gaps that other tools often miss. Particularly impressive is the high speed of its analyses — without compromising accuracy. In addition, it’s extremely easy to use, allowing even less experienced users…

Identify security vulnerabilities easy to use
November 11, 2025
Verified review
FS

Franz Steinbauer

★★★★★
STEINBAUER IT GmbH, Wies

I especially like the easy-to-use interface, the appealing analysis, and the customer-focused structure. The price-performance ratio is also excellent. Thank you!

Security assessment
December 2, 2025
Verified review
AO

Alexander Oberegger

★★★★★
CTO, smaXtec

CheckFix provides an excellent overview of the security posture of our IT landscape. We rely heavily on CheckFix to support changes in our IT and product areas from a security perspective, continuously monitor our security status, and detect vulnerab…

Continuous monitoring change management security
November 17, 2025
Verified review
SI

Sharif Ibrahim

★★★★★
eitk Elektro IT Kommunikations Gmbh, Premstätten

We used CheckFix to analyze our own domains and received a wealth of valuable insights on how to further improve our security. The report is clearly structured and highlights details you wouldn’t normally think of. We highly recommend CheckFix to any…

Security assessment actionable recommendations
November 12, 2025
Verified review
SS

Simon Schmelzer-Ziringer

★★★★★
EDV & IT Schmelzer-Ziringer, Trahütten

The software detects even the smallest security gaps that other tools often miss. Particularly impressive is the high speed of its analyses — without compromising accuracy. In addition, it’s extremely easy to use, allowing even less experienced users…

Identify security vulnerabilities easy to use
November 11, 2025
Verified review

How can cyberattacks affect your company?

Examples of hacking attacks from practice

In the purchasing department – Emil alone in the office: It’s Friday afternoon, employees are already in weekend mode. Just then, an email from the CEO arrives. It’s a wire transfer order regarding an important potential contract. It absolutely must go out before the weekend. The sender is the CEO’s email address. Done immediately. What could go wrong? On Wednesday, Emil writes to the CEO that the important transfer for the new contract went out before the weekend. The CEO doesn’t know what contract Emil is talking about.

Identity theft via email by a hacker.

A simple attack made possible by inadequate mail server maintenance. The transfer went to the hacker.

CheckFix lists all mail servers and existing security vulnerabilities. Additionally, all to-dos to close the gaps.

At the bar – one CEO to another CEO: We have the most efficient marketing department. They’ve already implemented 5 different campaigns this year. It cost almost nothing. They use the coolest online platforms for it. The platform simply uses our data and we don’t need to do anything else. You just have to register there – it costs almost nothing!

The platform was operated by hackers. They collect passwords from important employees and use them for other applications and logins.

No overview of a jungle of company applications and their providers very quickly leads to data loss and very often to targeted attacks.

CheckFix gives you an overview of applications used and evaluates them. Superfluous or potentially dangerous applications can be eliminated from the company.

Dialogue between the sys-admin in a death metal T-shirt and the CEO in shirt and jacket: “We still need 2 ESXs so we can set up new servers with us. The new software doesn’t work with the old systems.”

“Why do we need a new one, we and our customers are still using the old one.”

“Yes, but the new one that should be switched to no longer runs on these, they’re outdated and there are no more updates for some components.”

“Ok, but the old ones will still run without problems?”

“Yes, of course.”

Outdated software has known vulnerabilities and enables automated attacks. These happen globally every second!

Unmaintained components or poorly configured software are like a honey pot for Winnie the Pooh.

CheckFix recognizes software and components used and informs you about their condition. CheckFix creates a list of recommended improvements for vulnerable components.

CTO to a promising applicant: “Remote is in our DNA. Of course, it’s appreciated when you also come to the office. We don’t just use open source, we also promote it. With AI, we’re now also developing our products even more efficiently. This requires being way ahead of state-of-the-art. Can you identify with that?”

“Yes, of course, my repos on Github have an average of 100 stars. On Discord and Twitter, I follow all the trendsetters in the industry.”

Sensitive information frequently (unintentionally) ends up in publicly accessible portals (like Github). These are immediately exploited by attackers.

Digitalization and remote work expand and simplify the attack surface for hackers. Who has the same security precautions at home as in the office?

CheckFix searches through publicly accessible information about your company and marks where action is needed.

In the purchasing department – Emil alone in the office: It’s Friday afternoon, employees are already in weekend mode. Just then, an email from the CEO arrives. It’s a wire transfer order regarding an important potential contract. It absolutely must go out before the weekend. The sender is the CEO’s email address. Done immediately. What could go wrong? On Wednesday, Emil writes to the CEO that the important transfer for the new contract went out before the weekend. The CEO doesn’t know what contract Emil is talking about.

Identity theft via email by a hacker.

A simple attack made possible by inadequate mail server maintenance. The transfer went to the hacker.

CheckFix lists all mail servers and existing security vulnerabilities. Additionally, all to-dos to close the gaps.

At the bar – one CEO to another CEO: We have the most efficient marketing department. They’ve already implemented 5 different campaigns this year. It cost almost nothing. They use the coolest online platforms for it. The platform simply uses our data and we don’t need to do anything else. You just have to register there – it costs almost nothing!

The platform was operated by hackers. They collect passwords from important employees and use them for other applications and logins.

No overview of a jungle of company applications and their providers very quickly leads to data loss and very often to targeted attacks.

CheckFix gives you an overview of applications used and evaluates them. Superfluous or potentially dangerous applications can be eliminated from the company.

Dialogue between the sys-admin in a death metal T-shirt and the CEO in shirt and jacket: “We still need 2 ESXs so we can set up new servers with us. The new software doesn’t work with the old systems.”

“Why do we need a new one, we and our customers are still using the old one.”

“Yes, but the new one that should be switched to no longer runs on these, they’re outdated and there are no more updates for some components.”

“Ok, but the old ones will still run without problems?”

“Yes, of course.”

Outdated software has known vulnerabilities and enables automated attacks. These happen globally every second!

Unmaintained components or poorly configured software are like a honey pot for Winnie the Pooh.

CheckFix recognizes software and components used and informs you about their condition. CheckFix creates a list of recommended improvements for vulnerable components.

CTO to a promising applicant: “Remote is in our DNA. Of course, it’s appreciated when you also come to the office. We don’t just use open source, we also promote it. With AI, we’re now also developing our products even more efficiently. This requires being way ahead of state-of-the-art. Can you identify with that?”

“Yes, of course, my repos on Github have an average of 100 stars. On Discord and Twitter, I follow all the trendsetters in the industry.”

Sensitive information frequently (unintentionally) ends up in publicly accessible portals (like Github). These are immediately exploited by attackers.

Digitalization and remote work expand and simplify the attack surface for hackers. Who has the same security precautions at home as in the office?

CheckFix searches through publicly accessible information about your company and marks where action is needed.

If attacks can look like this – How secure Is your company really?

Check your IT security for free – clearly, quickly, and from a hacker's perspective.

CheckFix Brand

Security Check from the outside

from the hacker’s perspective, without penetrating the system

CheckFix Brand

Clear overview through ratings

immediately recognize where action is needed

CheckFix Brand

To-Do List with AI support

concrete measures to work through

CheckFix Brand

Re-Check with report

usable for customers, auditors, or internal documentation

Frequently asked questions

CheckFix Brand

How can I find security vulnerabilities in my IT infrastructure?

There are two ways to find security vulnerabilities: through manual security audits or penetration tests – or through automated tools that systematically and regularly scan your IT for known weaknesses.

Proven methods for vulnerability discovery:

  • External scans from a hacker’s perspective (open ports, SSL/TLS, DNS, e-mail security)
  • Matching your software versions against CVE databases for known vulnerabilities
  • Reviewing the configuration of web servers and mail servers
  • Identifying outdated or forgotten systems (shadow IT)

The key distinction is between the internal and external perspective: internal audits check your systems from within – external scans show exactly what attackers see from the outside, the doors hackers actually use to break in. More than 70% of all cyberattacks start from the outside, which is why the external view matters so much.

CheckFix automates this external vulnerability discovery: within 24 hours, you receive a complete overview of all identified security vulnerabilities – including a prioritized to-do list with actionable remediation guidance that your own technician can implement.

CheckFix Brand

What exactly does CheckFix check?

CheckFix analyzes your entire external attack surface: domains, subdomains, email servers, open ports, SSL certificates, DNS configuration, web technologies, and mail security (SPF, DKIM, DMARC).

Specifically, CheckFix checks:

  • Your email addresses for faulty configurations
  • Known vulnerabilities (CVEs) in recognizable technologies
  • Open ports and outdated SSL/TLS protocols
  • DNS and mail security settings

Everything accessible from outside via your domain(s) is checked – exactly as hackers would use automated tools.

Important: CheckFix is not a virus protection replacement, but complements your existing security measures with an external perspective. Zero-day vulnerabilities (unknown security gaps) cannot be detected by any tool – CheckFix finds known vulnerabilities (n-day) before attackers exploit them.

CheckFix Brand

Who is CheckFix suitable for?

CheckFix is suitable for any company with an online presence: website, email server, cloud services, or APIs. Particularly benefiting are SMEs (professional IT security without 5-figure pentest budgets), NIS-2 obligated companies (technical compliance support and supplier verification), CRA-affected manufacturers (prove product security), and IT service providers/MSPs (customer verification and inventory monitoring).

CheckFix Brand

Can my technician fix the vulnerabilities themselves?

Yes! CheckFix was developed exactly for this purpose. Each vulnerability is explained with step-by-step instructions – understandable for any competent technician. So whoever set up your IT now also fixes the security gaps. Additionally, an AI assistant supports implementation for your specific environment (Plesk, cPanel, Azure, AWS, etc.). A system administrator doesn’t replace a cybersecurity expert – but CheckFix translates security knowledge so your technician can implement it without 5-figure consulting costs.

CheckFix Brand

What’s the difference between CheckFix and virus protection?

Virus protection (antivirus) protects your devices from inside against malware. CheckFix analyzes your company from outside – like a hacker. Both approaches complement each other: Antivirus defends against attacks that are already in the system. CheckFix prevents attackers from getting in at all by finding open doors (ports, misconfigurations, outdated software) before you get hacked. Optimal: Use both!

CheckFix Brand

How often should I perform CheckFix?

Best practice is twice yearly. Why? New vulnerabilities arise continuously (software updates, new subdomains, configuration changes). After each check, your team needs time to fix – the re-check shows measurable progress. Semi-annual checks correspond to common compliance cycles (ISO 27001, NIS-2) and keep you secure between pentests. This makes security a routine instead of a mandatory exercise.

CheckFix Brand
800+
domains tested
CheckFix Brand
70%
of all cyberattacks
start from outside
CheckFix Brand
85%
find critical vulnerabilities

Start Now

Protect your company before it’s too late

Start Free Security Check Now

100% free
No credit card required
Results in 24h
Contact

E-mail: office@checkfix.io

Phone: +43 660 77 24 524

secinto

secinto GmbH

Poststraße 3

8530 Deutschlandsberg

Austria

E-mail: office@checkfix.com

*Studie KPMG zur Cybersecurity in Österreich 2023