Kovyr
See what's hiding in plain sight.
How exposed is your business?
Enter your website and get a free security grade in seconds — the same things an attacker or your cyber-insurance auditor can see.
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
What's behind your grade
The grade isn't the point. What it protects is.
The scan looks at the same things an attacker, a cyber-insurer, or an auditor would check first. Here's what's behind the letter — in plain English.
Can someone impersonate your email?
Whether a scammer can send email that looks exactly like it came from your business — how fake-invoice and wire-fraud scams start. It burns your customers' trust, not just yours.
Is your data protected as it travels?
Whether the connection to your website and customer portals is properly secured and up to date. If it's not, information can be intercepted — and it's the first red flag an insurer or a sharp customer notices.
What are you exposing to the internet?
What an outsider can see about your setup without touching anything private. Every exposed service is a door, and automated attacks look for them around the clock — small businesses are the easy targets, not the exception.
Have your logins turned up in a breach?
Whether your business email addresses show up in known data breaches. Leaked passwords get reused to break into accounts — one old breach can hand someone the keys.
A grade is a snapshot. We turn it into an ongoing set of eyes.
You get an outside expert who never sleeps — without hiring one.
The must-have, not the nice-to-have
We produce the security documentation regulated businesses are legally required to have.
HIPAA requires a written Security Risk Analysis. The FTC Safeguards Rule requires a Written Information Security Program. Most small practices and firms don't have one — until an auditor, an insurer, or a breach asks. Kovyr writes it, keeps it current, and monitors your exposure so it stays true. Compliance is the foundation; monitoring rides on top.
Find your requirement
Dental & medical
HIPAA Security Risk Analysis
HIPAA requires a documented risk analysis — the item OCR asks for first. We're your outside risk-analysis provider: your practice names its own Security Official, and we never touch ePHI.
The HIPAA packet →
Tax & financial
FTC Safeguards WISP
The FTC Safeguards Rule requires a Written Information Security Program — and your PTIN renewal now asks whether you have one. We write it, and keep it current.
The WISP packet →
Insurance agencies
Written Information Security Program
Utah insurance rule R590-216 requires licensed agents to maintain a written security program. Independent agents especially are on their own — not covered by a carrier's corporate program. We write it, and keep it current.
The insurance WISP →
Not regulated — trucking, retail, auto, agriculture? You still have real risk. Monitoring from $99/mo.
Who you're working with
Kendall Sorenson
IT technician · Richfield, Utah
Real, hands-on experience with network security, DNS and email infrastructure, and PCI remediation for local businesses. When you call Kovyr, you reach a competent human who knows your setup — not a faceless tool or an overseas ticket queue.
Get the documentation you're required to have.
Start with a free scan, or book your Compliance Assessment — quoted per business, from $399.