Based on an assessment
The badge cannot be bought; it is given to assets that went through a security test and whose critical findings were closed by retest. The record states which domain and which date it covers.
The badge shows that a specific asset passed a Doki assessment on a specific date and that the vulnerabilities found were verified as closed. It is not an official certificate or a security guarantee; anyone can verify its scope, date and validity.
The badge cannot be bought; it is given to assets that went through a security test and whose critical findings were closed by retest. The record states which domain and which date it covers.
When a visitor clicks the badge, the verification page on Doki opens and shows the current status: valid, expired or revoked. A copied image cannot pass this check.
Security is not static, so the badge has an end date. Renewal requires a fresh assessment. A serious incident or a change of scope can lead to the badge being suspended.
Every stage from application to renewal is recorded and reflected on the verification page.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
We assess the current state against agreed criteria and note gaps with evidence.
We close findings together with your team and document each change.
We check the result with an independent eye and keep the verification record.
We reassess before the period ends and renew if the conditions are met.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectNo. The badge shows that a defined scope was assessed on a given date and that the findings were closed; it does not guarantee that no vulnerability will appear later. That is why it is time-limited and its scope is stated clearly on the verification page.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Scope, time window and methods are agreed in advance; risky steps require your separate approval.
Tell us what you need; we will define the scope together.