Clearing a compromised site and closing the way in, priced after we have looked
Request a quote
Quoted per project
Scope varies too much for a fixed price. We quote in writing, free.
The four questions this page answers
1
What you buy
Remote work on a website that has been hacked, defaced, or is serving content it should not be. We remove what was injected, work out how it got in, and close that route where it is within our reach.
2
What you get
5 deliverables, listed in full below
A cleaned site returned to service, with injected content removed
A written incident summary naming what was found, what was removed and how it most likely got in
A record of every credential and key rotated during the work
Scoped and priced in writing first. Nothing is charged for the quotation.
CUSTOM BUILD
4
How long it takes
Triage normally begins within one business day of receiving access; cleanup timing is confirmed in the written quote
Measured from the point everything under “what we need from you” is with us, not from the moment you pay.
An incident runbook: detection through escalation to a resolved, written-up close. Illustrative interface concept — not a screenshot of a client deployment.
What is this, in plain English?
Remote work on a website that has been hacked, defaced, or is serving content it should not be. We remove what was injected, work out how it got in, and close that route where it is within our reach.
This is quoted rather than sold at a fixed price, because no two compromises are the same size. A single injected file is an afternoon. A site with a backdoor in every directory, no clean backup and a host who has suspended the account is a different job entirely. We triage first, tell you in writing what we found and what the cleanup will cost, and you decide before any billable work begins.
The problem it solves
Your site is warning visitors away, search results show pages you did not write, and your hosting provider has suspended the account until it is dealt with.
If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.
What you get
The concrete things that exist at the end and that you own.
5 deliverables
A cleaned site returned to service, with injected content removed
A written incident summary naming what was found, what was removed and how it most likely got in
A record of every credential and key rotated during the work
The list of changes made to close the entry point, with anything outside our control clearly marked
A written recommendation of what to do next, priced separately if you want us to do it
What's included
The work covered by the figure in the buy box, at no extra cost.
Triage of the compromise and a written quote
Removal of injected files, database entries and scheduled tasks
Core file comparison against a clean platform copy
Backdoor and persistence search across the accessible file system
Credential, key and salt rotation
Safe-browsing review request and a written incident summary
Everything listed here is delivered as part of this product. Nothing on this list is aspirational.
Triage and a written quote before any billable cleanup starts
Removal of injected files, database content, scheduled tasks and rogue accounts
Platform core files compared against a clean copy of the same version
Search for backdoors, web shells and other persistence left behind for a return visit
Credentials, keys and salts rotated across the accounts we can reach
Review request submitted to browser and search safe-browsing services where a listing exists
A written incident summary of what was found, what was removed and what remains uncertain
How it works
The delivery sequence from order to handover.
1
Triage
With your written authorisation and access, we establish what has happened, how far it has spread and whether a clean backup exists.
2
Quote in writing
You receive a written scope and price, including a plain statement of whether cleaning is sensible or a rebuild is the better answer. Nothing billable happens until you accept.
3
Contain and clean
The site is taken offline or put behind a holding page, injected content is removed, and core files are restored from a clean copy.
4
Close the entry point
Credentials are rotated, the vulnerable component is updated or removed, and access is tightened where we control it.
5
Report and hand back
You receive the incident summary, the site returns to service, and we set out what would reduce the chance of it recurring.
Delivery & fulfilment
Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.
CUSTOM BUILDHow this is delivered
1We scope it with youWe work through what the build has to do, what it connects to and what would make it a success.
2We quote in writingA written proposal with deliverables, milestones, timeline and price. Free, and no obligation.
3We build and hand over remotelyOn acceptance the work is built to the agreed milestones and handed over with its credentials and documentation.
Scoped and priced in writing first. Nothing is charged for the quotation. Typical turnaround: Triage normally begins within one business day of receiving access; cleanup timing is confirmed in the written quote.
Delivery method
Custom Build
Expected delivery time
Triage normally begins within one business day of receiving access; cleanup timing is confirmed in the written quote
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.
Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.
What we need from you
Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.
Written authorisation from the site owner before we access anything
Full hosting, file and platform administrator access, including database access
Any suspension or abuse notice your host has sent you
Agreement that the site may be taken offline during the work
A named decision-maker who can accept the quote without a committee
Who this is for
Businesses whose website has been defaced or is redirecting visitors
Owners whose host has suspended an account for malicious content
Sites flagged by a browser or a search engine as unsafe
Companies who found unfamiliar administrator accounts on their platform
Just as plainly as the list above: the things this package is not.
Rebuilding a site too badly compromised to clean safely, which is quoted as a separate project and is not part of this work
Recovery of content that was destroyed and never backed up anywhere
Any guarantee against reinfection, particularly where the entry point sits in a staff device, a shared password, a neighbouring site on the same hosting account, or software whose vendor has not published a fix
Forensic investigation to an evidential standard, and any legal or regulatory notification on your behalf
Hosting, licence and scanning tool costs, which you pay those providers directly
Ongoing monitoring after the cleanup, which is a separate subscription
Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.
FAQs
Why is there no fixed price?
Because the size of the job is genuinely unknowable until someone looks. Two sites with identical symptoms can be an hour apart or a week apart, depending on how long the compromise went unnoticed and whether a clean backup exists. Quoting a fixed fee would mean either overcharging the simple cases or abandoning the difficult ones halfway, so we triage, quote in writing, and let you decide.
Can it come back after you have cleaned it?
Yes, and we will not pretend otherwise. If the way in was a password also used on a staff member’s infected computer, a neighbouring site on the same shared hosting account, or a plugin whose vendor has not published a fix, then the route back exists outside anything we control. The incident summary states plainly where we believe the remaining risk sits, so you can act on it.
What if the site cannot be safely cleaned?
Sometimes the honest answer is that a rebuild from known-good content is faster, cheaper and safer than picking through thousands of modified files. If we reach that view during triage we say so, and the rebuild is quoted as its own project rather than folded into this one. You are never billed for cleanup work we have advised against.
Do you handle telling our customers or a regulator?
No. Whether an incident must be notified, to whom and within what period is a legal question that depends on where you operate and what data was involved. We give you the factual summary of what happened, and you should take legal advice on your obligations before notifying anyone.
Refund & cancellation
What happens if you change your mind, and what happens to money already paid.
Nothing is charged for the quote
Requesting a quote costs nothing and commits you to nothing. Refund and cancellation terms are agreed in writing as part of the proposal, before any money changes hands.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.