Doelve™ / Queens, New York City / Digital presence + digital security
The website that gets you found is the same website that gets you targeted.
Doelve builds your online presence and secures it. Same team, same project, one invoice — because the two were never actually separate jobs.
$497 flat · 5 business days · refundable for 14 days · credited if you hire us
Two founders · Founded 2026 · Taking our first clients now
Presence
- 1Your Google Business Profile — where most of your walk-ins actually start.
- 2The words on this page, and what they ask people to do next.
- 3How fast it loads on a phone with two bars.
Security
- 4Whether a stranger can send email that looks like it came from you — and the three DNS records that stop it.
- 5Whether the login that runs all of this has a second step — and how long it takes to add one.
- 6Whether the backup has ever actually been restored — and what it costs to test it once.
Nobody owns the whole problem.
Small businesses hire two kinds of companies. Neither one covers the other's blind spot.
A site that looks good and shows up on Maps. Then handed you a login and moved on. Nobody asked who else has that login, whether anyone can restore the site, or whether your domain can be spoofed.
Antivirus and a password rule. And no opinion on whether your site loads on a phone, ranks in your neighborhood, or looks like a business people trust.
One business. Two half-owners. And a gap between them where the incident happens.
That's not two problems. It's one problem, split between two invoices.
Getting found and getting hit run on the same infrastructure. Your domain name is your marketing asset and your attack surface. Your booking form collects leads and collects liability. Your Google listing brings customers in — and if someone else claims it, it sends them somewhere else.
Seven checks. This is the list, not your results.
Every Exposure Report runs the same seven checks and reports them in plain English. Here they are, before you pay for anything.
| Check | Why it matters |
|---|---|
| 01Email that can't be faked | Whether SPF, DKIM and DMARC are published and enforcing. Without them, a stranger can send your customers an invoice with your business name on it. |
| 02Encryption, end to end | Whether HTTPS is enforced and HSTS is set, so a visitor on public Wi-Fi can't be pushed onto an unencrypted copy of your site. |
| 03Two-step login coverage | Which of your accounts have a second step and which don't. We start with the two everyone misses: the domain registrar, and the mailbox that resets everything else. |
| 04A backup that has been restored | Whether backups exist, where they live, and whether anyone has ever restored one. A backup nobody has tested is a rumor. |
| 05Patch state | What software is actually running your site, how old it is, and which of it can't be updated on your schedule. |
| 06What's exposed | Which services and admin pages face the open internet, and what your site's response headers say about it. |
| 07Vendor and app access | Every outside company holding your data or your money, and what each one can see. |
Status: awaiting authorization. These are the checks, not your results. We read only what is already public, and we do not scan, log in to, or test any system without a signed authorization naming the assets and the time window.
The Doelve Exposure Report
For $497 we show you what a stranger can learn about your business from the outside in an afternoon — and what it would cost to close each gap. You keep the report either way.
What you get
- A written report in plain English. Every finding, what it means, what it would take to exploit it, and what it costs to fix.
- A ranked fix list. Each item marked you can do this, we can do this, or this needs a vendor — with the effort estimate attached.
- A 30-minute walkthrough call. We read it with you and answer whatever you want to ask.
- Fixed prices for everything we'd fix. Quoted from the report, in writing, before any work starts.
- Yours to keep. Take it to another shop for a second opinion. We'd rather you did that than hire us blind.
The $497 comes off the price of anything you hire us for within 30 days. And if the report turns up nothing worth fixing in your email authentication, your account access, your backups or your website security, we refund it in full and tell you honestly that you're in better shape than most businesses we see.
Two pillars. Sold together, on purpose.
You can buy either one alone. Most people shouldn't. Here's everything that's actually on the table.
Get found. Look like the business you actually are.
- Website design and build — fast on a phone, readable on a bad connection, built to WCAG 2.2 Level AA so a customer with low vision or a keyboard instead of a mouse can still book you.
- Local search and Google Business Profile — claimed, verified, filled in and defended. Hours, service area, photos, and the categories that decide whether you show up in the map pack.
- Brand and visual identity — logo, type, colour, and the rules that keep them consistent across a sign, a truck and a screen.
- Photo and video — shot for your business, not pulled from a stock library three of your competitors already used.
- Copy — what your homepage says in the first eight seconds, and what it asks people to do next.
And
Make the thing you just built hard to take away from you.
- Security assessment — we inventory what you actually own: domains, logins, hosts, plugins, vendors. Most owners have never seen this list written down.
- Website and domain hardening — patching, admin access, removing the plugins nobody uses, and locking the registrar so the domain can't be transferred out from under you.
- Email that can't be faked — SPF, DKIM and DMARC published and moved to enforcement, with the reports read by a human for the first 60 days so your real mail doesn't break. To be exact about the limit: this stops someone spoofing your exact domain. It does not stop a lookalike domain, and it does not stop mail sent from your own account after somebody steals the password.
- Two-step login everywhere — email, banking, the website, the point of sale, payroll. Rolled out for your whole staff, with recovery codes stored somewhere that isn't a sticky note.
- Backups that have been restored — set up off-host and versioned, then one restored in front of you and timed, with a written recovery point and recovery time you agreed to.
- Phishing awareness training your staff won't hate — 60 minutes, real examples from your industry, English or Spanish, no fake shame emails.
- Vulnerability assessment — scheduled, hand-validated, and ranked by what actually gets exploited instead of dumped on you as a raw list. This is assessment, not exploitation; penetration testing is a separate engagement with its own signed authorization.
- If-it-happens plan — who you call, in what order, what you say to customers, and where the phone numbers live when your email is down.
- Vendor and app review — the eleven tools your business quietly runs on, and what each one can see.
Not sure which half you need? That's normal, and it's what the report is for.
Four steps. No mystery, no retainer trap.
You'll know what we're doing, why, and what it costs before anything changes.
-
Call. Thirty minutes, free.
You tell us what you have. We tell you the three things we'd fix first. You leave with those three whether or not you hire us. If we think you don't need us yet, we'll say so on this call.
-
Exposure Report. Five business days, $497.
Written findings across both halves, ranked by what actually gets exploited, each one priced. Yours to keep. Refundable in full for 14 days. Credited toward anything you hire us for within 30.
-
Fix. Fixed scope, fixed price, agreed in writing before we touch anything.
Presence work, security work, or both. You approve every change to a live system, and we take a restorable backup first.
-
Hand over.
Every account is in your name, at your email, with your recovery codes. You get the documentation. If you leave us, you leave with everything.
That last one is a policy, not a promise. Owning your own accounts is the single most valuable security control a small business has.
We didn't invent our own checklist.
There is published, public guidance for exactly this. We work from it, we cite it, and you can read it yourself.
Fifty-six safeguards the Center for Internet Security calls essential cyber hygiene, written specifically for organizations with no security staff. We work the list and hand you the sheet with every safeguard marked implemented, compensated, or accepted with a reason.
The U.S. standard for organizing security work into six functions: Govern, Identify, Protect, Detect, Respond, Recover. We use it to structure your assessment so a future insurer, auditor or enterprise client recognizes the format immediately.
The accessibility standard. It's what keeps your site usable for a customer with low vision, tremors, or a keyboard instead of a mouse. New York is one of the highest-volume venues in the country for website accessibility suits, and the fix costs almost nothing at build time and a great deal afterward.
These are standards we work to, not certifications we hold. NIST does not certify anyone. There is no such thing as HIPAA certification and no vendor can hand you compliance. Doelve is not SOC 2 or ISO 27001 certified, is not a PCI Qualified Security Assessor, and is not a law firm. We're a two-person company and we'll tell you exactly what we are.
Four commitments. In writing, in every contract.
-
Fixed price before we start.
No hourly creep, no additional discovery, no number that moves once agreed. If we underestimated, that's ours to absorb.
-
Every account in your name.
Domain, host, Google, analytics, email. You are the owner. We're a user you can remove yourself, in one click, without calling us.
-
No lock-in.
Month-to-month on anything ongoing. Cancel by email with thirty days' notice. We hand over credentials and a written runbook within five business days, and answer transition questions for thirty days after that, free.
-
Plain-English reporting.
If a report needs a translator, it isn't finished.
We will not promise you a Google ranking, a revenue number, or that you will never be breached. Nobody can make a business unhackable, and anyone who tells you otherwise is selling something. What we promise is the work, on a date, to a published standard — and the Exposure Report refunded in full if it wasn't worth what you paid for it.
Two people. You'll deal with both of us.
No account manager, no offshore ticket queue. The people who scope the work are the people who do it.
Samuel Mendieta Brito
Security and buildM.S. in Cybersecurity from Touro University and a B.E. in Electronic Engineering. Three-plus years running network operations for Claro Dominicana, a national telecom — the job where a bad night takes service down for a lot of people.
I do offensive security work: I test systems by attacking them in a lab, which is the only honest way to know whether a defense holds. That's the perspective I bring to a business with fourteen employees. Not a compliance checklist — the actual question of how someone would get in.
Spanish, English and French. Queens.
samuelmendieta.com — I built it and I hardened it. Run your own tools against it.
Victor Silverio
Brand, content, and your accountFilm, photography and visual storytelling. Victor shoots the work — the photographs of your space, the video of what you actually do, the identity that makes a stranger trust you before they've read a word.
He also handles the relationship. When you have a question about your project, he's the call.
victorsart.com — his own film and photography work.
Doelve started in 2026. We'll say that plainly rather than let you find it out later.
What it means for you: the two people on this page are the two people who do your work. Nothing gets handed to a junior, nothing gets offshored, and nothing gets lost between an account manager and a technician, because there is neither.
What it also means: we're building a reputation from zero, in a city where our clients talk to each other. There is no client list long enough for us to be careless with any one of them. That isn't a slogan. It's arithmetic.
This row is reserved.
Doelve opened in 2026 and has not yet completed a client engagement. When we do, the client's name goes here, with their permission, and nothing else goes here.
We are not going to put a wall of logos on this page that belongs to somebody else's client list.
The first businesses we work with get our full assessment and remediation at a founding rate, direct access to both founders rather than a junior, and that rate held for twenty-four months if you stay on monthly care.
What we ask back: permission to describe the work publicly, with your name, once it's done and you're happy with it. And twenty minutes on a call telling us honestly what we got wrong.
If you'd rather stay anonymous, say so and you still get the rate — we'll write it up as "a fourteen-person law office in Forest Hills" instead. We would rather have the work than the logo.
Hablamos español. De verdad.
Samuel es hispanohablante nativo. Toda la conversación — la revisión, el informe, el contrato y el soporte — puede ser en español, de principio a fin. Sin traductor, sin sobrino que ayuda, sin adivinar.
Si alguna vez le explicaron algo técnico en inglés y usted asintió sin entender: eso no pasa aquí.
Full service in Spanish — the call, the report, the contract and support. Not a translated page: an actual conversation.
The things owners actually say on the first call.
We're small. Is anyone really targeting us?
Almost nobody is targeting you personally. That's the point. Most of what hits a small business is automated: software scanning every domain on the internet for an old plugin, or a login with no second step, or a domain with no DMARC record. It doesn't know your name and it doesn't care what you do. You're not a target. You're a match.
What does it cost?
The Exposure Report is 497 dollars flat, refundable in full for 14 days, and credited toward anything you hire us for within 30 days. Everything after it is quoted from the report as a fixed price, item by item, before any work starts. We don't publish a number for the build because a five-page site for a salon and a security cleanup for a five-person law office are not the same job.
Do we have to buy both the website and the security?
No. You can hire us for either half. We'll tell you honestly if the half you're asking for isn't the half you need.
Someone else built our website. Will you work on it?
Usually yes. WordPress, Squarespace, Wix, Shopify or a custom build. If your site is on something we can't safely maintain, that goes in the report instead of quietly costing you money to find out.
Will you touch our live site without telling us?
No. Nothing changes on a live system without your written approval, and we take a restorable backup first. The Exposure Report itself only reads what is already public: DNS records, response headers, your public listings, and what your pages return to any visitor. We do not log in to anything, test anything, or attempt access. Active testing never happens without a separate signed authorization naming the assets and the time window.
Someone can send email that looks like it came from us. How?
By default, email does not verify who sent it. Unless your domain publishes records saying who is allowed to send on its behalf, a stranger can put your business name and address on a message to your customers or your bookkeeper and ask for a wire, a password or an invoice payment. Three DNS records fix it: SPF, DKIM and DMARC. It is usually an afternoon of work and it is the first thing we check. To be exact about the limit: enforcing DMARC stops someone spoofing your exact domain. It does not stop a lookalike domain, and it does not stop mail sent from your own account after somebody steals the password.
We already have an IT guy.
Good. Keep him. He handles your machines and your network. We handle what is public: the site, the domain, the listings, the email authentication and the accounts. Tell us who he is and we will stay out of his lane, or bring him on the call.
Our last web person disappeared and we don't have our own passwords.
This is the most common thing we hear. You can usually get your domain back through the registrar with proof that the business owns it. Ask us on the call and we will walk you through it whether or not you hire us. As for us: every account we set up is in your name, on your card, from day one. We hold access you can revoke yourself, and every engagement ends with a written runbook. You should not have to trust that we will still be here. You should be structurally fine if we are not.
Request the Exposure Report
Eight fields. Two of them are optional. You'll hear from a person, not a queue.
Got it. Check your inbox.
We sent a confirmation to the address you gave us. Your report comes back within five business days. If you don't see the confirmation in ten minutes, check spam — and tell us, because that's a deliverability problem worth knowing about.
No credit card. No account. We don't sell or share your information. This form posts to Web3Forms and nowhere else.
Prefer email? hello@doelve.com — we answer within one business day.
Queens, New York City. Hablamos español.