Approach
How an engagement runs.
Every engagement follows the same five stages. You get named practitioners, a weekly status update, and a report written by the person who did the testing.
Scoping
We start with your team: what the board is worried about, what the engineers work around, what last year's audit did and did not catch. Scope, rules of engagement and success criteria are agreed in writing before any testing begins.
Mapping
We document the environment and the threat model: attack paths, blast radius, critical assets, and the low-value systems that make them reachable.
Execution
Testing, review, engineering or incident support, depending on scope. Weekly status, and any critical finding reported the day we confirm it — never held back for the report.
Reporting
Two documents: a management summary with findings ranked by business risk, and a technical appendix with reproduction steps and a fix for each. Both written by the practitioner who did the work.
Remediation support
We stay available while your team fixes the findings, and can retest them on request once the work is done.
Some work we will not take.
It matters as much what we decline as what we accept. We will tell you honestly, at the first conversation, if we are not the right practice for your need — and who we would call in our place.
- Engagements against unwitting or non-consenting parties.
- Offensive work without clear legal authority.
- Certification work where there is no intent to remediate findings.
- Work we cannot staff with experienced practitioners.
- Contracts that require us to name clients we cannot name.