Approach

How an engagement runs.

Every engagement follows the same five stages. You get named practitioners, a weekly status update, and a report written by the person who did the testing.

Scoping

We start with your team: what the board is worried about, what the engineers work around, what last year's audit did and did not catch. Scope, rules of engagement and success criteria are agreed in writing before any testing begins.

Mapping

We document the environment and the threat model: attack paths, blast radius, critical assets, and the low-value systems that make them reachable.

Execution

Testing, review, engineering or incident support, depending on scope. Weekly status, and any critical finding reported the day we confirm it — never held back for the report.

Reporting

Two documents: a management summary with findings ranked by business risk, and a technical appendix with reproduction steps and a fix for each. Both written by the practitioner who did the work.

Remediation support

We stay available while your team fixes the findings, and can retest them on request once the work is done.

What we refuse

Some work we will not take.

It matters as much what we decline as what we accept. We will tell you honestly, at the first conversation, if we are not the right practice for your need — and who we would call in our place.

  • Engagements against unwitting or non-consenting parties.
  • Offensive work without clear legal authority.
  • Certification work where there is no intent to remediate findings.
  • Work we cannot staff with experienced practitioners.
  • Contracts that require us to name clients we cannot name.

Confirm