Approach

Security testing should never surprise you. You know what we will test, when, from where, and what happens the moment we find something serious.

Five stages

How every engagement runs.

  1. 01

    Scope

    A call to understand your systems, what matters most to the business, and any deadline driving the work, such as a client security questionnaire or an audit. You get a written scope and a fixed quote.

  2. 02

    Authorise

    Testing starts only after you sign a written authorisation naming the targets, dates and source IPs. We sign an NDA and agree an emergency contact on both sides.

  3. 03

    Test

    Automated discovery narrows the ground; the findings come from manual testing. If we find something critical, such as exposed customer data or a path to take over the system, we tell you straight away rather than holding it for the report.

  4. 04

    Report

    An executive summary, then every finding with its severity, steps to reproduce, evidence and a specific fix. We walk your engineers through it on a call and answer questions while they remediate.

  5. 05

    Retest

    Once fixes are deployed we retest every finding and reissue the report with its current status, which you can share with customers or auditors as evidence of closure.

Ground rules

The rules we test by.

These apply to every engagement, whatever its size.

R1

Written authorisation first

No testing starts until you have signed an authorisation naming the targets, dates and our source IPs.

R2

Scope is a hard boundary

We test only what is in the signed scope. If we find a path into something outside it, we stop and ask.

R3

Critical issues the same day

Anything that exposes customer data or allows a takeover is reported to your contact immediately, not saved for the report.

R4

Production handled with care

On live systems we avoid destructive tests and denial of service, and agree testing windows in advance.

R5

Evidence kept to the engagement

Credentials, data and screenshots gathered during testing are stored encrypted, shared only with the people on your engagement, and deleted at the end unless you ask us to keep them.

R6

Reports shared securely

Reports contain exploit detail, so we deliver them through an agreed secure channel, never as a plain email attachment.

Severity

How findings are rated.

Each finding gets a CVSS score and vector, so the rating can be checked independently. We then adjust for your context: the same flaw on an internal admin tool and on a public payment page is not the same risk, and the report says why.

  • CriticalDirect compromise of the system or its data, exploitable now with little effort.
  • HighSerious impact such as access to other users’ data, needing little or no special access.
  • MediumReal risk that needs specific conditions, or limited impact on its own.
  • LowHardening gaps and minor issues worth fixing in normal maintenance.
  • InfoObservations and good-practice recommendations with no direct risk.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope