Security testing should never surprise you. You know what we will test, when, from where, and what happens the moment we find something serious.
How every engagement runs.
- 01
Scope
A call to understand your systems, what matters most to the business, and any deadline driving the work, such as a client security questionnaire or an audit. You get a written scope and a fixed quote.
- 02
Authorise
Testing starts only after you sign a written authorisation naming the targets, dates and source IPs. We sign an NDA and agree an emergency contact on both sides.
- 03
Test
Automated discovery narrows the ground; the findings come from manual testing. If we find something critical, such as exposed customer data or a path to take over the system, we tell you straight away rather than holding it for the report.
- 04
Report
An executive summary, then every finding with its severity, steps to reproduce, evidence and a specific fix. We walk your engineers through it on a call and answer questions while they remediate.
- 05
Retest
Once fixes are deployed we retest every finding and reissue the report with its current status, which you can share with customers or auditors as evidence of closure.
The rules we test by.
These apply to every engagement, whatever its size.
Written authorisation first
No testing starts until you have signed an authorisation naming the targets, dates and our source IPs.
Scope is a hard boundary
We test only what is in the signed scope. If we find a path into something outside it, we stop and ask.
Critical issues the same day
Anything that exposes customer data or allows a takeover is reported to your contact immediately, not saved for the report.
Production handled with care
On live systems we avoid destructive tests and denial of service, and agree testing windows in advance.
Evidence kept to the engagement
Credentials, data and screenshots gathered during testing are stored encrypted, shared only with the people on your engagement, and deleted at the end unless you ask us to keep them.
Reports shared securely
Reports contain exploit detail, so we deliver them through an agreed secure channel, never as a plain email attachment.
How findings are rated.
Each finding gets a CVSS score and vector, so the rating can be checked independently. We then adjust for your context: the same flaw on an internal admin tool and on a public payment page is not the same risk, and the report says why.
- CriticalDirect compromise of the system or its data, exploitable now with little effort.
- HighSerious impact such as access to other users’ data, needing little or no special access.
- MediumReal risk that needs specific conditions, or limited impact on its own.
- LowHardening gaps and minor issues worth fixing in normal maintenance.
- InfoObservations and good-practice recommendations with no direct risk.
Let's strengthen your security — get in touch.
- 01Tell us what you need and by when
- 02We reply with questions or a written scope
- 03You get a fixed quote before any work starts