HOW WE WORK

We do not ask you to trust a logo

Every engagement runs on public standards. All of them are free to read. What is scarce is the discipline to follow them the same way every time.

PTES OWASP WSTG OWASP MASTG NIST SP 800-115 MITRE ATT&CK

The engagement, step by step

01

Scoping call

Forty-five minutes, free. We agree what is in scope, what is out, and which product fits. You get a fixed price and a delivery date in writing.

02

Signed authorization

No packet leaves our side before the letter of authorization and the rules of engagement are signed by someone entitled to sign them.

03

Testing window

You know the dates and the source addresses. Emergency stop works around the clock, and anything fragile is tested outside business hours by prior agreement.

04

Report and debrief

Delivered on the date in the contract, walked through twice: once with your engineers, once with your leadership. If it is late, you pay ten percent less.

05

Retest within 30 days

You fix, we verify, the report is reissued clean — included in the price, evidence your auditor accepts.

YOUR DATA

Collected minimally, destroyed on schedule

We collect the minimum the engagement needs, store it encrypted, and destroy everything thirty days after the engagement closes — retest included. The obligation is written into the contract. No report reaches you without review by a second member of the core team.

CHECK US THE WAY WE CHECK YOU

This site is part of the audit

Static site, zero third-party scripts, no trackers, CSP without unsafe-inline, HSTS with preload, signed mail policy. Run it through Mozilla Observatory or SSL Labs — that screenshot is our first reference.

The first call costs nothing.

Book a scoping call