four ways we work with you
The right engagement depends on what you already know. If you have never had a test, start with the perimeter. If you have had five and they all came back clean, you probably want a red team.
- typical lead time
- 3–5 weeks
- smallest engagement
- 5 days
- retest
- Included, 90 days
- 01
penetration testing
Time-boxed, scoped testing of a system you already have, graded against exploitability rather than a scanner's opinion.
5–15 - 02
red teaming
An objective-led simulation of a real adversary, run against your detection and response rather than against a checklist.
4–10 - 03
cloud security review
A read of your AWS, Azure or GCP estate as an attacker reads it: identity first, blast radius second, compliance a distant third.
10–20 - 04
application security
Design review, threat modelling and code-level testing embedded with the team building the thing.
Retained,
a finding is exploitable or it is noise
Nothing reaches your report unless one of our testers has confirmed it works in your environment and written down how to reproduce it. Scanner output is where we start, not what we sell.
severity is argued, not calculated
Every finding carries a score and the reasoning behind it. If we have rated something lower than the tool did, you will see why, and you are free to disagree.
the retest is part of the price
We test every fix you make within ninety days and reissue the report. Charging twice to check our own recommendation is not a business model we want.
your engineers are the audience
Reports are written for the people who have to change the code. The board summary is one page at the front, and it is genuinely one page.
not sure which one you need
Describe what you are worried about and we will tell you which engagement answers it — including when the answer is that you do not need us yet.
