Get in touch
Request a consultation
Tell us what you need assessed. We’ll come back with scope, timeline, safeguards and deliverables — no obligation, and no testing of any kind until it’s agreed in writing.
[email protected]The process
What happens next
Every engagement follows the same path, whether it’s a single application test or a full red team.
01 You tell us what needs testing
An application, an API, a cloud estate, a network, your people — or you're not sure yet, which is also a fine place to start.
02 We scope it with you
Scope, safeguards, environment (staging by default), timing and deliverables are agreed in writing before any testing begins.
03 Testing runs to that agreement
Most assessments run one to three weeks. Red team engagements run four to eight. Anything higher-risk is flagged and scheduled with your team.
04 You get findings you can act on
Executive summary, CVSS-rated technical findings, evidence and remediation guidance — with optional retesting to confirm the fix held.
Before you write
Helpful things to include
None of this is required — it just gets us to an accurate scope faster.
- Which of our 15 services you're interested in, if you know
- Roughly how large the target is (endpoints, users, hosts, cloud accounts)
- Whether testing must happen against production or staging is available
- Any compliance driver behind the request (PCI DSS, ISO/IEC 27001, SOC 2)
- Your target timeline, and any date you're working back from
- Whether you'd want post-remediation retesting included