Skip to content

Get in touch

Request a consultation

Tell us what you need assessed. We’ll come back with scope, timeline, safeguards and deliverables — no obligation, and no testing of any kind until it’s agreed in writing.

[email protected]

The process

What happens next

Every engagement follows the same path, whether it’s a single application test or a full red team.

  1. 01 You tell us what needs testing

    An application, an API, a cloud estate, a network, your people — or you're not sure yet, which is also a fine place to start.

  2. 02 We scope it with you

    Scope, safeguards, environment (staging by default), timing and deliverables are agreed in writing before any testing begins.

  3. 03 Testing runs to that agreement

    Most assessments run one to three weeks. Red team engagements run four to eight. Anything higher-risk is flagged and scheduled with your team.

  4. 04 You get findings you can act on

    Executive summary, CVSS-rated technical findings, evidence and remediation guidance — with optional retesting to confirm the fix held.

Before you write

Helpful things to include

None of this is required — it just gets us to an accurate scope faster.

  • Which of our 15 services you're interested in, if you know
  • Roughly how large the target is (endpoints, users, hosts, cloud accounts)
  • Whether testing must happen against production or staging is available
  • Any compliance driver behind the request (PCI DSS, ISO/IEC 27001, SOC 2)
  • Your target timeline, and any date you're working back from
  • Whether you'd want post-remediation retesting included