Engagement
Nothing starts without your signature
Offensive testing is only legitimate when it’s authorised, scoped and bounded in writing. This page is the whole arrangement.
Rules of engagement
What we agree before anything runs
These go in the agreement. They are the rules a manual penetration testing firm works under.
Authorisation first
Nothing runs until the agreement and a signed authorisation are both in place.
Named scope only
We test the targets named in the agreement. Third-party services are out: only their provider can authorise those.
An agreed window
You name the window and we stay inside it. A test nobody is expecting during release week becomes an incident.
A named contact on each side
Someone on your side who can answer a question or call a halt. One on ours.
Nothing destructive
No denial-of-service, no deleting or corrupting data, no degrading your service to make a point. Anything we can’t show safely gets described.
Enough to prove it, and no more
We take only what demonstrates the finding, and record that in the report. No datasets pulled, none kept.
We stop and call you
Something critical, or a sign somebody else got there first, and testing stops. You hear from us the same day.
Production is your call
Staging that mirrors production is usually enough. Production itself is fine, with the constraints agreed in writing.
Where this page and the signed agreement disagree, the agreement wins.
The flow
Four steps, in this order
From first contact to a report in your hands.
- 01
Sign the agreement and the authorisation
The agreement sets the commercial terms; the authorisation names the targets and the window. Nothing happens before both are signed.
- 02
A discovery call
Which parts carry real risk, which roles and tenants exist, what would genuinely hurt. In white-box this is the hour of engineers’ time we ask for.
- 03
You provide the environment and access
Test credentials for each role, network reachability, and any allowlisting your WAF wants. Source access too, in white-box. Nothing is installed on your side — no agent, no collector — and if your source cannot leave your network, the scanner is self-contained enough to run where the code already lives.
- 04
The first report
A day to several weeks. You get a real estimate after the discovery call.
Timing
How long the first report takes
What decides it is the application, and how much proving a finding takes.
Contained app in black-box at the fast end; a large white-box system at the slow end.
Your data
The environment is destroyed. The report is all that survives.
The safest place for your source code is somewhere that stops existing.
- A fresh container per test
- Never shared with another customer, never reused for your next test.
- Your filesystem is never mounted
- In white-box a copy of your source goes in. The container has no route back.
- Destroyed when the test ends
- The copied source goes with it, along with the captured traffic, the working notes and the exploit code.
- Nothing trains a model, nothing is left behind
- Your code goes to the model you choose, your own if you have one, and nothing you send is used to train it. No agent, no residual account, no callback.
The deliverable
One interactive report
Everything we found, in one place an engineer can work from.
- Findings by severity, each with its CWE and computed CVSS 3.1 score.
- The evidence: what was sent, what came back, what that proves.
- The reproduction script, inline and copyable, to re-run after the fix.
- The fix as a diff against the responsible lines, in white-box.
- A summary a non-engineer can act on, plus a methodology section for an auditor.
The free scan returns a summary instead: scores and counts by severity. What each tier includes →
Start with the discovery call
Tell us what you’d want tested. We’ll send the agreement and the authorisation.