A documented process, not a black box.
Every engagement follows the same arc, and every step of it is written down — what was in scope, what was run, who approved it and whether the fix held.
Four steps, in order.
- 01
Scope and sign-off
We agree the perimeter and the Rules of Engagement in writing before anything is touched — targets, windows, permitted techniques, emergency contacts on both sides.
Ownership is proven, not asserted: a DNS-TXT record you place, or a signed authorisation on file.
- 02
Test and assess
Work inside that boundary and nowhere else. Automated passes find the known; our engineers go after the logic, authorisation and chaining flaws that no scanner reaches.
Assessment, not exploitation — we stop at the proof, never at the damage.
- 03
Report, twice
A technical report with CVSS scores, evidence and reproduction steps for your engineers, and a plain-terms executive summary for whoever signs the budget.
Both halves are in every report — including what was tested and held.
- 04
Retest and debrief
Once you remediate, we test the same finding again and record whether the fix held. Then a live call with your technical team to go through it.
A finding is closed when a retest says so, not when a ticket is marked done.
Why it is safe to let us in.
Nothing runs without a human yes
Every active command is approved by an operator before it goes out, even on a target whose ownership we have already verified by DNS.
Results are reviewed before you see them
Findings are held at a review gate. A staff member releases them, so you never receive an unvetted automated result.
We take the least data that proves it
A vulnerability is demonstrated with the smallest possible sample, masked. We do not extract databases to make a point.
Everything is written down
Scope, authorisation, every command proposed and approved, every artefact created and removed. The audit trail is the product, not a by-product.
See what comes out of it.
Every engagement ends in the same report. Here is what it contains.