Legality first
We would rather lose a contract than test without authorisation.
Proof, not opinion
We report what we have reproduced, with the evidence attached.
Plain language
A report that management cannot read and engineers cannot act on is a failed report.
Independence
We sell no security products and take no commission from vendors or platforms. Our recommendations have no second purpose.
Responsibility for impact
We test as if the system were ours: carefully, and with a way back.
Discretion
We do not name clients and do not tell stories about them.
We attack for the defence
Security Test Team is an offensive security practice. We find the weaknesses of a system before someone with other intentions does, and we do it only where the owner has asked us to.
01Principles
What we hold to
02Team
Who works on your engagement
Named specialists
The proposal names the people who will do the work. They are the ones who do it.
A second pair of eyes
Every report is reviewed by a specialist who took no part in the test.
The right specialisation
A smart contract is audited by people who audit smart contracts, a mobile application by people who take mobile applications apart. Where we lack the specialisation, we say so and decline.
One point of contact
A lead tester is reachable for the whole duration of the engagement.
03Boundaries
Work we do not take
- Testing without the written authorisation of the asset owner
- Access to accounts, devices or correspondence of private individuals
- Collection of compromising information about people or competitors
- Development or sale of malware and exploits for use outside an authorised test
- Anything that requires concealing the engagement from the owner of the systems
04Operator
Osaühing Ida Portal
- Registry code
- 10970449
- Registered office
- Kivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia
05Request
Tell us what needs testing
- Website check free of charge
- Reply within 1 business day
- NDA before any technical detail
- Fixed price for paid engagements
- No obligation
Request received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the request and replies within 1 business day.
- We agree the scope, the rules of engagement and a secure channel for sensitive material.
- You receive a proposal with method, schedule and a fixed price. For the free website check you receive the authorisation to sign.
We never ask for payment, passwords or remote access in the first reply.