Request
You describe the systems and the goal through the form on this site.
- You
- Describe the system, the goal and the deadline.
- We
- Reply within 1 business day with questions and a time for a call.
Scoping call
A conversation with a technical specialist, under NDA if you wish.
- You
- Show the system and name the constraints.
- We
- Propose the scope, the depth and the type of test.
Proposal
A document with scope, method, schedule, team and a fixed price.
- You
- Review and approve.
- We
- Answer questions and fit the scope to the budget.
Authorisation
The contract, the NDA, the authorisation letter and the rules of engagement are signed. Consents of third parties are collected.
- You
- Sign as the asset owner; provide accounts and contacts.
- We
- Verify the authority to sign; check the testing policies of your providers.
Testing
Work starts on the agreed date. You have a direct channel to the lead tester.
- You
- Keep the contacts reachable; tell us about changes to the system.
- We
- Test, report urgent findings within 24 hours of confirmation, send status updates.
Report, debrief and retest
The report is delivered through a secure channel and presented in a call. After your fixes every finding is retested.
- You
- Fix and request the retest within 60 days of the report.
- We
- Retest, issue the attestation letter, destroy working data 30 days after the engagement is closed.
What happens after you press send
No surprises: every step, who does what, and the document that closes it.
01Steps
Step by step: who does what
02Models
Engagement models
The model follows the maturity of the system and the pace of its releases.
Free website check
An external check of one website. You learn whether it is open to common attacks before you spend anything.
- Fits
- A first look at the security of a public website.
- Pricing
- Free of charge. The report is paid only when vulnerabilities are found; its price depends on their number and severity.
Fixed-scope assessment
A defined set of assets is tested once, with a report and a retest.
- Fits
- Releases, audits, due diligence, compliance deadlines.
- Pricing
- Fixed price for the agreed scope.
Continuous testing
A standing team tests every significant change and re-examines the perimeter on a schedule.
- Fits
- Products that ship every week.
- Pricing
- Monthly fee for an agreed volume of testing.
Pay for results
A private, time-boxed hunt by our team. You pay for confirmed vulnerabilities according to a reward table agreed in advance.
- Fits
- Mature systems that have been tested before.
- Pricing
- Reward per confirmed finding, with a budget cap.
Program management
We design, launch and run your bug bounty or disclosure program: policy, scope, triage and communication with researchers.
- Fits
- Companies opening up to external researchers.
- Pricing
- Setup fee and a monthly management fee.
03Price
What determines the price
We publish no price list, because two applications of the same kind can differ tenfold in size. These factors decide. After scoping, the price is fixed.
Size of the scope
The number of applications, roles, endpoints, hosts, contracts or lines of code.
Depth
A baseline assessment of common weaknesses, or an in-depth test that includes logic and chaining.
Access
Testing with accounts, documentation and source code finds more per day than testing blind.
Constraints
Night-time windows, production-only testing and work on site add effort.
Evidence
Compliance sections, segmentation tests and attestation letters for third parties.
Urgency
A start within days means rearranging other work.
The price in the proposal is fixed. It changes only if the scope changes, and only with your written approval. The website check is free of charge: its terms and the price of its report are set by the terms of the free website security check.
04Documents
What you sign, and why
The documents are what separates a penetration test from an intrusion.
Non-disclosure agreement
Signed before you share any detail. It covers everything we learn, including the fact that you are a client.
Contract
Scope, schedule, price, liability, confidentiality and data protection.
Authorisation letter
The statement of the asset owner that permits the test. It names the assets, the dates and the testers, and it is what makes the test lawful.
Rules of engagement
Permitted and excluded techniques, test windows, stop conditions, contacts and the handling of sensitive data.
Third-party consents
Hosting, cloud and SaaS providers whose systems are touched. We check their testing policies and obtain consent where it is required.
Data processing agreement
Where personal data may be encountered: the terms of processing under the data protection law that applies to you.
05Request
Tell us what needs testing
- Website check free of charge
- Reply within 1 business day
- NDA before any technical detail
- Fixed price for paid engagements
- No obligation
Request received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the request and replies within 1 business day.
- We agree the scope, the rules of engagement and a secure channel for sensitive material.
- You receive a proposal with method, schedule and a fixed price. For the free website check you receive the authorisation to sign.
We never ask for payment, passwords or remote access in the first reply.