What happens after you press send

No surprises: every step, who does what, and the document that closes it.

01Steps

Step by step: who does what

  1. Request

    You describe the systems and the goal through the form on this site.

    You
    Describe the system, the goal and the deadline.
    We
    Reply within 1 business day with questions and a time for a call.
  2. Scoping call

    A conversation with a technical specialist, under NDA if you wish.

    You
    Show the system and name the constraints.
    We
    Propose the scope, the depth and the type of test.
  3. Proposal

    A document with scope, method, schedule, team and a fixed price.

    You
    Review and approve.
    We
    Answer questions and fit the scope to the budget.
  4. Authorisation

    The contract, the NDA, the authorisation letter and the rules of engagement are signed. Consents of third parties are collected.

    You
    Sign as the asset owner; provide accounts and contacts.
    We
    Verify the authority to sign; check the testing policies of your providers.
  5. Testing

    Work starts on the agreed date. You have a direct channel to the lead tester.

    You
    Keep the contacts reachable; tell us about changes to the system.
    We
    Test, report urgent findings within 24 hours of confirmation, send status updates.
  6. Report, debrief and retest

    The report is delivered through a secure channel and presented in a call. After your fixes every finding is retested.

    You
    Fix and request the retest within 60 days of the report.
    We
    Retest, issue the attestation letter, destroy working data 30 days after the engagement is closed.

02Models

Engagement models

The model follows the maturity of the system and the pace of its releases.

  • Free website check

    An external check of one website. You learn whether it is open to common attacks before you spend anything.

    Fits
    A first look at the security of a public website.
    Pricing
    Free of charge. The report is paid only when vulnerabilities are found; its price depends on their number and severity.
  • Fixed-scope assessment

    A defined set of assets is tested once, with a report and a retest.

    Fits
    Releases, audits, due diligence, compliance deadlines.
    Pricing
    Fixed price for the agreed scope.
  • Continuous testing

    A standing team tests every significant change and re-examines the perimeter on a schedule.

    Fits
    Products that ship every week.
    Pricing
    Monthly fee for an agreed volume of testing.
  • Pay for results

    A private, time-boxed hunt by our team. You pay for confirmed vulnerabilities according to a reward table agreed in advance.

    Fits
    Mature systems that have been tested before.
    Pricing
    Reward per confirmed finding, with a budget cap.
  • Program management

    We design, launch and run your bug bounty or disclosure program: policy, scope, triage and communication with researchers.

    Fits
    Companies opening up to external researchers.
    Pricing
    Setup fee and a monthly management fee.

03Price

What determines the price

We publish no price list, because two applications of the same kind can differ tenfold in size. These factors decide. After scoping, the price is fixed.

  • Size of the scope

    The number of applications, roles, endpoints, hosts, contracts or lines of code.

  • Depth

    A baseline assessment of common weaknesses, or an in-depth test that includes logic and chaining.

  • Access

    Testing with accounts, documentation and source code finds more per day than testing blind.

  • Constraints

    Night-time windows, production-only testing and work on site add effort.

  • Evidence

    Compliance sections, segmentation tests and attestation letters for third parties.

  • Urgency

    A start within days means rearranging other work.

The price in the proposal is fixed. It changes only if the scope changes, and only with your written approval. The website check is free of charge: its terms and the price of its report are set by the terms of the free website security check.

04Documents

What you sign, and why

The documents are what separates a penetration test from an intrusion.

  • Non-disclosure agreement

    Signed before you share any detail. It covers everything we learn, including the fact that you are a client.

  • Contract

    Scope, schedule, price, liability, confidentiality and data protection.

  • Authorisation letter

    The statement of the asset owner that permits the test. It names the assets, the dates and the testers, and it is what makes the test lawful.

  • Rules of engagement

    Permitted and excluded techniques, test windows, stop conditions, contacts and the handling of sensitive data.

  • Third-party consents

    Hosting, cloud and SaaS providers whose systems are touched. We check their testing policies and obtain consent where it is required.

  • Data processing agreement

    Where personal data may be encountered: the terms of processing under the data protection law that applies to you.

05Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. A manager replies within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

Our specialists read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. Our team plays a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

Our attackers and your defenders work side by side: we show an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test arranged so that an auditor, a regulator or a large customer accepts its report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and a specialist will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check