Questions and answers

What clients ask before the first engagement. If your question is missing, send it through the request form.

Legality and authorisation

Is penetration testing legal?

Yes, when the owner of the system has authorised it in writing. Without authorisation the same actions are a criminal offence in most jurisdictions. That is why every engagement starts with an authorisation letter and a scope, and why we verify that the signatory has the authority to sign.

Who can authorise a test?

The owner of the system or a person the owner has empowered: usually a director, or a head of security or technology acting under a power that the company has granted. We ask for confirmation through an official channel of the company.

Our systems run at a cloud provider. Whose permission is needed?

Yours, for what you operate, and the policy of the provider for the platform underneath. The large providers publish testing policies that permit testing of your own resources without prior approval and list what is prohibited. We check the current policy before every engagement.

Can you test the systems of our suppliers?

Only with the written consent of the supplier. Your contract with a supplier does not give you the right to authorise an attack on their systems unless it says so.

Course of an engagement

How long does an engagement take?

It depends on the scope. The proposal states the number of testing days and the calendar dates; both are agreed before the contract is signed.

Will testing disrupt production?

The rules of engagement define what is allowed: test windows, request rates, excluded techniques and stop conditions. Denial-of-service testing is never performed unless you request it in writing. If we observe instability, we stop and call your contact.

What do you need from us?

A contact person, test accounts, a description of the system and, ideally, an environment that matches production. The page of each service lists what that service needs.

What happens when you find a critical vulnerability during the test?

You are informed within 24 hours of confirmation, through the secure channel agreed at the start, with enough detail to act. We do not wait for the final report.

Results

What does the report contain?

An executive summary, the scope and the method, every finding with evidence, reproduction steps, a CVSS 4.0 vector, a CWE class and a fix, the attack paths, and a remediation plan ordered by priority.

Is a retest included?

Yes. One retest of every finding is included within 60 days of the report. After it you receive an updated report and an attestation letter.

Can we show the results to customers and auditors?

The attestation letter is written for that purpose: it states what was tested, when, by which method and with what result, without technical detail. The full report is yours to share as you see fit.

Does a clean report mean that we are secure?

No. A test shows the state of the systems in scope during the test window, at the agreed depth. It lowers the risk and proves what was checked; it cannot prove that no vulnerability exists. Systems change with every release, which is why the retest and continuous testing exist.

Do you help with the fixes?

Every finding comes with a specific fix, and the debrief call is there for the questions of your engineers. We do not change your systems ourselves: the party that tests should not be the party that fixes.

Price and contract

Is the website check really free?

Yes. The check costs nothing, and so does the report when no vulnerabilities are found. When we find vulnerabilities, you learn their number and severity free of charge and decide whether to buy the report. Its price depends on the number and the severity of the findings and is stated before you decide.

What happens if we do not buy the report?

Nothing. You owe nothing, and what we found stays confidential: we pass it to no one and publish nothing. Signs that the website has already been broken into are reported to you at once and free of charge.

How is the price determined?

By the size and complexity of the scope, the depth of testing and the access provided. After scoping you receive a fixed price; it does not change unless the scope does.

Do you sign an NDA?

Yes. The NDA is signed before you share any detail about your systems.

In which languages do you work?

We correspond and write reports in English and in Russian. A request can be written in any language of this website; the reply comes in English or in Russian. An executive summary of the report in the second language is available on request.

What happens to our data after the engagement?

Working data is destroyed 30 days after the engagement is closed. The report is kept for as long as the contract says and then deleted.

Bug bounty

How does your bug bounty platform work?

Owners publish programs and name the rewards, after they have proved with documents that the system is theirs. Researchers report vulnerabilities through the platform. We examine every report and pay the reward. Our commission is 20% of each reward and is paid by the owner.

What is the difference between a penetration test and a bug bounty?

A penetration test is a time-boxed assessment by a contracted team against an agreed scope, with a report that covers everything tested. A bug bounty is an open-ended program in which independent researchers are rewarded for valid findings. The first gives assurance at a point in time, the second gives continuous discovery.

Are we ready for a public bug bounty program?

If you have not had a penetration test, no. Start with a test and a private program. A public launch on an untested scope pays high rewards for findings that a fixed-price assessment would have delivered.

Someone has sent us a vulnerability report and asks for money. What do we do?

Do not pay under pressure and do not threaten. Acknowledge receipt, ask for the technical detail and verify the claim. We can verify the report, assess its severity and help you answer: send a request through the form and mention that a report is pending.

Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. A manager replies within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

Our specialists read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. Our team plays a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

Our attackers and your defenders work side by side: we show an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test arranged so that an auditor, a regulator or a large customer accepts its report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and a specialist will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check