Questions and answers
What clients ask before the first engagement. If your question is missing, send it through the request form.
Legality and authorisation
Is penetration testing legal?
Yes, when the owner of the system has authorised it in writing. Without authorisation the same actions are a criminal offence in most jurisdictions. That is why every engagement starts with an authorisation letter and a scope, and why we verify that the signatory has the authority to sign.
Who can authorise a test?
The owner of the system or a person the owner has empowered: usually a director, or a head of security or technology acting under a power that the company has granted. We ask for confirmation through an official channel of the company.
Our systems run at a cloud provider. Whose permission is needed?
Yours, for what you operate, and the policy of the provider for the platform underneath. The large providers publish testing policies that permit testing of your own resources without prior approval and list what is prohibited. We check the current policy before every engagement.
Can you test the systems of our suppliers?
Only with the written consent of the supplier. Your contract with a supplier does not give you the right to authorise an attack on their systems unless it says so.
Course of an engagement
How long does an engagement take?
It depends on the scope. The proposal states the number of testing days and the calendar dates; both are agreed before the contract is signed.
Will testing disrupt production?
The rules of engagement define what is allowed: test windows, request rates, excluded techniques and stop conditions. Denial-of-service testing is never performed unless you request it in writing. If we observe instability, we stop and call your contact.
What do you need from us?
A contact person, test accounts, a description of the system and, ideally, an environment that matches production. The page of each service lists what that service needs.
What happens when you find a critical vulnerability during the test?
You are informed within 24 hours of confirmation, through the secure channel agreed at the start, with enough detail to act. We do not wait for the final report.
Results
What does the report contain?
An executive summary, the scope and the method, every finding with evidence, reproduction steps, a CVSS 4.0 vector, a CWE class and a fix, the attack paths, and a remediation plan ordered by priority.
Is a retest included?
Yes. One retest of every finding is included within 60 days of the report. After it you receive an updated report and an attestation letter.
Can we show the results to customers and auditors?
The attestation letter is written for that purpose: it states what was tested, when, by which method and with what result, without technical detail. The full report is yours to share as you see fit.
Does a clean report mean that we are secure?
No. A test shows the state of the systems in scope during the test window, at the agreed depth. It lowers the risk and proves what was checked; it cannot prove that no vulnerability exists. Systems change with every release, which is why the retest and continuous testing exist.
Do you help with the fixes?
Every finding comes with a specific fix, and the debrief call is there for the questions of your engineers. We do not change your systems ourselves: the party that tests should not be the party that fixes.
Price and contract
Is the website check really free?
Yes. The check costs nothing, and so does the report when no vulnerabilities are found. When we find vulnerabilities, you learn their number and severity free of charge and decide whether to buy the report. Its price depends on the number and the severity of the findings and is stated before you decide.
What happens if we do not buy the report?
Nothing. You owe nothing, and what we found stays confidential: we pass it to no one and publish nothing. Signs that the website has already been broken into are reported to you at once and free of charge.
How is the price determined?
By the size and complexity of the scope, the depth of testing and the access provided. After scoping you receive a fixed price; it does not change unless the scope does.
Do you sign an NDA?
Yes. The NDA is signed before you share any detail about your systems.
In which languages do you work?
We correspond and write reports in English and in Russian. A request can be written in any language of this website; the reply comes in English or in Russian. An executive summary of the report in the second language is available on request.
What happens to our data after the engagement?
Working data is destroyed 30 days after the engagement is closed. The report is kept for as long as the contract says and then deleted.
Bug bounty
How does your bug bounty platform work?
Owners publish programs and name the rewards, after they have proved with documents that the system is theirs. Researchers report vulnerabilities through the platform. We examine every report and pay the reward. Our commission is 20% of each reward and is paid by the owner.
What is the difference between a penetration test and a bug bounty?
A penetration test is a time-boxed assessment by a contracted team against an agreed scope, with a report that covers everything tested. A bug bounty is an open-ended program in which independent researchers are rewarded for valid findings. The first gives assurance at a point in time, the second gives continuous discovery.
Are we ready for a public bug bounty program?
If you have not had a penetration test, no. Start with a test and a private program. A public launch on an untested scope pays high rewards for findings that a fixed-price assessment would have delivered.
Someone has sent us a vulnerability report and asks for money. What do we do?
Do not pay under pressure and do not threaten. Acknowledge receipt, ask for the technical detail and verify the claim. We can verify the report, assess its severity and help you answer: send a request through the form and mention that a report is pending.
Request
Tell us what needs testing
- Website check free of charge
- Reply within 1 business day
- NDA before any technical detail
- Fixed price for paid engagements
- No obligation
Request received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the request and replies within 1 business day.
- We agree the scope, the rules of engagement and a secure channel for sensitive material.
- You receive a proposal with method, schedule and a fixed price. For the free website check you receive the authorisation to sign.
We never ask for payment, passwords or remote access in the first reply.