How we test, in the open

A method that cannot be explained cannot be audited. This page describes what we do in every engagement, in what order, and what you hold in your hands after each phase.

01Phases

Every phase ends with an output

The sequence follows PTES and NIST SP 800-115. The depth of each phase depends on the service; the order does not.

  1. Pre-engagement

    Scope, objectives, test windows, contacts, stop conditions and legal documents are agreed and signed. Nothing is tested before this phase is closed.

    • Authorisation letter
    • Rules of engagement
    • Scope statement
  2. Reconnaissance

    We collect what is publicly known about the target and map the attack surface inside the scope.

    • Map of assets and entry points
  3. Threat modelling

    We establish what an attacker would want and which paths lead there, and spend the time where the damage would be greatest.

    • Test plan with priorities
  4. Vulnerability analysis

    Automated tools cover the known classes. Every candidate is verified by hand; unverified scanner output is never reported.

    • Verified candidates
  5. Exploitation

    Verified weaknesses are exploited to the depth the rules of engagement allow, to prove impact instead of assuming it.

    • Evidence of impact
    • Urgent finding notices
  6. Post-exploitation

    We establish what the access is worth: which data, which systems, which further steps. Everything created during the test is removed.

    • Attack paths
    • Clean-up record
  7. Reporting and retest

    Findings are written up, reviewed by a second specialist, presented to your team and retested after the fix.

    • Report
    • Debrief
    • Retest report
    • Attestation letter

02Severity

One scale for every finding

Findings are rated with CVSS 4.0. The score is the starting point: the business context of the affected asset can raise or lower the priority, and the report says when it does and why.

RatingScoreWhat it meansHow it is handled
Critical9.0 – 10.0The system or its data can be compromised remotely, without special conditions.Reported within 24 hours of confirmation. Fix before anything else.
High7.0 – 8.9Serious impact, with a condition that limits exploitation.Reported within 24 hours of confirmation. Fix in the current cycle.
Medium4.0 – 6.9Limited impact, or exploitation that depends on circumstances the attacker does not control.Reported in the final report. Plan the fix.
Low0.1 – 3.9Minor impact; useful to an attacker mainly in combination with other findings.Reported in the final report. Fix with routine maintenance.
Informational0.0A deviation from good practice without direct security impact.Reported as an observation.

CVSS is published by FIRST. The ranges follow the qualitative severity rating scale of the CVSS 4.0 specification.

03Safety

Rules that protect production

A test must not become the incident it is meant to prevent.

  • Stop conditions

    Testing stops when a system becomes unstable, when data of real users is exposed beyond the minimum proof, or when traces of another attacker are found. Your contact is called at once.

  • No denial of service

    Availability is not tested unless you ask for it in writing, in a window you choose.

  • Minimal proof

    Access is proven with the smallest possible action: one record and not the table, a harmless file and not a payload.

  • Our own test data

    Where data has to be created or modified, we use accounts and records made for the test.

  • Clean-up

    Accounts, files and configuration changes made during the test are removed and listed in the report.

  • Evidence handling

    Evidence is stored encrypted, access is limited to the engagement team, and working data is destroyed 30 days after the engagement is closed.

04Automation and AI

Led by people, assisted by tools

Automation widens coverage. Judgement stays with specialists.

  • What tools do

    Discovery, enumeration and checks for known vulnerability classes are automated, so that manual time goes to what needs judgement.

  • What people do

    Business logic, access control, chaining and impact are tested by hand. Every finding in a report has been reproduced by a specialist.

  • AI assistance

    Language models help with the analysis of code and tool output inside environments we control. Client data is never submitted to public AI services and never used for training.

  • No unverified output

    Nothing produced by a tool or a model reaches a report without manual verification.

05Standards

The public standards behind the method

Versions as verified on the publishers’ own pages on September 28, 2026. Following a standard does not mean being certified, approved or endorsed by its publisher.

Testing methods

Verification requirements

Adversary emulation

AI systems

Software supply chain

Rating and classification

Disclosure and handling

06Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. A manager replies within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

Our specialists read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. Our team plays a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

Our attackers and your defenders work side by side: we show an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test arranged so that an auditor, a regulator or a large customer accepts its report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and a specialist will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check