Skip to content

Offensive security, scoped to what you actually ship.

Five engagement types. Every one is scoped individually, priced before it starts, and delivered by named operators who do not subcontract.

Engagement types
5
Stages per engagement
4
Retest
Included
  1. Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.

    OWASP WSTGOWASP ASVSPTESNIST SP 800-115

    Typical scope

    • Web applications and single-page front ends
    • REST, GraphQL and gRPC APIs
    • Internal and external network infrastructure
    • Cloud configuration and identity boundaries
    • Mobile applications (Android, iOS)
    • Authentication, session and multi-tenancy logic

    You receive

    • Findings report with severity, business impact and CVSS v4 vector per issue
    • Reproduction steps and a working proof of concept for every finding
    • Remediation guidance written for the engineers who own the code
    • Executive summary suitable for board or customer distribution
    • Retest and a reissued report once fixes ship — included in the original price
  2. Adversary simulation that measures whether you detect and respond — not just whether the perimeter holds on the day of the test.

    MITRE ATT&CKTIBER-EU (as a structural reference)PTESDocumented rules of engagement

    Typical scope

    • Objective-based full-scope operations
    • Assumed-breach and insider-threat scenarios
    • Social engineering and phishing (where authorised in writing)
    • Initial access, persistence, privilege escalation, lateral movement
    • Purple team exercises run jointly with your defenders
    • Detection engineering validation against specific ATT&CK techniques

    You receive

    • Attack narrative with a full timeline of operator actions
    • MITRE ATT&CK technique mapping for every stage executed
    • Detection and response gap analysis, per stage
    • Indicators of compromise and artefacts for your SOC to hunt against
    • Joint replay session with your blue team
  3. Deep review of software and protocols, down to the primitives, to surface the bug classes an automated scanner has no way to model.

    CVE / CNA coordinationCWE classificationCVSS v4.0Coordinated disclosure policy

    Typical scope

    • Source-assisted and black-box binary review
    • Reverse engineering of native and managed binaries
    • Protocol and file-format analysis
    • Coverage-guided fuzzing with custom harnesses
    • Cryptographic implementation review
    • Firmware and embedded targets

    You receive

    • Technical advisory per issue, with root cause and affected version range
    • Reproducible crash cases, harnesses and triage notes
    • Exploitability assessment — reachable, conditional, or theoretical
    • Coordinated disclosure handling and CVE coordination where applicable
    • Patch review once a fix is proposed
  4. Testing that runs alongside your release cycle instead of once a year, so findings land while the code is still fresh in someone’s head.

    OWASP SAMM (as a maturity reference)OWASP WSTGCVSS v4.0

    Typical scope

    • Per-release testing of new and changed functionality
    • Regression testing against previously confirmed findings
    • Shared findings queue with live severity and status
    • Threat modelling on new features before they ship
    • Ad-hoc review of security-relevant pull requests
    • Quarterly summary for stakeholders and auditors

    You receive

    • Live findings queue, updated as issues are confirmed and closed
    • Per-release test notes tied to your version tags
    • Quarterly consolidated report for stakeholders and auditors
    • A named lead who carries context between cycles
    • Direct channel to the operators, not a ticket queue
  5. Hands-on sessions built from real engagements and competition work, run for engineering teams as well as internal security functions.

    OWASP Top 10 / API Top 10MITRE ATT&CKMaterial derived from live engagements

    Typical scope

    • Secure development for engineering teams
    • Web and API exploitation, hands-on
    • Binary exploitation and reverse engineering fundamentals
    • Cloud and identity attack paths
    • Detection engineering for blue teams
    • Internal CTF design and facilitation

    You receive

    • Live instructor-led sessions, remote or on site
    • Lab environment participants keep access to afterwards
    • Exercise set and full solutions
    • Recording and materials for teams to reuse internally
    • Optional internal CTF built on your own stack

Not sure which applies?

Send the stack and the deadline. We will say plainly what is worth testing first — including when the honest answer is “not yet”.

Book a scoping call