What we can evidence, and what we cannot yet.
Engagements run against published standards, under written authorisation, by certified operators. Anything on this page still awaiting confirmation is marked as such rather than estimated.
- Standards applied
- 8
- Disclosure ack.
- 3 working days
- Public record
- CTFtime verified
Certifications
Placeholder — awaiting data
Operators on this team hold industry certifications including OSCP, CPTS and CRTO, and several have long professional practice outside competition. Exact figures are pending confirmation and are deliberately left blank rather than estimated.
To publish real figures, set holders on each entry in content/trust.ts. Until then every count renders as pending; the page will not invent a number.
- OSCPOffensiveOffensive Security Certified ProfessionalOffSecCount pending
- CPTSOffensiveCertified Penetration Testing SpecialistHack The BoxCount pending
- CRTORed teamCertified Red Team OperatorZero-Point SecurityCount pending
- OSWESpecialistOffensive Security Web ExpertOffSecCount pending
- OSEPRed teamOffensive Security Experienced Penetration TesterOffSecCount pending
- CBBHOffensiveCertified Bug Bounty HunterHack The BoxCount pending
Methodology standards
Each standard below is applied to a specific part of the work. Naming them makes coverage arguable: you can hold a report against the guide it claims to follow.
- PTESPenetration Testing Execution Standard · PTESOverall engagement structure, from pre-engagement to reporting
- WSTGOWASP Web Security Testing Guide · OWASPWeb application and API test coverage
- ASVSApplication Security Verification Standard · OWASPVerification depth and control-level assertions
- MASTGMobile Application Security Testing Guide · OWASPAndroid and iOS assessments
- ATT&CKMITRE ATT&CK · MITRERed team technique selection and detection-gap mapping
- SP 800-115Technical Guide to Information Security Testing · NISTAssessment planning, execution and post-test handling
- CVSS v4.0Common Vulnerability Scoring System · FIRSTSeverity scoring, with environmental context applied
- CWECommon Weakness Enumeration · MITRERoot-cause classification in reports and advisories
Operational handling
Data handling
Engagement data is held only as long as the engagement and its retest require, then destroyed on a schedule agreed in the contract. Reports are delivered over an encrypted channel.
Rules of engagement
Every engagement runs under a written authorisation naming the in-scope assets, the testing window, prohibited techniques, and the escalation path for anything that risks availability.
Insurance and contracting
PLACEHOLDER — professional indemnity and liability cover details are pending. Contracting entity and terms are supplied during scoping.
Confidentiality
Mutual NDA before scope is discussed in detail. We do not name clients, publish findings, or reference engagements without written permission.
Coordinated disclosure
Found something in our own estate? Tell us. We acknowledge within 3 working days and work to a 90 days from acknowledgement, or an agreed extension.
In scope
- v1olet.xyz and its subdomains
- Repositories under github.com/v1oletSec
Out of scope
- Findings from automated scanners without a demonstrated impact
- Denial of service, volumetric or resource-exhaustion testing
- Social engineering of team members
- Missing hardening headers with no demonstrated exploit path
Report to
hello@v1olet.xyzPLACEHOLDER — no monetary bounty programme is currently published. Credit is given in the advisory unless you ask otherwise.
Machine-readable policy: /.well-known/security.txt
References
Placeholder
PLACEHOLDER — client references are available on request during scoping, subject to the referencing client’s consent. No client is named publicly.
Public evidence available today
Competition placements are published by the organisers and indexed on CTFtime. That record is independent of anything we say about ourselves, which is why it is the evidence we lead with.

