Process

How we work

Five steps. The order does not change. Testing does not begin on a handshake or an email thread.

  1. Authorisation

    You name the assets. We write the scope, the rules of engagement, and a maximum invoice. Both parties sign. Until then, nothing is tested.

  2. Test

    The assessment is remote and non-destructive. Work stays inside the signed scope and the signed rules. Destructive or prohibited techniques are not used.

  3. Report

    You receive a written report of verified findings. Each finding includes evidence, a severity band, and a recommended next step.

  4. Retest

    After you remediate, we retest the named findings. The retest belongs to the same assessment unless the signed scope says otherwise.

  5. Close

    The assessment closes when the report is delivered and any agreed retest is complete. Further testing needs a new signed scope.