Methodology
How our engagements run
Scoping and a written proposal
Every engagement begins with a written scope and proposal.
Before any work starts, we agree on the question the engagement has to answer, what’s in scope, and what isn’t. Remote-first, senior-led delivery. Every engagement is led by an experienced practitioner.
What shapes scope and price
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Authorization before any testing
All penetration testing requires written authorization, a signed scope, rules of engagement, approved targets, testing windows, emergency contacts, and stop conditions.
Penetration testing touches live systems, so these documents are in place before testing begins.
- Written authorization
- Permission, in writing, from someone with the authority to approve testing of the systems in scope.
- Signed scope
- The systems, applications, and accounts that are included, and the ones that aren't.
- Rules of engagement
- What testers may and may not do while testing.
- Approved targets
- The specific addresses, hostnames, or applications that may be tested.
- Testing windows
- The dates and times when testing is allowed.
- Emergency contacts
- Who to reach, on both sides, if something unexpected happens.
- Stop conditions
- The situations in which testing pauses right away.
Handling your evidence
Assessments and readiness work often involve sensitive material, such as configurations, policies, logs, and test results.
Don't send sensitive information through this website
We don't collect sensitive evidence through this website. Please don't send passwords or other credentials, sensitive incident details, payment card data, health information, or controlled defense information through a website form. When an engagement needs sensitive evidence, we arrange a secure channel with you after initial contact.
Active client records follow the signed contract and applicable legal and accounting schedules.
Reporting
Penetration tests
Penetration-test pricing assumes authorized manual testing, an executive summary, a technical report, remediation guidance, and one retest within 60 days unless the proposal says otherwise.
Assessments, readiness, and advisory work
Deliverables differ by service, so each service page describes its own. Browse services and their deliverables
Frameworks we reference
Security posture and risk assessments mapped to NIST CSF 2.0 and CIS Controls.
- NIST Cybersecurity Framework (CSF) 2.0
- Published by the U.S. National Institute of Standards and Technology. It describes security outcomes under six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It gives a shared way to describe where an organization is today and where it wants to be.
- CIS Critical Security Controls v8.1
- Published by the Center for Internet Security. A prioritized set of technical safeguards, grouped into implementation groups by an organization’s resources and risk, that turns priorities into concrete steps.
Compliance readiness for SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, and CMMC. Compare compliance readiness options
Independence
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Start with a scoping conversation
Tell us what you need to decide or prove, and we’ll start from there.